<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Universal Forwarder in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639478#M221571</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252727"&gt;@VijayA&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk reads and immediately sends files when they are generated, the generation frequency hasn't inpact one the UF activity.&lt;/P&gt;&lt;P&gt;If you want to limit the bandwidth occupation of your data, you can setup a limit of the dimension of the data packets sent by the UF, but you don't need any intervene on the frequency.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 09:57:56 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-04-11T09:57:56Z</dc:date>
    <item>
      <title>Is there any way we can control logs generation time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639472#M221568</link>
      <description>&lt;P&gt;Hi, Can you advise on my Query.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Splunk Universal Forwarder installed on client machine, the are generating log files for every 2hrs, is there any way we can control there logs generation time? can we set anything in UF to generate log files for every 30mins and push to Indexer?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 17:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639472#M221568</guid>
      <dc:creator>VijayA</dc:creator>
      <dc:date>2023-04-11T17:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639478#M221571</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252727"&gt;@VijayA&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk reads and immediately sends files when they are generated, the generation frequency hasn't inpact one the UF activity.&lt;/P&gt;&lt;P&gt;If you want to limit the bandwidth occupation of your data, you can setup a limit of the dimension of the data packets sent by the UF, but you don't need any intervene on the frequency.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 09:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639478#M221571</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-11T09:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639479#M221572</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You mean, we can't control the frequency of sending logs from UF to Index, like for every 30mins?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no issues with&amp;nbsp;&lt;SPAN&gt;bandwidth occupation,&amp;nbsp; only I want to know is can we set any time frequency to send logs.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 10:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639479#M221572</guid>
      <dc:creator>VijayA</dc:creator>
      <dc:date>2023-04-11T10:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639481#M221573</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252727"&gt;@VijayA&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, Splunk continously checks the presence of new logs and reads and sent them.&lt;/P&gt;&lt;P&gt;What's the problem for this behavior?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 10:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639481#M221573</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-11T10:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639486#M221576</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;NO problem from Splunk side, I'm comparing 2 logs from different servers, both are coming to Splunk in different times, not able to extract the correct results. Hence, checking if there any possibility to control.&lt;/P&gt;&lt;P&gt;Thanks for your inputs!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 10:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-any-way-we-can-control-logs-generation-time/m-p/639486#M221576</guid>
      <dc:creator>VijayA</dc:creator>
      <dc:date>2023-04-11T10:39:06Z</dc:date>
    </item>
  </channel>
</rss>

