CData Python Connector for Splunk

Build 26.0.9770

Establishing a Connection

The objects available within our connector are accessible from the "cdata.splunk" module. To use the module's objects directly:

  1. Import the module as follows:
    import cdata.splunk as mod
  2. To establish a connection string, call the connect() method from the connector object using an appropriate connection string, such as:
    mod.connect("user=MyUserName;password=MyPassword;URL=MyURL;")

Connecting to Splunk APIs

You must specify the URL to a valid Splunk server. By default the connector makes requests on port 8089.

By default, the connector attempts to negotiate TLS/SSL with the server. For more information on TLS/SSL configuration, see SSL Configuration.

Authenticating to Splunk

There are three ways to authenticate to Splunk: logging in with Splunk credentials, using a Splunk authentication token, or using an HTTP Event Collector (HEC) token. The HTTP Event Collector token is a special-purpose option that works with only a single stored procedure; review its requirements below before you select it.

Splunk Credentials

To authenticate with Splunk credentials, set User and Password to your login credentials.

Splunk Token

When you access Splunk via an authentication token, you can access the Splunk platform using Representational State Transfer (REST) calls. On Splunk Enterprise, you can also use the CLI. Both of these methods enable you to access the instance and make requests without having to authenticate via credentials.

Note: Unless you are accessing a search head cluster (where you can use the same token to access all available head clusters), you must have a separate token for each instance being accessed.

To authenticate with a Splunk token:

  1. In the Splunk UI, navigate to Users and Authentication > Tokens to access your assigned authentication token. If you do not have one, request one from the administrator of the instance you want to access.
  2. Set AuthScheme to AccessToken and the AccessToken property to your Splunk token.

HTTP Event Collector Token

The HTTP Event Collector (HEC) token authentication scheme is used exclusively to send events to Splunk through the HTTP Event Collector. When you set AuthScheme to HTTPEventCollectorToken, the connector can only call the CreateHTTPEvent stored procedure. You cannot query tables or views, run searches, or perform any other operation with this authentication scheme.

Before you use this authentication scheme, the HTTP Event Collector must be enabled on your Splunk instance, and the IP address of the machine running the connector (or, in a hosted environment, the egress IP addresses of the host) must be allowed in the HTTP Event Collector configuration on the Splunk side. Otherwise, requests are rejected.

To authenticate with an HTTP Event Collector token:

  1. In the Splunk UI, navigate to Data Inputs > HTTP Event Collector to create or locate your token. If the collector is disabled, enable it and confirm that your client IP address is allowed.
  2. Set AuthScheme to HTTPEventCollectorToken and set HTTPEventCollectorToken to your token value.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770