/** * Splunk connector. * * Thin REST wrapper over the Splunk search-job API. The official Node SDK * is sparsely maintained, so we use fetch directly: * 1. POST /services/search/jobs → search job sid * 2. GET /services/search/jobs/{sid} → poll `isDone` * 3. GET /services/search/jobs/{sid}/results?offset=N&count=1000 → paginate * * Auth: `SPLUNK_HOST` + `SPLUNK_TOKEN` (bearer). Also honors `~/.splunkrc` * which users of the Splunk CLI often have set up. */ import type { SiemConnector } from './index.js'; /** * Stratified-sampling bucket count for Splunk pulls. Lower than the other * connectors on purpose: Splunk dispatches one search job per bucket and the * search head's default per-user concurrency cap is 6. * * Exported for the offline export-plan emitter, which must draw the same * sample this connector draws. See CLOUDWATCH_BUCKET_COUNT. */ export declare const SPLUNK_BUCKET_COUNT = 12; /** Results page size used against `search/jobs/{sid}/results`. */ export declare const SPLUNK_PAGE_SIZE = 1000; export declare const splunkConnector: SiemConnector;