Exam SPLK-1003 Topic 11 Question 162 Discussion
Actual exam question for Splunk's SPLK-1003 exam
Question #: 162
Topic #: 11
Question #: 162
Topic #: 11
In case of a conflict between a whitelist and a blacklist input setting, which one is used?
Suggested Answer: A Vote an answer
https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Whitelistorblacklistspecificincomingdata
"It is not necessary to define both an allow list and a deny list in a configuration stanza. The settings are independent. If you do define both filters and a file matches them both, Splunk Enterprise does not index that file, as the blacklist filter overrides the whitelist filter." Source:https://docs.splunk.com/Documentation/Splunk
/8.1.0/Data/Whitelistorblacklistspecificincomingdata
"It is not necessary to define both an allow list and a deny list in a configuration stanza. The settings are independent. If you do define both filters and a file matches them both, Splunk Enterprise does not index that file, as the blacklist filter overrides the whitelist filter." Source:https://docs.splunk.com/Documentation/Splunk
/8.1.0/Data/Whitelistorblacklistspecificincomingdata
by Samantha at Feb 22, 2026, 03:29 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).