Deployment Architecture
Highlighted

Remote event log collections polling

Path Finder

When collecting remote event logs how frequently does Splunk poll the remote host and is this configurable?

Tags (4)
0 Karma
Highlighted

Re: Remote event log collections polling

Path Finder

There is no default value and you can configure the interval of polling, check wmi.conf documentation http://www.splunk.com/base/Documentation/latest/admin/Wmiconf

interval = <integer>
* How often, in seconds, to poll for new data.
* This attribute is required, and the input will not run if the attribute is
  not present.
* There is no default.

View solution in original post

0 Karma
Highlighted

Re: Remote event log collections polling

Path Finder

Doh! I knew that I knew the answer before posting the question.

It's in the config file but not in the UI.

Thank you.

0 Karma