<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fetching data from Splunk Cloud every 5 min over the API in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511506#M124</link>
    <description>I suppose it comes down to how many results your searches find. I search over 5 minutes every minute that ends up with a single results could be fine. You probably should contact Splunk for a definitive answer.</description>
    <pubDate>Wed, 29 Jul 2020 12:35:47 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-07-29T12:35:47Z</dc:date>
    <item>
      <title>Fetching data from Splunk Cloud every 5 min over the API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511374#M121</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;According to&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice&lt;/A&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Data extracted as a result of search query, whether from the UI or REST API is limited to 5% of daily ingest for optimal performance.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Scheduled search is not supported from a hybrid search head.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let's say I want to fetch over the API (not from a hybrid search head, instead of from a third-party system) 5 min worth of data and I schedule that search to run every minute.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I cannot see that that kind of set up would violate the agreement, but I want to make sure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- 5 min worth of data every min will never equal&amp;nbsp;5% of daily ingest...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyone who has done a similar setup successfully?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Many Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jonas&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 15:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511374#M121</guid>
      <dc:creator>Jonas951</dc:creator>
      <dc:date>2020-07-28T15:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching data from Splunk Cloud every 5 min over the API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511399#M122</link>
      <description>By my reckoning, pulling 5 minutes of data every minute equals 600% of daily ingest.</description>
      <pubDate>Tue, 28 Jul 2020 18:57:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511399#M122</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-28T18:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching data from Splunk Cloud every 5 min over the API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511415#M123</link>
      <description>&lt;P&gt;Hi, you are indeed right, 600% as a total.&lt;/P&gt;&lt;P&gt;That is what I cannot get my head around since it says "&lt;SPAN&gt;Data extracted as a result of search query"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My take on that is that every individual search query is not allowed to bring back a dataset larger than 5% of daily ingest.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splitting hairs, I know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS, otherwise it should be "Data extracted as a result of total search queries per day are not allowed to bring back a dataset larger than 5% of daily ingest."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you with me?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Small different in language, but a huge difference in terms of what I can do with my data in Splunk Cloud&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Many thanks for answering my post &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 20:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511415#M123</guid>
      <dc:creator>Jonas951</dc:creator>
      <dc:date>2020-07-28T20:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching data from Splunk Cloud every 5 min over the API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511506#M124</link>
      <description>I suppose it comes down to how many results your searches find. I search over 5 minutes every minute that ends up with a single results could be fine. You probably should contact Splunk for a definitive answer.</description>
      <pubDate>Wed, 29 Jul 2020 12:35:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Fetching-data-from-Splunk-Cloud-every-5-min-over-the-API/m-p/511506#M124</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-29T12:35:47Z</dc:date>
    </item>
  </channel>
</rss>

