Dashboards & Visualizations

How do I access data in Splunk via PowerBi?

hgarnica
Engager

I have a local install of SPlunk Enterprise 9.0.4.1 64bit, I installed the 64bit ODBC Driver and configured the data source. 

I then go to PowerBi to GetData via ODBC, I get a list of tables. When I select a table some data visible while some tables generate an error as follows:

DataSource.Error: ODBC: ERROR [HY000] [Splunk][SplunkODBC] (140) The saved search returned no results.
Details:
DataSourceKind=Odbc
DataSourcePath=dsn=Splunk ODBC
OdbcErrors=[Table]

I do not see find my data or field extractions from Splunk. Any ideas?

Screenshot 2023-05-09 094935.jpgScreenshot 2023-05-09 095033.jpg

Labels (1)
Tags (1)
0 Karma
1 Solution

hgarnica
Engager

You were correct, my search report needed modification in Splunk. Thereafter I was able to see the Table in PowerBi that was named the same as my Saved Search Report.

 

Thanks again, Hector

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Sometimes it's normal for a search to return no results.  It may be that there is no data that meets the search criteria.  This is especially true for searches that look for error conditions.

Have you tried running the search within Splunk to see what it returns?

---
If this reply helps you, Karma would be appreciated.
0 Karma

hgarnica
Engager

You were correct, my search report needed modification in Splunk. Thereafter I was able to see the Table in PowerBi that was named the same as my Saved Search Report.

 

Thanks again, Hector

srinivasmanikan
Engager

Hey hgarnica,

i have the same issue, like i was not able to run the search from powerbi, what type of modifications or permissions i need to provide and how will be the sample url for connecting the splunk as i was using it with https://hostname:8089 --> do we need to give any specific app names like that.

Thanks in-advance for awaiting for your response.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...