Splunk Search

Polling Interval

tympaniplayer
Path Finder

Will changing the polling interval of my remote data help in reducing the amount of data indexed in a day?

I am hoping to bring down my daily indexed volume so we don't have to pay an arm and a leg

0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

twkan
Splunk Employee
Splunk Employee

It is important to note that changing the polling interval will affect the granularity of your data, that is if you set an interval that is too long it may affect the ability for you to make sense of what is going on. From a Splunk administrator perspective, I will never sacrifice data loss due to commercial issues, and will simply upgrade to a bigger license if I need to. If I can't produce the data needed by the business, I'm going to get screwed, and nobody is going to thank me for scrimping on the license costs. This is the reality.

tympaniplayer
Path Finder

even from changing every few seconds to once a minute?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...