this depends on your needs and environment. Usually ETL is for once a day or maybe once a hour cases. Splunk has targeted mostly online data access and analysis. Based on that I prefer to get ETL data to splunk viaETL system or if possible in real-time when we can forgot ETL limitations. But as. I said it depends on your situation.