<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: default interval for data sending in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74377#M18746</link>
    <description>&lt;P&gt;What's in your environment that makes it a bad idea to send the data as soon as it arrives to the forwarder?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Sep 2012 12:22:16 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2012-09-28T12:22:16Z</dc:date>
    <item>
      <title>default interval for data sending</title>
      <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74373#M18742</link>
      <description>&lt;P&gt;I am using Universal forwarder to send data to main Splunk instance to monitor files/directories.&lt;/P&gt;

&lt;P&gt;What is default interval to send data?&lt;BR /&gt;
How do I change this interval for x seconds to y seconds?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 10:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74373#M18742</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-09-28T10:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: default interval for data sending</title>
      <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74374#M18743</link>
      <description>&lt;P&gt;There is no interval. The forwarder sends data as soon as it has anything to send. You should expect some minor delay before you see the data in your index since data needs to move through the various queues in both the forwarder and the indexer, though. The inputs your forwarder is configured with might use some kind of intervals, like scripted inputs or WMI based inputs.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 12:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74374#M18743</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-28T12:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: default interval for data sending</title>
      <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74375#M18744</link>
      <description>&lt;P&gt;Then how do I configure Splunk Universal forwarder to send data every one hour to main Instance?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 12:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74375#M18744</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-09-28T12:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: default interval for data sending</title>
      <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74376#M18745</link>
      <description>&lt;P&gt;To achieve that you'd need to use a scripted input that only reads the data once an hour. There's some stuff on it here: &lt;A href="http://splunk-base.splunk.com/answers/59916/can-you-set-a-certain-time-forwarding-occurs"&gt;http://splunk-base.splunk.com/answers/59916/can-you-set-a-certain-time-forwarding-occurs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 12:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74376#M18745</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-28T12:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: default interval for data sending</title>
      <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74377#M18746</link>
      <description>&lt;P&gt;What's in your environment that makes it a bad idea to send the data as soon as it arrives to the forwarder?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 12:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74377#M18746</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-28T12:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: default interval for data sending</title>
      <link>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74378#M18747</link>
      <description>&lt;P&gt;If the log constantly changes, then it would be expensive to send a TCP traffic every time it changes.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2015 23:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/default-interval-for-data-sending/m-p/74378#M18747</guid>
      <dc:creator>InkerzBrad</dc:creator>
      <dc:date>2015-10-07T23:04:46Z</dc:date>
    </item>
  </channel>
</rss>

