Getting Data In

how to use the interval parameter for modular input ?

jzhong_splunk
Splunk Employee
Splunk Employee

Hi All,

I got confused while reading the documentation: http://docs.splunk.com/Documentation/Splunk/6.1.2/AdvancedDev/ModInputsSpec#interval_parameter

It says

Some parameters are always implicitly defined by Splunk. Specifying any of the following parameters for your modular inputs has no effect. However, you could specify these to help clarify the usage: .. interval

Avoid using interval as a parameter. This parameter is reserved by Splunk for future use.

Then

New with Splunk 6, you can optionally specify the interval parameter much as you can with scripted inputs.
Entering an empty value for interval results in a script only being executed on start and/or endpoint reload (on edit).

I tried to write a Java modular input for Splunk6 and use the interval=6000 in the inputs.conf.spec. According to the log, my input is only called once.

Any suggestions?

Tags (3)

schose
Builder

Hi,

The interval for a modular input is defined in inputs.conf stanza for the modular input script script.
If you modular input script is named foobar.py then you can define

inputs.conf
[foobar://myname]
interval=10
myparam1 = true

Then foobar will be executed every 10 seconds.
The documentation is quite misleading.. also have to test it out out while creating a modular input.

Regards,

Andreas

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...