How to Visualize Splunk Data in Python with pandas via CData Connect AI

Jerod Johnson
Jerod Johnson
Director, Technology Evangelism
Use the CData Connect AI Python SDK with pandas and Matplotlib to analyze and visualize live Splunk data in Python.

The rich ecosystem of Python modules lets you get to work quickly and integrate your systems more effectively. With the CData Connect AI Python SDK, the pandas and Matplotlib modules, you can build Splunk-connected Python applications and scripts for visualizing Splunk data. This article shows how to connect to Connect AI and use the pandas and Matplotlib built-in functions to query Splunk data and visualize the results.

The Connect AI Python SDK (cdata-connect-ai) is a DB-API 2.0 (PEP 249) compliant client, so pandas can read query results directly from the SDK connection object. There is no driver to install per source and no SQLAlchemy engine to configure: connect with a Personal Access Token and pass the connection straight to pandas.read_sql.

Connect to Splunk in Connect AI

CData Connect AI uses a straightforward, point-and-click interface to connect to data sources.

  1. Log into Connect AI, click Sources, and then click Add Connection
  2. Adding a Connection
  3. Select "Splunk" from the Add Connection panel
  4. Selecting a data source
  5. Enter the necessary authentication properties to connect to Splunk.

    To authenticate requests, set the User, Password, and URL properties to valid Splunk credentials. The port on which the requests are made to Splunk is port 8089.

    The data provider uses plain-text authentication by default, since the data provider attempts to negotiate TLS/SSL with the server.

    If you need to manually configure TLS/SSL, see Getting Started -> Advanced Settings in the data provider help documentation.

    Configuring a connection (Salesforce is shown)
  6. Click Save & Test
  7. Navigate to the Permissions tab and update the user-based permissions. Updating permissions

Generate a Personal Access Token (PAT)

The Python SDK authenticates to Connect AI with your account email and a Personal Access Token (PAT). It is best practice to create a separate PAT for each application to maintain granularity of access.

  1. Click the Gear icon () at the top right of the Connect AI app to open the Settings page.
  2. On the Settings page, go to the Access Tokens section and click Create PAT.
  3. Give the PAT a name and click Create. Creating a new PAT
  4. The PAT is only visible at creation, so copy it and store it securely.

Install Required Modules

Install the SDK (with the pandas extra) and Matplotlib using the pip utility:

pip install "cdata-connect-ai[full]"
pip install matplotlib

Visualize Splunk Data in Python

Import the modules, then connect to Connect AI with your account email and PAT. Identifiers are three-part: <Connection>.<Schema>.<Table>, where the connection name defaults to the source name (for example, Splunk1).

import pandas
import matplotlib.pyplot as plt
import cdata_connect_ai

conn = cdata_connect_ai.connect(
    username="[email protected]",
    password="<your_pat>",
)

Query Splunk with pandas

Use the read_sql function from pandas to execute a SQL statement and store the result set in a DataFrame. Pass the SDK connection directly, no engine required.

df = pandas.read_sql(
    "SELECT Name, Owner "
    "FROM [Splunk1].[Splunk].[DataModels] "
    "WHERE Id = 'SampleDataset'",
    conn,
)

Note: pandas may print a UserWarning stating that it only officially supports SQLAlchemy connectables. This is expected when passing a DB-API connection directly—the query runs correctly and the warning is safe to ignore.

Visualize Splunk Data

With the query results stored in a DataFrame, use the plot function to build a chart. The show method displays the chart in a new window.

df.plot(kind="bar", x="Name", y="Owner")
plt.show()

conn.close()
The Matplotlib chart of the query results (Salesforce is shown)

More Information and Free Trial

Now you can read live Splunk data into pandas through the CData Connect AI Python SDK. For more information on connecting to Splunk (and hundreds of other data sources), visit the Connect AI page. Sign up for a free trial and start working with live Splunk data in Python.



Full Source Code

import pandas
import matplotlib.pyplot as plt
import cdata_connect_ai

conn = cdata_connect_ai.connect(
    username="[email protected]",
    password="<your_pat>",
)

df = pandas.read_sql(
    "SELECT Name, Owner "
    "FROM [Splunk1].[Splunk].[DataModels] "
    "WHERE Id = 'SampleDataset'",
    conn,
)

df.plot(kind="bar", x="Name", y="Owner")
plt.show()

conn.close()

Ready to get started?

Learn more about CData Connect AI or sign up for free trial access:

Free Trial