When collecting remote event logs how frequently does Splunk poll the remote host and is this configurable?
There is no default value and you can configure the interval of polling, check wmi.conf documentation http://www.splunk.com/base/Documentation/latest/admin/Wmiconf
interval = <integer>
* How often, in seconds, to poll for new data.
* This attribute is required, and the input will not run if the attribute is
* There is no default.
View solution in original post
Doh! I knew that I knew the answer before posting the question.
It's in the config file but not in the UI.