Splunk Tech Talks
Deep-dives for technical practitioners.

Visualize Splunk data in your favorite BI Tool

melissap
Splunk Employee
Splunk Employee

View our Splunk Tech Talk, Visualize Splunk Data in your Favorite BI Tool , featuring the ODBC Driver to empower all users to quickly create executive facing visualizations using Splunk data in business intelligence tool dashboards.

Tune in to learn about how Splunk’s new release of the ODBC connector allows you to:

  • Enable your business users to analyze and visualize mission critical machine data
  • Expose Splunk data collected from your app and services in a consumable way to a non technical audience
  • Create high quality visualizations of your Splunk data in your favorite BI tool

Check out our Splunk ODBC conversations in Splunk Answers community for more!

melissap
Splunk Employee
Splunk Employee

Hey everyone! We had some great questions during this Tech Talk in June. 

Recapping for all!

Q: The documentation I read indicates that the ODBC driver is for Windows only. Are there plans to make an OSX version?
A: Yes! We are actively working on OSX support. We don't have an ETA at this time but do stay tuned for updates!
 
Q: Is the ODBC driver available for splunk cloud?
A: Yes! The ODBC driver is available for Splunk Cloud 7.3 and higher
 
Q: What type of Splunk instance is this? Full Splunk Enterprise or Heavy forwarder?
A: The ODBC driver is installed on the Windows environment where the BI Tool (in this case Tableau) is installed
 
Q: Where are the ODBC credentials stored? Are they encrypted?
A: The credentials are actually your Splunk login credentials
 
Q: how to connect to splunk cloud ?
A: It's the same process to connect to Splunk Cloud 7.3 ! In the installation process, just point to your Splunk Cloud instance.
 
Q: What about ad-hoc queries for visualization exploration? For example, I may need to reduce my fields because the visualization won't fit. Is there a back and forth with a saved query, or can I do an ad-hoc Splunk query in tableau leveraging the new ODBC driver?
A: The ODBC driver only supports Saved Searches, and not ad-hoc queries. That means you'll need to update the Saved Search to update the query.
 
Q: does the ODBC driver need to be installed on a Search Head?
A: No, the ODBC driver is installed on the Windows environment where your BI Tool is installed.  In the installation process, just point the SHC you want to use.
 
Q: Is there a PowerBI server driver also?
A: Yes, the ODBC driver also works with PowerBI. Check out the Splunk Docs for details on how to set that up. https://docs.splunk.com/Documentation/ODBC/3.0.1/UseODBC/PowerBI
 
 Q: Do you think the ODBC driver could be used to move data to Azure DataLake
A: We haven't tested that specific use case.
melissap
Splunk Employee
Splunk Employee

We also want to make sure you have these additional resources for your journey:

  • Download the ODBC Driver from Splunkbase (Compatible with 7.3 and above; Cloud compatible)
  • Splunk ODBC Driver Documentation (Get step by step details to install and use the ODBC Driver with your BI Tool of choice)
KumarVarun
New Member

@melissap Can you let me know if this connector can be used even in Qlik BI tool to connect to Splunk. What would be the additional configuration etc?

Qlik just has ODBC connector and not a specific Splunk connector like how Tableau has.

melissap
Splunk Employee
Splunk Employee

@KumarVarun 

The Splunk Open Database Connectivity (ODBC) Driver allows a Splunk platform user to connect Microsoft Excel, Tableau Desktop, and Microsoft Power BI (Microsoft Windows machines only) to their Splunk platform deployment through Open Database Connectivity. After installing and configuring the Splunk ODBC driver, you can visualize and report Splunk software data directly from Microsoft Excel, Tableau, or Microsoft Power BI. https://splunkbase.splunk.com/app/4793/

There is a way to connect to Qlik, built by Cdata, over ODBC, just not using a Splunk built driver, but by using a technology partner app built on the same underlying ODBC driver idea. See the link here  https://www.cdata.com/kb/tech/splunk-odbc-qlikview-chart.rst

I will connect with our product team to see what is on the roadmap for ODBC Connector.

KumarVarun
New Member

@melissap 

Thank you so much for the update.

It would be great if you plan on a Splunk integration with Qlik demo in one of the Tech talks.

I'll check with the default Splunk ODBC once and see if i'm able to query Splunk data in Qlik.  I might get back with some questions.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...