Dashboards & Visualizations

How do I access data in Splunk via PowerBi?

hgarnica
Engager

I have a local install of SPlunk Enterprise 9.0.4.1 64bit, I installed the 64bit ODBC Driver and configured the data source. 

I then go to PowerBi to GetData via ODBC, I get a list of tables. When I select a table some data visible while some tables generate an error as follows:

DataSource.Error: ODBC: ERROR [HY000] [Splunk][SplunkODBC] (140) The saved search returned no results.
Details:
DataSourceKind=Odbc
DataSourcePath=dsn=Splunk ODBC
OdbcErrors=[Table]

I do not see find my data or field extractions from Splunk. Any ideas?

Screenshot 2023-05-09 094935.jpgScreenshot 2023-05-09 095033.jpg

Labels (1)
Tags (1)
0 Karma
1 Solution

hgarnica
Engager

You were correct, my search report needed modification in Splunk. Thereafter I was able to see the Table in PowerBi that was named the same as my Saved Search Report.

 

Thanks again, Hector

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Sometimes it's normal for a search to return no results.  It may be that there is no data that meets the search criteria.  This is especially true for searches that look for error conditions.

Have you tried running the search within Splunk to see what it returns?

---
If this reply helps you, Karma would be appreciated.
0 Karma

hgarnica
Engager

You were correct, my search report needed modification in Splunk. Thereafter I was able to see the Table in PowerBi that was named the same as my Saved Search Report.

 

Thanks again, Hector

srinivasmanikan
Engager

Hey hgarnica,

i have the same issue, like i was not able to run the search from powerbi, what type of modifications or permissions i need to provide and how will be the sample url for connecting the splunk as i was using it with https://hostname:8089 --> do we need to give any specific app names like that.

Thanks in-advance for awaiting for your response.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...