Splunk Search

Polling Interval

tympaniplayer
Path Finder

Will changing the polling interval of my remote data help in reducing the amount of data indexed in a day?

I am hoping to bring down my daily indexed volume so we don't have to pay an arm and a leg

0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

People frequently reduce polling intervals, or even completely disable inputs due to licensing constraints. While this is not ideal, it is not always possible to obtain the additional funds necessary to procure additional license volume. As such, choices need to be made about how to deal with this situation. Sometimes there is data being collected that isn't valuable, and people can route that data to the nullQueue as it is mixed in with valuable data. Other times polling intervals are reduced, as is the granularity of the data collected.

twkan
Splunk Employee
Splunk Employee

It is important to note that changing the polling interval will affect the granularity of your data, that is if you set an interval that is too long it may affect the ability for you to make sense of what is going on. From a Splunk administrator perspective, I will never sacrifice data loss due to commercial issues, and will simply upgrade to a bigger license if I need to. If I can't produce the data needed by the business, I'm going to get screwed, and nobody is going to thank me for scrimping on the license costs. This is the reality.

tympaniplayer
Path Finder

even from changing every few seconds to once a minute?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...