/** * Splunk export-plan emitter. * * Mirrors `lib/siem/splunk.ts`: the same 12 stratified sub-windows (12, not * 24, because a Splunk search head's default per-user job concurrency is 6) * and the same per-bucket cap, expressed as `| head ` in the SPL. * * One difference from the connector, and it simplifies the script rather than * changing what it reads: the connector uses the three-call job API (create / * poll / paginate) because it needs progress reporting. A script that only * has to land bytes on disk uses `search/jobs/export`, which streams results * from a single request. With `output_mode=raw` the response IS the log text, * one event per line, so there is no JSON to unwrap and no field-name guess * to get wrong. */ import { type SamplePlan, type SamplePlanOptions } from './_shared.js'; export declare function emitSplunkPlan(opts: SamplePlanOptions): SamplePlan;