Splunk + Excel. What will happen?
In previous articles, we talked a lot about Splunk . This is a product that allows you to collect and analyze data from any IT system in real time, for example, it can be the results of a web server, mail server , Windows, various applications and so on. Does this mean that if all employees interested in the analysis received at Splunk need to understand the work of the program, make changes to their business processes and do all the analytics only in Splunk? Of course not!
In this article, we show how to make the sales department in a few clicks get a spreadsheet in MS Excel, with up-to-date data on the sale of goods through the online store.
There are two files in the archive: for MSExcel 32-bit, or 64-bit.
The MSExcel version can be viewed on the tab. "File" - "Account" - "About Excel" . Select the required version and run SplunkODBC64.msi or SplunkODBC32.msi.
Begin the installation and create a data source.
Enter the user's login. The password can be left blank and enter each time or check the box that we enter the password now and save it. Enter the URL of the server Splunk Enterprise, port number specify 8089.
Finish the installation.
We check the correctness of the installation.
Open the "ODBC Data Sources" program (Path: C: ProgramDataMicrosoftWindowsStart MenuProgramsAdministrative Tools )
In section "System DSN" there must be a Splunk ODBC driver. By clicking on the name of the driver, you can change its settings: login, password, source address.
Using the driver in Excel
Open the required .xls document. It can be a blank document or already have preliminary information. In our document there is such a table, which we fill, using information from Splunk.
In section "Data" - "Get data" - "From other sources" - "From Microsoft Query" .
We select the data source "Splunk ODBC *", set the "Use the query wizard" check box.
In the query creation window we will see a list of available tables from Splunk.
Select the table and columns saved in the first step.
Next, you can specify a data selection rule, for example, count> 1000. But since we already have a table ready, we leave the conditions empty and click "Next".
Specify the sorting conditions.
We put the condition that you need to return the data to Excel.
We choose the way of data representation.
The data is loaded, and we can update them at any time by pressing the button. «Update all» .
We add the information to the template of the tableUsing the formula: = ESDD (VLP (A: A; Table_Request_of_Splunk_ODBC_1; 3; FALSE); 0)
We get the final result
Thus, by installing and configuring the ODBC driver, you can download the results of any queries stored in Splunk into several clicks in Excel. Conduct, if necessary, their filtering and sorting and get useful data for further analytics in Excel.
We are happy to answer all your questions and comments on this topic. Also, if you are interested in something specifically in this field, or in the field of analyzing machine data as a whole - we are ready to finalize the existing solutions for you, for your specific task. To do this, you can write about this in the comments or simply send us a request through the form on our site .
It may be interesting