Getting Data In

Windows WMI configuration

phoenixsecure
Engager

Hi,

Is there a way to configure how Splunk get the data from WMI for event logs, ex: how often Splunk check the host for logs, when, bandwith max etc.

Thanks.

Tags (2)
1 Solution

the_wolverine
Champion

You can configure the polling interval when configuring your WMI input via UI or by editing the wmi.conf file directly. Read the Monitor WMI data section of the documentation for more details about what is configurable and examples:

View solution in original post

Ledio_Ago
Splunk Employee
Splunk Employee

The collection of Windows Event Logs via WMI is done in a interval, every 10 seconds by default. This is configurable.

Currently there is not limit on the bandwidth, but that's a good idea and worth looking into it.

Thank you!

0 Karma

the_wolverine
Champion

You can configure the polling interval when configuring your WMI input via UI or by editing the wmi.conf file directly. Read the Monitor WMI data section of the documentation for more details about what is configurable and examples:

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...