Splunk Search

Polling Interval

tympaniplayer
Path Finder

Will changing the polling interval of my remote data help in reducing the amount of data indexed in a day?

I am hoping to bring down my daily indexed volume so we don't have to pay an arm and a leg

0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

twkan
Splunk Employee
Splunk Employee

It is important to note that changing the polling interval will affect the granularity of your data, that is if you set an interval that is too long it may affect the ability for you to make sense of what is going on. From a Splunk administrator perspective, I will never sacrifice data loss due to commercial issues, and will simply upgrade to a bigger license if I need to. If I can't produce the data needed by the business, I'm going to get screwed, and nobody is going to thank me for scrimping on the license costs. This is the reality.

tympaniplayer
Path Finder

even from changing every few seconds to once a minute?

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...