Splunk® Cloud Gateway (Legacy)

Install and Administer Splunk Cloud Gateway

Acrobat logo Download manual as PDF


Splunk Cloud Gateway is a legacy app as of version 1.13.2. To register mobile devices and configure your Splunk Connected Experiences deployment, use Splunk Secure Gateway. See the Splunk Secure Gateway documentation to learn more.
Acrobat logo Download topic as PDF

Set up MDM and in-app registration for iOS devices

You can scale app delivery to a large number of mobile devices, secure content access, and manage data on mobile devices with Mobile Device Management (MDM). With admin setup in Splunk Cloud Gateway and a compatible MDM provider, users can register and authenticate their devices directly in the mobile app with their Splunk credentials. Users won't need access to Splunk Cloud Gateway.

MDM and in-app registration are currently available for the following Connected Experiences apps:

  • Splunk Mobile for iOS
  • Splunk Mobile for Android
  • Splunk AR for iOS

The Connected Experiences apps support MDM providers that are part of the AppConfig community. This includes, but isn't limited to, InTune, MobileIron, VMware AirWatch, IBM, and Citrix.

See the AppConfig website for the iOS and Android standards and check with your MDM provider to see if they follow these standards.

To set up MDM and in-app registration for Splunk Mobile for Android users, see Set up MDM and In-app registration for Android devices.

To set up in-app registration and distribute a Connected Experiences mobile app using MDM, take the following steps:

  1. Add a supported Connected Experiences app to your compatible MDM provider.
  2. Generate or retrieve instance ID files from all of the Splunk instances that you want your mobile device users to have access to.
    1. If you're providing your users access to multiple instances, combine the instance ID files into a single instance ID file using the concatenation feature in Splunk Cloud Gateway.
  3. Add the contents of the instance ID file as a custom app configuration for the Connected Experiences mobile app in your MDM provider.

For more details about MDM features and how the in-app device registration process works, see About Mobile Device Management and In-app registration.

Prerequisites and requirements

MDM and in-app registration are currently available for the following Connected Experiences apps:

  • Splunk Mobile for iOS
  • Splunk Mobile for Android
  • Splunk AR for iOS

Complete the following prerequisites before you deploy a Connected Experiences mobile app with MDM and in-app registration:

Steps

Complete the following steps to deploy a Connected Experiences app at scale with MDM and in-app registration.

Add an iOS Connected Experiences app to your MDM provider

Add the mobile app as a native public app from the App Store. See your MDM provider documentation for instructions on how to add an app.

Generate or retrieve instance ID files

Get instance ID files from Splunk Cloud Gateway on all of the Splunk instances that you want to register users to. If you've already generated an instance ID file, retrieve the existing instance ID file. If this is the first time you're getting an instance ID file, generate a new instance ID file. If you want to reset your MDM encryption and signing keys, renew the instance ID file.

Generating a new instance ID file overwrites the previous MDM signing key. Users who haven't registered using the previously deployed mobile app can't register until they receive the new MDM signing key. You must recombine the instance ID files and upload the new combined file as a configuration to your MDM provider for users to register their devices.

If this is your first time getting an instance ID file, or if you want to renew your instance ID file, complete the following steps:

  1. Log into the Splunk instance that you want to register users to.
  2. Navigate to the Configure tab of Splunk Cloud Gateway.
  3. If you're getting an instance ID file for the first time, select Generate Instance ID File. If you're renewing an instance ID file, select Renew Instance ID File.


If you've already generated an instance ID file for this instance, complete the following steps to retrieve it: If this is your first time getting an instance ID file, or if you want to renew your instance ID file, complete the following steps:

  1. Log into the Splunk instance that you want to register users to.
  2. Navigate to the Configure tab of Splunk Cloud Gateway.
  3. Click Get Existing Instance ID File.

The instance ID file contains the instance's Splunk Cloud Gateway public encryption and signing, Cloud Gateway ID, and MDM signing private key. The files allow the mobile client to identify your Splunk instance.

Combine instance ID files

If you're providing your users access to more than one Splunk instance, combine the instance ID files in Splunk Cloud Gateway. If you're providing users access to just one instance, you can skip this step.

  1. On any of the Splunk instances that you generated an instance ID file with, navigate to the Configure tab of Splunk Cloud Gateway.
  2. Upload all of the instance ID files.
  3. Click Combine Instance ID Files.

Splunk Cloud Gateway runs a script that combines the instance ID files into a single instance ID file.

Configure the mobile app for in-app registration

Add a custom app configuration to add the mobile app to your AppConfig-compatible MDM service.

If you're using MobileIron, use the custom app configuration iOS Managed App Configuration.

If you're using another AppConfig MDM service, follow your provider's documentation to set a configuration for the mobile app.

After selecting a configuration, add the instance ID information as a key value pair. Use the following information to complete the key-value fields:

  • Key: server_config
  • Value: The contents of the single or combined instance ID file from Splunk Cloud Gateway
  • Value type: String

Distribute the mobile app to your iOS device users

Follow your MDM provider's instructions to distribute the mobile app to your users.

User registration

When a user launches the Connec, they select from a list of Cloud Gateway IDs that represent the Splunk instances that instance ID files are generated from. Mobile users can select a Cloud Gateway ID and register to that instance using their Splunk credentials. See Use SAML authentication with Mobile Device Management (MDM) for registration documentation.

(Optional) Use MDM with SAML authentication

You can use MDM with SAML authentication to secure your Connected Experiences app deployment. See Use SAML authentication with Mobile Device Management (MDM) for more information.

Last modified on 12 November, 2020
PREVIOUS
About MDM and In-app Registration
  NEXT
Set up MDM and In-app registration for Android devices

This documentation applies to the following versions of Splunk® Cloud Gateway (Legacy): 1.12.4, 1.13.0, 1.13.2, 1.13.3


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters