A filtering rule that excludes one or more members from a set. For example, you can use blacklist rules to tell a forwarder which files not to consume when monitoring directories, or you can use blacklists with the deployment server to filter out certain deployment clients.
You can combine blacklist rules with whitelist rules, which tell the Splunk platform which members of a set to allow, to achieve precise filtering. Blacklist rules override whitelist rules.
For more information
In Getting Data In:
In Updating Splunk Enterprise Instances: