Splunk® ODBC Driver

Install and Use Splunk ODBC Driver

This documentation does not apply to the most recent version of Splunk® ODBC Driver. For documentation on the most recent version, go to the latest release.

Use the driver with Microsoft Excel

The Splunk ODBC Driver is not supported on Splunk platform versions 7.x. Upgrading your Splunk platform to 7.x can cause breaking changes to the Splunk ODBC Driver.

You can access Splunk Enterprise data from Microsoft Excel 2010 and 2013 (32-bit or 64-bit) using the Splunk ODBC Driver version 1.0 and later.

To use the Splunk ODBC Driver to get Splunk data into Microsoft Excel:

  1. Open a new worksheet in Excel.
  2. Click the Data tab.
  3. In the Get External Data group, click From Other Sources, and click From Microsoft Query.
  4. In the Choose Data Source window, click Splunk ODBC.
  5. Select the Use the Query Wizard to create/edit queries checkbox.
  6. Click OK.

Microsoft Query connects to your Splunk Enterprise server.

Note: Using the Query Wizard is the supported method for creating queries with Excel.

The Choose Columns window of the Query Wizard appears after Microsoft Query opens.

The tables listed in the Available tables and columns pane map to the saved searches you created in Splunk.

Msquery1.jpg

Expand or collapse a table:

  • Click the plus sign (+) or the minus sign (-) next to the table name.

Move columns into the query:

  • Click the name of the column (each of which corresponds to a field in Splunk) in the left pane, and click the > button to move it to the query.

Change the order of columns in the query:

  • In the right pane, click the column name, and click the up or down arrow button to move it up or down, respectively.

Remove columns from the query:

  • Click the column name in the right pane, and click the < button to remove it.

Note: Table joins are not supported. Add columns from just one table to the query. Otherwise, the following error dialog box appears.

Msqueryjoinsuppt0.jpg

When you're done choosing columns, click Next. The Filter Data window of the Query Wizard appears. The columns that you chose appear in the left pane.

Filter results:

  1. Choose the column to filter from the left pane.
  2. Specify criteria to filter on in the right pane. For example, in the screen shot, we included only rows in the category_id column that do not equal GIFTS.

Msquery2.jpg

When you're done adding filter criteria, click Next. The Sort Order window of the Query Wizard appears. In this window, you choose how to sort the results that Splunk returns.

Specify how to sort data:

  1. Choose a column name from the list box under Sort by to sort on that column.
  2. Specify any secondary sorting in the next list box, and so on.

When you're done choosing sorting order, click Next. The Finish window of the Query Wizard appears. You can either return the data to Excel or to view or edit the query in Microsoft Query. Choose an option, and click Finish.

Msquery3.jpg

If you chose the first option, the data that corresponds to the options you chose will be returned to Excel. If you see the error message "The query returned no results" after you click Finish, your criteria was too specific, or in some other way did not select any results. Click OK, and click Back a few times to reenter your search criteria.

For more information, see "Use the Query Wizard to define a query" on the Microsoft Office website.

Last modified on 19 October, 2018
Load Balancer Configuration   Use the driver with Tableau

This documentation applies to the following versions of Splunk® ODBC Driver: 2.1.0, 2.1.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters