Tableau connection issue with Splunk ODBC 2.1.1 After Upgrading Splunk to 7.1 from 7.0
We are having a Tableau connection Issue with Splunk ODBC 2.1.1 after Upgrading Splunk to 7.1 from 7.0. Every time we upgraded before, we didn't have an issue.
I'm not sure if there was a big change from 7.0 to 7.1.2 but for some reason we are now getting errors on our Tableau.
We tried downgrading to ODBC 2.0 and 2.1.0 , but that didn't work.
Here's the error from =Tableau refresh.
com.tableausoftware.nativeapi.dll.TableauException: [Splunk][SplunkODBC] (60) Unexpected response from server. Veriy the server URL. Error parsing JSON: Text only contains white space(s)
Not sure what changed or what release notes
The Web Data Connector doesn't look like it can work with SSIS. We rely on the ODBC connection for a number of metrics reports and long term trending. Our company is planning the upgrade to 7.x, so we need this connectivity soon.
@sudoritz I understand your concerns, ODBC seem to have some issues with newer version of splunk, which hopefully shall be fixed in next release.
BUT the good news is that Splunk's FDSE team has developed Splunk Tableau WDC (web data connector).
Splunk Tableau WDC is an alternative solution to
get data from Splunk to Tableau!
Let us know if you have any further questions.
Hope this helps answer your question!
The JDBC driver for Splunk has setup instructions provided by the Splunk team https://unityjdbc.com/splunk/setup/SplunkSolutionsTeamUnityJDBCSetup.pdf. The licensed version has a cost but there is a free trial.
The WDC doesn't have the ability to send the data in the datatype they are. If it is a date it appears as string same with numeric and other fields. WDC is a partial solution not complete, I still hope that you guys make updated versions of ODBC.
The Tableau WDC is kind of clunky where if you make a change on your saved search you have to regenerate WDC and doesn't feel where you can just see all your searches/reports .
i heard of JDBC driver but having to pay for something that is broke and splunk cant support when it used to work.
wish there was more movement on this too.
i had to spin up a 7.0 so this would work but there comes a time where it might even fail here.
whats funny is the JSON payload from 7.1+ response via 8089 has alot of blank spaces in front of the query where 7.0 doesnt so not sure if on splunk end can actually fix that if looking deep into the query.