The Splunk connector allows the retrieval of data from a running Splunk instance.

Using Splunk

  1. When creating a new data table, select Splunk from the Connect to data dialog. The Splunk Connection dialog is displayed:

  1. Update the Connection Details for the Splunk instance as appropriate (Host, Port, Username and Password).

  1. Select the Application.

  2. Select either a Saved Search from the listing, or Manual and define a new search query.

  3. Select whether the parameters should be automatically enclosed in quotes by checking the Enclose parameters in quotes box.

  4. Change the required Time zone (assuming data is stored in UTC).

  5. Click OK to execute the Splunk data request. The source data is returned in the Edit Data Table view, with the fields displayed in the Data Source Preview.