Deployment Architecture

Remote event log collections polling

Jodge
Path Finder

When collecting remote event logs how frequently does Splunk poll the remote host and is this configurable?

Tags (4)
0 Karma
1 Solution

Vladimir
Path Finder

There is no default value and you can configure the interval of polling, check wmi.conf documentation http://www.splunk.com/base/Documentation/latest/admin/Wmiconf

interval = <integer>
* How often, in seconds, to poll for new data.
* This attribute is required, and the input will not run if the attribute is
  not present.
* There is no default.

View solution in original post

0 Karma

Jodge
Path Finder

Doh! I knew that I knew the answer before posting the question.

It's in the config file but not in the UI.

Thank you.

0 Karma

Vladimir
Path Finder

There is no default value and you can configure the interval of polling, check wmi.conf documentation http://www.splunk.com/base/Documentation/latest/admin/Wmiconf

interval = <integer>
* How often, in seconds, to poll for new data.
* This attribute is required, and the input will not run if the attribute is
  not present.
* There is no default.
0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...