Splunk Search

Polling Interval

tympaniplayer
Path Finder

Will changing the polling interval of my remote data help in reducing the amount of data indexed in a day?

I am hoping to bring down my daily indexed volume so we don't have to pay an arm and a leg

0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

twkan
Splunk Employee
Splunk Employee

It is important to note that changing the polling interval will affect the granularity of your data, that is if you set an interval that is too long it may affect the ability for you to make sense of what is going on. From a Splunk administrator perspective, I will never sacrifice data loss due to commercial issues, and will simply upgrade to a bigger license if I need to. If I can't produce the data needed by the business, I'm going to get screwed, and nobody is going to thank me for scrimping on the license costs. This is the reality.

tympaniplayer
Path Finder

even from changing every few seconds to once a minute?

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...