KNOWLEDGE BASE

Missing Fields in Connection to Splunk


Published: 11 Nov 2014
Last Modified Date: 30 Aug 2016

Issue

When connecting to raw data using a live Splunk connection, some expected fields are not available.

Environment

  • Tableau Desktop
  • Splunk

Resolution

As a workaound: Change the filter on the Splunk side to always include some data in each field.

 

Cause

When Tableau Desktop queries for metadata, it looks at only a small number of rows (100).
The API is designed to (for the sake of preventing bloated payloads) drop any fields that do not contain data.
So, if the customer’s data in Splunk include many rows that are often empty, this unexpected behavior can result.

 

Did this article resolve the issue?