All Apps and Add-ons

Splunk Add-ons for Microsoft Windows/Unix and Linux: Can I reduce the volume of data indexed by increasing the script intervals?

edwardrose
Contributor

Hello

It is my understanding that the Splunk Add-on for Unix and Linux scripts that run take a snapshot in time on the nix servers correct? So if that is true, to reduce the amount of data that we are ingesting for index=os, all I have to do is change the intervals to something longer. An example would be if I were increase the intervals by 3x, I would theoretically reduce the data being ingested by 3x. As we have 250G/day license and OS is using 60G/day on average and now we are starting to go over on our licensing on a regular basis. So I am trying to reduce the Splunk_TA_nix add-on and the Splunk Add-on for Microsoft Windows so we are not getting as much data from those add-ons.

Thanks
ed

0 Karma

hortonew
Builder

You're correct - if you go into the TA apps, you can copy the inputs.conf out of default, and place it into local. Then edit that version, increasing the interval. A lot of the inputs are scripted inputs, so they run a unix command at those intervals, adding all data pulled back.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...