<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608050#M105528</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for asking. Actually the client had CPU problem in windows server end and they seeing that this is the cause of Universal Forwarder as per they initial checks. So this is our work around just to refrain of getting the data real time.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We believe (somehow) that it will resolve the problem by changing interval in every 30mins. However, we have also another approach which are the whitelist/blacklist but it seems like it is not working for us. We think that it is because the task name event is not a part&amp;nbsp; of the filtering suggestion for whitelist/blacklist. The suggested events are EventID, Category, message,&amp;nbsp; Opcode etc which are not available in the _raw events. This is related to this link:&amp;nbsp;&lt;U&gt;&lt;EM&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-setup-to-whitelist-and-blacklist-in-inputs-conf-to-pulll/m-p/608021#M105525" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-setup-to-whitelist-and-blacklist-in-inputs-conf-to-pulll/m-p/608021#M105525&lt;/A&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Aug 2022 09:49:44 GMT</pubDate>
    <dc:creator>vin_ven27</dc:creator>
    <dc:date>2022-08-03T09:49:44Z</dc:date>
    <item>
      <title>How to set timing/interval when pulling event in WinEventLog using universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608008#M105521</link>
      <description>&lt;P&gt;We install Universal forwarder in Windows Server for us to pull data from [WinEventLog://Microsoft-Windows-TaskScheduler/Operational] to Splunk, to monitor jobs/event.&lt;BR /&gt;Currently per check we are getting data real time from WinEventLog. Is there a way that we can change the timing/interval in every 10mins? We already tried:&lt;/P&gt;
&lt;P&gt;interval = 600, interval = &amp;lt;cron&amp;gt; , schedule = 600 and schedule = &amp;lt;cron&amp;gt; but doesn't work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May we know if you have any solution for this?&lt;/P&gt;
&lt;P&gt;Please...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608008#M105521</guid>
      <dc:creator>vin_ven27</dc:creator>
      <dc:date>2022-08-03T14:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608018#M105524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227484"&gt;@vin_ven27&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can find the options for a wineventlog input at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Anyway, Splunk UF continously takes wineventlogs and send them (by default) every&amp;nbsp; 30 seconds.&lt;/P&gt;&lt;P&gt;If you want, you can change the sending frequency on the outputs.conf.&lt;/P&gt;&lt;P&gt;It's not possible to set a frequency for wineventlog frequency.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 07:13:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608018#M105524</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-03T07:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608031#M105526</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;May I know what parameters I can use in outputs.conf for the frequency setup?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I saw&amp;nbsp;autoLBfrequency and&amp;nbsp;polling_interval but I am not sure if I these is the parameter you are referring to. Please advise... tia&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 07:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608031#M105526</guid>
      <dc:creator>vin_ven27</dc:creator>
      <dc:date>2022-08-03T07:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608034#M105527</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227484"&gt;@vin_ven27&lt;/a&gt;.,&lt;/P&gt;&lt;P&gt;at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&amp;nbsp;you can find all the outputs.conf parameterts.&lt;/P&gt;&lt;P&gt;Between them see batchTimeout:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;batchTimeout = &amp;lt;integer&amp;gt;
* How often, in seconds, to send out pipeline data.
* HTTP OUT batch pipeline data before sending out.
* If the wait time is greater than 'batchTimeout', HEC sends the data 
  out immediately.
* Default: 30&lt;/LI-CODE&gt;&lt;P&gt;But, why do you want to have data at fixed intervals instead continously?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 08:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608034#M105527</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-03T08:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608050#M105528</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for asking. Actually the client had CPU problem in windows server end and they seeing that this is the cause of Universal Forwarder as per they initial checks. So this is our work around just to refrain of getting the data real time.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We believe (somehow) that it will resolve the problem by changing interval in every 30mins. However, we have also another approach which are the whitelist/blacklist but it seems like it is not working for us. We think that it is because the task name event is not a part&amp;nbsp; of the filtering suggestion for whitelist/blacklist. The suggested events are EventID, Category, message,&amp;nbsp; Opcode etc which are not available in the _raw events. This is related to this link:&amp;nbsp;&lt;U&gt;&lt;EM&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-setup-to-whitelist-and-blacklist-in-inputs-conf-to-pulll/m-p/608021#M105525" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-setup-to-whitelist-and-blacklist-in-inputs-conf-to-pulll/m-p/608021#M105525&lt;/A&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 09:49:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608050#M105528</guid>
      <dc:creator>vin_ven27</dc:creator>
      <dc:date>2022-08-03T09:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608051#M105529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227484"&gt;@vin_ven27&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I encountered this kind of problem and I solved with Splunk Support, so I hint to open a ticket.&lt;/P&gt;&lt;P&gt;usually the problem is related to the connection with the DNS for url resolution not to the frequency of data send.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 09:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608051#M105529</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-03T09:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608052#M105530</link>
      <description>&lt;P&gt;Will do. thanks buddy. Appreciated your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alvin&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 10:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608052#M105530</guid>
      <dc:creator>vin_ven27</dc:creator>
      <dc:date>2022-08-03T10:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608121#M105535</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227484"&gt;@vin_ven27&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if one answer solves your need, please accept one answer for the other people of Community or tell us how we can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 15:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/608121#M105535</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-08-03T15:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701773#M116119</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what about reading log from application log files? is it continuously monitoring or can we make it interval?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 08:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701773#M116119</guid>
      <dc:creator>hazem</dc:creator>
      <dc:date>2024-10-14T08:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701775#M116121</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267164"&gt;@hazem&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's usually continouslòy monitored every 30 seconds, but you can cheange this frequency, even fi I'didn't do it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 08:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701775#M116121</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-14T08:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701779#M116122</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you please provide me with the stanza to change the interval required to read logs from the log file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;,EX MSSQL-&amp;nbsp; ERROR.log file&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 08:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701779#M116122</guid>
      <dc:creator>hazem</dc:creator>
      <dc:date>2024-10-14T08:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to set Timing/Interval when pulling event in WinEventLog using Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701781#M116123</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267164"&gt;@hazem&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;now I don't find the parameter, also because I try to avoid to change it, the default value usually is the best solution.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 09:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-timing-interval-when-pulling-event-in-WinEventLog/m-p/701781#M116123</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-14T09:01:05Z</dc:date>
    </item>
  </channel>
</rss>

