Configuring a Connection
After Installing the Connector you can connect and create a Data Source for data in Splunk.
Setting Up a Data Source
Complete the following steps to connect to the data:
- Under Connect | To a Server, click More....
- Select the data source called Splunk by CData.
- Enter the information required for the connection.
- Click Sign In.
- If necessary, select a Database and Schema to discover what tables and views are available.
Using the Connection Builder
The connector makes the most common connection properties available directly in Tableau. However, it can be difficult to use if you need to use more advanced settings or need to troubleshoot connection issues. The connector includes a separate connection builder that allows you to create and test connections outside of Tableau.
There are two ways to access the connection builder:
- On Windows, use a shortcut called Connection Builder in the Start menu, under the CData Tableau Connector for Splunk folder.
- You can also start the connection builder by going to the driver install directory and running the .jar file in the lib directory.
In the connection builder, you can set values for connection properties and click Test Connection to validate that they work. You can also use the Copy to Clipboard button to save the connection string. This connection string can be given to the Connection String option included in the connector connection window in Tableau.
Connecting to Splunk APIs
You must specify the URL to a valid Splunk server. By default the connector makes requests on port 8089.
By default, the connector attempts to negotiate TLS/SSL with the server. For more information on TLS/SSL configuration, see SSL Configuration.
Authenticating to Splunk
There are three ways to authenticate to Splunk: logging in with Splunk credentials, using a Splunk authentication token, or using an HTTP Event Collector (HEC) token. The HTTP Event Collector token is a special-purpose option that works with only a single stored procedure; review its requirements below before you select it.
Splunk Credentials
To authenticate with Splunk credentials, set User and Password to your login credentials.
Splunk Token
When you access Splunk via an authentication token, you can access the Splunk platform using Representational State Transfer (REST) calls. On Splunk Enterprise, you can also use the CLI. Both of these methods enable you to access the instance and make requests without having to authenticate via credentials.
Note: Unless you are accessing a search head cluster (where you can use the same token to access all available head clusters), you must have a separate token for each instance being accessed.
To authenticate with a Splunk token:
- In the Splunk UI, navigate to Users and Authentication > Tokens to access your assigned authentication token. If you do not have one, request one from the administrator of the instance you want to access.
- Set AuthScheme to AccessToken and the AccessToken property to your Splunk token.
HTTP Event Collector Token
The HTTP Event Collector (HEC) token authentication scheme is used exclusively to send events to Splunk through the HTTP Event Collector. When you set AuthScheme to HTTPEventCollectorToken, the connector can only call the CreateHTTPEvent stored procedure. You cannot query tables or views, run searches, or perform any other operation with this authentication scheme.
Before you use this authentication scheme, the HTTP Event Collector must be enabled on your Splunk instance, and the IP address of the machine running the connector (or, in a hosted environment, the egress IP addresses of the host) must be allowed in the HTTP Event Collector configuration on the Splunk side. Otherwise, requests are rejected.
To authenticate with an HTTP Event Collector token:
- In the Splunk UI, navigate to Data Inputs > HTTP Event Collector to create or locate your token. If the collector is disabled, enable it and confirm that your client IP address is allowed.
- Set AuthScheme to HTTPEventCollectorToken and set HTTPEventCollectorToken to your token value.
Next Step
See Using the Connector to create data visualizations.