Splunk® Secure Gateway

Release Notes

Splunk Secure Gateway is a default enabled application that's included in Splunk Cloud version 8.1.2103 and Splunk Enterprise version 8.1.0 and higher. An admin must agree to the opt-in notice before using Splunk Secure Gateway. See Get started with Splunk Secure Gateway to get started.
This documentation does not apply to the most recent version of Splunk® Secure Gateway. For documentation on the most recent version, go to the latest release.

Visualization support for the Connected Experiences apps

These are the current supported and unsupported dashboard visualizations and features for the Connected Experiences apps and the latest version of Splunk Secure Gateway. If your dashboard isn't loading, it may contain an unsupported visualization or you might be using an outdated Splunk Secure Gateway version.

To check if a dashboard contains any visualizations or configurations that the Connected Experiences apps don't support, see Editing Simple XML in the Splunk Enterprise Dashboards and Visualizations manual.

Supported and unsupported dashboard and visualization and configurations

Keep in mind the following points when creating dashboards and visualizations for the Connected Experiences apps:

  • Visualizations with more than 3,000 data points take a long time to load. To load visualizations faster, you can increase the sample ratio to adjust the number of data points. See Specify a sampling ratio in the Splunk Enterprise Search Manual for more information on activating event sampling.
  • Dashboards in the Connected Experiences apps display one title. If your dashboard has both an object title and a panel title, the dashboard displays the object title.
  • By default, Splunk Enterprise displays visualizations in panels. Visualizations must have the panel tag in order to display in the Connected Experiences apps. If you remove the panel tag from the dashboard XML, the visualization will not display in the Connected Experiences apps.
  • The Connected Experiences apps don't support HTML elements.

The following table lists the supported visualizations and the supported and unsupported configurations for each visualization for the Connected Experiences apps.

Trellis visualizations require setting the value of the "trellis.splitby" option to the desired result field name in the dashboard XML. See Configure trellis layout in Simple XML in the Splunk Enterprise ''Dashboards and Visualizations'' manual.

Supported visualization Supported configurations Unsupported configurations
Area
  • Axis scale
  • Axis minimum and maximum
  • Axis visibility
  • Second axis range
  • Second axis scale
  • Stackmode (default, stacked, and stacked 100%)
  • Data labels (all, minimum, maximum, none)
  • Null values
  • Trellis
  • Multi-series charts
  • Legend placement
  • Overlay fields
Bar
  • Axis visibility
  • Axis min/max
  • Axis scale
  • Stackmode (default, stacked, and stacked 100%)
  • Data labels (all, min, max, none)
  • Trellis
  • Multi-series charts
  • Legend placement
  • Overlay fields
Bubble
  • Axis visibility
  • Axis min/max
  • Axis scale
  • Multi-series charts
  • Legend placement
Column
  • Axis visibility
  • Axis min/max
  • Axis scale
  • Second axis range
  • Data labels (all, min, max, none)
  • Trellis
  • Multi-series charts
  • Legend placement
  • Overlay fields
Line
  • Second y-axis for overlays
  • Y-axis fields for overlays
  • Second axis range
  • Second axis scale
  • Data labels (all, min, max, none)
  • Trellis
  • Multi-series mode
  • Legend placement
  • Overlay fields
Filler Gauge
  • Chart range values
  • Chart orientation
  • Trellis
Marker Gauge
  • Chart range values
  • Trellis
Radial Gauge
  • Chart range values
  • Trellis
Pie
  • Collapsing label
  • Collapsing threshold
  • Percentage labels
Scatter
  • Axis min/max
  • Axis scale
  • Multi-series charts
  • Legend placement
Single value
  • Unit
  • Color thresholding
  • Trend indicator
  • Trellis
Table
  • Pagination
Map
  • Cluster
  • Choropleth

App-specific limitations

Splunk AR, Splunk TV, and Splunk Mobile for Apple Watch have the following visualization limitations:

Splunk AR limitations

  • Splunk AR does not support drilldown or dynamic form inputs.
  • Splunk AR supports maps in non-AR dashboards. Splunk AR does not support maps in AR workspaces.

Splunk TV limitations

  • Splunk TV does not support drilldown.

Splunk Mobile for iOS limitations

  • Cloud Monitoring Console (CMC) dashboards require any version of Splunk Secure Gateway and Splunk Mobile for iOS version 2.10.1 or higher.

Splunk Mobile for Android limitations

  • Cloud Monitoring Console (CMC) dashboards require any version of Splunk Secure Gateway and Splunk Mobile for Android version 2020.10.28 or higher.

Splunk Mobile for Apple Watch limitations

  • Splunk Mobile for Apple Watch supports only line charts, bar charts, pie charts, and single value visualizations.
  • Due to WatchOS limitations, visualizations pinned to your watch face do not follow any refresh intervals defined in dashboard XML.

Token limitations

The following are limitations for token usage in visualizations in the Connected Experiences apps:

Dynamic form inputs

Only Splunk Mobile and Splunk TV support dynamic form inputs. Checkbox, dropdown, multiselect, radio, text, and time picker form inputs are supported.

The following are limitations for dynamic form inputs in the Connected Experiences apps:

  • The Connected Experiences apps might experience issues with more than 200 drop-down options with a dynamic form input.
  • The Splunk Connected Experiences apps do not support conditional form input action tokens.

Drilldown

Drilldown in the Connected Experiences apps has the following limitations:

  • Only Splunk Mobile supports drilldown. Splunk AR does not support drilldown.
  • Drilldown requires Splunk Secure Gateway or Splunk Cloud Gateway version 1.4.0 or higher.
  • Only single value and table dashboards support drilldown.

This table provides a list of supported and unsupported drilldown configurations:

Supported drilldown configurations Unsupported drilldown configurations
  • Only single value and table dashboards support drilldown.
  • Link to URL
    • URL links must be http:// or https://
  • Link to a different dashboard
  • Supported tokens:
    • $click.name$
    • $click.value$
    • $click.name2$
    • $click.value2$
    • $row.<fieldname>$
  • Chart drilldown
  • Link to search
  • Manage token values in the current dashboard in page drilldown
  • Unsupported tokens:
    • $row.<x-axis-name>$
    • $earliest$
    • $latest$
  • Conditional drilldown action tokens
  • Set destination action tokens

Event handler limitations

The Connected Experiences apps don't support event handlers with Splunk Secure Gateway versions lower than 2.5.6.

Splunk Secure Gateway version 2.5.6 and higher offers limited support for event handlers. Only the <done> event handler with the commands set and unset are supported. All other event handlers and their commands are not supported.

Event handler limitations

The Connected Experiences apps don't support event handlers with Splunk Secure Gateway versions lower than 2.5.6.

Splunk Secure Gateway version 2.5.6 and higher offers limited support for event handlers. Only the <done> event handler with the commands set and unset are supported. All other event handlers and their commands are not supported.

Other limitations

The Connected Experiences apps do not support the following features:

  • Glass tables
  • Custom HTML, including D3 visualizations
  • XML dashboards that have been converted to HTML
  • Custom JavaScript
  • The <init> element
  • dbx commands
  • Dashboards from the Splunk Dashboards (beta) app
Last modified on 22 August, 2022
Splunk Secure Gateway release notes   Third-party software credits

This documentation applies to the following versions of Splunk® Secure Gateway: 2.4.0, 2.0.2, 2.5.6 Cloud Only, 2.5.7, 2.6.3 Cloud only


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters