Splunk Search

Polling Interval

tympaniplayer
Path Finder

Will changing the polling interval of my remote data help in reducing the amount of data indexed in a day?

I am hoping to bring down my daily indexed volume so we don't have to pay an arm and a leg

0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

twkan
Splunk Employee
Splunk Employee

It is important to note that changing the polling interval will affect the granularity of your data, that is if you set an interval that is too long it may affect the ability for you to make sense of what is going on. From a Splunk administrator perspective, I will never sacrifice data loss due to commercial issues, and will simply upgrade to a bigger license if I need to. If I can't produce the data needed by the business, I'm going to get screwed, and nobody is going to thank me for scrimping on the license costs. This is the reality.

tympaniplayer
Path Finder

even from changing every few seconds to once a minute?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...