JDBC Driver for Splunk

Build 26.0.9770

Establishing a Connection

Creating a JDBC Data Source

You can create a JDBC data source to connect from your Java application using the CData JDBC Driver for Splunk.

Follow these steps:

  1. Add the driver JAR file to the classpath. The JAR file is located in the installation directory's lib subfolder. Ensure that the .lic file is located in the same folder as the JAR file.
  2. Provide the driver class. For example:
    cdata.jdbc.splunk.SplunkDriver
  3. Provide the JDBC URL. For example:
    jdbc:splunk:user=MyUserName;password=MyPassword;URL=MyURL;

    Or, if there is a conflict in your application between drivers using the same URL format, use this form to ensure that you are using the CData driver:

    jdbc:cdata:splunk:user=MyUserName;password=MyPassword;URL=MyURL;

    Ensure that the URL starts with either jdbc:splunk: or jdbc:cdata:splunk:. The URL can include any of the connection properties in name-value pairs separated with semicolons.

Connecting to Splunk APIs

You must specify the URL to a valid Splunk server. By default the driver makes requests on port 8089.

By default, the driver attempts to negotiate TLS/SSL with the server. For more information on TLS/SSL configuration, see SSL Configuration.

Authenticating to Splunk

There are three ways to authenticate to Splunk: logging in with Splunk credentials, using a Splunk authentication token, or using an HTTP Event Collector (HEC) token. The HTTP Event Collector token is a special-purpose option that works with only a single stored procedure; review its requirements below before you select it.

Splunk Credentials

To authenticate with Splunk credentials, set User and Password to your login credentials.

Splunk Token

When you access Splunk via an authentication token, you can access the Splunk platform using Representational State Transfer (REST) calls. On Splunk Enterprise, you can also use the CLI. Both of these methods enable you to access the instance and make requests without having to authenticate via credentials.

Note: Unless you are accessing a search head cluster (where you can use the same token to access all available head clusters), you must have a separate token for each instance being accessed.

To authenticate with a Splunk token:

  1. In the Splunk UI, navigate to Users and Authentication > Tokens to access your assigned authentication token. If you do not have one, request one from the administrator of the instance you want to access.
  2. Set AuthScheme to AccessToken and the AccessToken property to your Splunk token.

HTTP Event Collector Token

The HTTP Event Collector (HEC) token authentication scheme is used exclusively to send events to Splunk through the HTTP Event Collector. When you set AuthScheme to HTTPEventCollectorToken, the driver can only call the CreateHTTPEvent stored procedure. You cannot query tables or views, run searches, or perform any other operation with this authentication scheme.

Before you use this authentication scheme, the HTTP Event Collector must be enabled on your Splunk instance, and the IP address of the machine running the driver (or, in a hosted environment, the egress IP addresses of the host) must be allowed in the HTTP Event Collector configuration on the Splunk side. Otherwise, requests are rejected.

To authenticate with an HTTP Event Collector token:

  1. In the Splunk UI, navigate to Data Inputs > HTTP Event Collector to create or locate your token. If the collector is disabled, enable it and confirm that your client IP address is allowed.
  2. Set AuthScheme to HTTPEventCollectorToken and set HTTPEventCollectorToken to your token value.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770