Query Splunk Data as a MySQL Database in Node.js



Execute MySQL queries against Splunk data from Node.js.

You can use the SQL Gateway from the ODBC Driver for Splunk to query Splunk data through a MySQL interface. Follow the procedure below to start the MySQL remoting service of the SQL Gateway and start querying using Node.js.

Connect to Splunk Data

If you have not already done so, provide values for the required connection properties in the data source name (DSN). You can use the built-in Microsoft ODBC Data Source Administrator to configure the DSN. This is also the last step of the driver installation. See the "Getting Started" chapter in the help documentation for a guide to using the Microsoft ODBC Data Source Administrator to create and configure a DSN.

To authenticate requests, set the User, Password, and URL properties to valid Splunk credentials. The port on which the requests are made to Splunk is port 8089.

The data provider uses plain-text authentication by default, since the data provider attempts to negotiate TLS/SSL with the server.

If you need to manually configure TLS/SSL, see Getting Started -> Advanced Settings in the data provider help documentation.

Configure the SQL Gateway

See the SQL Gateway Overview to set up connectivity to Splunk data as a virtual MySQL database. You will configure a MySQL remoting service that listens for MySQL requests from clients. The service can be configured in the SQL Gateway UI.

Creating a MySQL Remoting Service in SQL Gateway (Salesforce is shown)

Query Splunk from Node.js

The following example shows how to define a connection and execute queries to Splunk with the mysql module. You will need the following information:

  • Host name or address, and port: The machine and port where the MySQL remoting service is listening for MySQL connections.
  • Username and password: The username and password of a user you authorized on the Users tab of the SQL Gateway.
  • Database name: The DSN you configured for the MySQL remoting service.

Connect to Splunk data and start executing queries with the code below:

var mysql      = require('mysql');
var connection = mysql.createConnection({
  host     : 'localhost',
  database : 'CData Splunk Sys',
  port	   : '3306',
  user     : 'mysql_user',
  password : 'test'
});
connection.connect();
connection.query('SELECT * FROM DataModels', function(err, rows, fields) {
  if (err) throw err;
  console.log(rows);
});

connection.end();

Ready to get started?

Download a free trial of the Splunk ODBC Driver to get started:

 Download Now

Learn more:

Splunk Icon Splunk ODBC Driver

The Splunk ODBC Driver is a powerful tool that allows you to connect with live Splunk, directly from any applications that support ODBC connectivity.

Access Splunk like you would a database - read, write, and update Datamodels, Datasets, SearchJobs, etc. through a standard ODBC Driver interface.