<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure heavy forwarder to send data periodically in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199448#M39482</link>
    <description>&lt;P&gt;Maybe, you could configure a regular monitor. Then use cron or any other scheduler tool to start and stop the UF as needed&lt;/P&gt;

&lt;P&gt;You could install several instances of uf in the same host, if needed, one for real time monitoring and the other one for batch (with the start and stop trick...)&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2014 12:36:16 GMT</pubDate>
    <dc:creator>gfuente</dc:creator>
    <dc:date>2014-01-10T12:36:16Z</dc:date>
    <item>
      <title>Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199443#M39477</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;

&lt;P&gt;I set-up Heavy forwarder at Machine-1 and wants to send data on Machine-2, since network in involve in between so i want to minimize the network traffic to prevent certain type of events and send the imp event immediately but less imp event per day or per hours. &lt;BR /&gt;
Many Places i read that using universal forwarder we cann't do filter as well as interval setting, that's why i moved to Heavy forwarder, I can able to filter out events in heavy forwarders but unable to set periodicity. &lt;/P&gt;

&lt;P&gt;It would be great help if some one can tell me stanza for setting interval of polling, &lt;BR /&gt;
lets say, I want to monitor, &lt;STRONG&gt;"testlog" all time and "testlog1" after every 30 mins and "testlog2" after every 1 hours.&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;Right now my inputs.conf is below, &lt;/P&gt;

&lt;P&gt;[monitor:///usr/local/preview/splunk/testlog/*]&lt;BR /&gt;
index = main&lt;BR /&gt;
sourcetype = testlog&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
_TCP_ROUTING = splunkindexer_9997 &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:37:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199443#M39477</guid>
      <dc:creator>moohkhol</dc:creator>
      <dc:date>2020-09-28T15:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199444#M39478</link>
      <description>&lt;P&gt;This is not unique to Universal Forwarders - no Splunk instance has the option to send logs just periodically. So, moving to a heavy forwarder does not help.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 10:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199444#M39478</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-01-10T10:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199445#M39479</link>
      <description>&lt;P&gt;What's the best practice for splunk to achieve this, lets say i wants to use log for data analytics perspective, i don't need real time information, even if it's hours old or day old it would me fine for me, it would be very general requirement. &lt;BR /&gt;
Any suggestion for that would help me a lots.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 10:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199445#M39479</guid>
      <dc:creator>moohkhol</dc:creator>
      <dc:date>2014-01-10T10:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199446#M39480</link>
      <description>&lt;P&gt;What's the best practice for splunk to achieve this, lets say i wants to use log for data analytics perspective, i don't need real time information, even if it's hours old or day old it would me fine for me, it would be very general requirement. &lt;BR /&gt;
Any suggestion for that would help me a lots.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 10:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199446#M39480</guid>
      <dc:creator>moohkhol</dc:creator>
      <dc:date>2014-01-10T10:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199447#M39481</link>
      <description>&lt;P&gt;Commonly this is not a problem as most environments don't have so little bandwidth. If it's bandwidth you're concerned about, you can limit at which rate forwarders send their data in limits.conf. Default for a Universal Forwarder is 256kB/s.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 10:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199447#M39481</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-01-10T10:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199448#M39482</link>
      <description>&lt;P&gt;Maybe, you could configure a regular monitor. Then use cron or any other scheduler tool to start and stop the UF as needed&lt;/P&gt;

&lt;P&gt;You could install several instances of uf in the same host, if needed, one for real time monitoring and the other one for batch (with the start and stop trick...)&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 12:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199448#M39482</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2014-01-10T12:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configure heavy forwarder to send data periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199449#M39483</link>
      <description>&lt;P&gt;Also, on the bandwidth consumption concern, note that if you enable useclientSSLcompression on the universal forwarder, you will achieve significant compression benefit. See here: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/92067/forwarder-output-compression-ratio"&gt;http://answers.splunk.com/answers/92067/forwarder-output-compression-ratio&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The heavyweight forwarder is not nearly as efficient. General rule of thumb - if you are dropping more than about 60% of the traffic, then it warrants an HWF.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 21:27:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-heavy-forwarder-to-send-data-periodically/m-p/199449#M39483</guid>
      <dc:creator>jbrodsky_splunk</dc:creator>
      <dc:date>2014-01-10T21:27:38Z</dc:date>
    </item>
  </channel>
</rss>

