<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you send events from a custom command asynchronously without waiting for the whole command to finish? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376560#M110545</link>
    <description>&lt;P&gt;Yes, I did set this to be a streaming command.&lt;/P&gt;

&lt;P&gt;I noticed this in the docs you sent :&lt;EM&gt;Streaming commands typically filter, augment, or update, search result records. Splunk will send them in batches of up to 50,000 records.&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Does this mean that I will only see the first batch after yielding 50,000 events? If so, how can I change that number to be much less than that? (~100) @sduff&lt;/P&gt;</description>
    <pubDate>Tue, 06 Nov 2018 05:48:47 GMT</pubDate>
    <dc:creator>yogevyuval</dc:creator>
    <dc:date>2018-11-06T05:48:47Z</dc:date>
    <item>
      <title>How do you send events from a custom command asynchronously without waiting for the whole command to finish?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376558#M110543</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a custom generating command that queries an external API and yields the results as events.&lt;/P&gt;

&lt;P&gt;As the API gives me the results in chunks and can be slow sometimes, I would like to be able to see the yielded events that I got so far in the Splunk interface, and have incoming events continue to be appended — Just like when I search a big index, and the events seems to be "streamed" to Splunk when they are ready while the search is working. Then, I can see some of the results before the entire search is ready.&lt;/P&gt;

&lt;P&gt;Currently, what is happening is that I see no results until the command finishes entirely, and then I see all of the events at once.&lt;BR /&gt;
If my API sends me 100 events over 10 seconds, I would like to see some of the events immediately.&lt;/P&gt;

&lt;P&gt;I thought that this happens automatically when I use the generator and &lt;CODE&gt;yield&lt;/CODE&gt; pattern, but it seems that it's not the case.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2018 15:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376558#M110543</guid>
      <dc:creator>yogevyuval</dc:creator>
      <dc:date>2018-11-05T15:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do you send events from a custom command asynchronously without waiting for the whole command to finish?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376559#M110544</link>
      <description>&lt;P&gt;When you created your custom command, did you specify that it should be a &lt;CODE&gt;streaming&lt;/CODE&gt; command?&lt;BR /&gt;
&lt;A href="http://dev.splunk.com/view/python-sdk/SP-CAAAEU2#streamingcommand"&gt;http://dev.splunk.com/view/python-sdk/SP-CAAAEU2#streamingcommand&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/DocumentationStatic/PythonSDK/1.6.5/searchcommands.html#splunklib.searchcommands.StreamingCommand"&gt;http://docs.splunk.com/DocumentationStatic/PythonSDK/1.6.5/searchcommands.html#splunklib.searchcommands.StreamingCommand&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 01:30:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376559#M110544</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2018-11-06T01:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do you send events from a custom command asynchronously without waiting for the whole command to finish?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376560#M110545</link>
      <description>&lt;P&gt;Yes, I did set this to be a streaming command.&lt;/P&gt;

&lt;P&gt;I noticed this in the docs you sent :&lt;EM&gt;Streaming commands typically filter, augment, or update, search result records. Splunk will send them in batches of up to 50,000 records.&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Does this mean that I will only see the first batch after yielding 50,000 events? If so, how can I change that number to be much less than that? (~100) @sduff&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 05:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-send-events-from-a-custom-command-asynchronously/m-p/376560#M110545</guid>
      <dc:creator>yogevyuval</dc:creator>
      <dc:date>2018-11-06T05:48:47Z</dc:date>
    </item>
  </channel>
</rss>

