I installed Splunk on a Windows DC and configured it as Light Forwarder to send the events to a linux based Splunk Indexer / Search.
Now, I would like to forward the events from the Windows Server for every 15 minutes. Presently any event that is generated on the server are going in realtime.
How can i configure the above?
You might do so by accessing the events through scripted WMI inputs instead of EventLog monitoring. That way you could set a time interval.
The whole point about splunk "monitor" is speed, so I don't think it is possible to tune it down and have it poll logs every 15 minutes.
If you want to limit network usage, you can tune the limits.conf file.