Splunk® Secure Gateway

Use Splunk Secure Gateway

Acrobat logo Download manual as PDF


Splunk Secure Gateway is a default enabled application that's included in Splunk Cloud version 8.1.2103 and Splunk Enterprise version 8.1.0 and higher. An admin must agree to the opt-in notice before using Splunk Secure Gateway. See Get started with Splunk Secure Gateway to get started.
Acrobat logo Download topic as PDF

Log in to a Splunk platform instance in a Connected Experiences app

Register your mobile device or TV using Splunk Secure Gateway to log in to a Splunk platform instance and view dashboards in augmented reality.

Prerequisites

See the following options for how you can log in to a Splunk Platform instance in a Connected Experiences app:

If you run into issues during registration, see Troubleshoot Splunk Secure Gateway performance issues in the Administer Splunk Secure Gateway manual.

Log in with an authentication code using Splunk Secure Gateway

To log in, you must have the securegateway role. You do not need the admin role to log in.

  1. In the Register tab in Splunk Secure Gateway, enter the 10-digit code provided by the Connected Experiences app.
  2. Name the device.
  3. Click Register.
  4. Check that the confirmation code matches the confirmation code on the device.
  5. Log in with your Splunk Enterprise credentials to complete registration.

Log in to multiple Splunk instances

You can log in to multiple Splunk platform instances and switch between Splunk platform instances.

  1. In the Connected Experiences mobile app, navigate to Settings.
  2. Click Manage instances.
  3. Click Edit.
  4. Click Register.
  5. Enter the provided authentication code in Splunk Secure Gateway.

Log in if your organization uses an SSO provider

If your organization uses SAML authentication, you can log in using your Splunk credentials and the authentication code provided in the Connected Experiences mobile app, or by entering your organization's hostname.

Prerequisites

  • Your admin has set up SAML authentication. See Set up SAML authentication for admin set up steps in the Administer Splunk Secure Gateway manual.

Log in with the authentication code

You can use Splunk Secure Gateway to log in to a Splunk Cloud or Splunk Enterprise platform with an SSO provider.

  1. Log in using the authentication code provided in the Connected Experiences app.
  2. During registration, you are redirected to your SSO provider.
  3. Log in and complete the registration steps. See Log in a device with an authentication code using Splunk Secure Gateway.

Log in with a hostname

Before logging in with a hostname, an admin must provide you with a registration QR code or your organization's hostname in the form of https://<splunk-cloud-instance-name>.splunkcloud.com. For admin steps, see Provide a QR code for SAML authentication device registration with a hostname in the Administer Splunk Secure Gateway manual.

You can only log in to Splunk Cloud platform instances with a hostname.

  1. In the Splunk Mobile app, tap Sign in with SSO.
  2. Scan the QR code or enter the hostname provided by your admin.
  3. Tap Sign in with SSO. You're redirected to your organization's IdP.
  4. Sign in with your SSO credentials.

Log in if your organization uses MDM

If your admin set up Mobile Device Management (MDM) and in-app device registration, you can enter your Splunk login credentials to log in.

MDM allows admins to scale and further secure their Splunk Mobile deployment. To learn more about compatible apps and providers, see About MDM and in-app registration.

If your organization uses both SAML authentication and an MDM provider, see Log in if your organization uses both SAML authentication and an MDM provider

Prerequisites

  • Use a MDM-supported app. See About MDM and in-app registration to learn which Connected Experiences apps support MDM.
  • Your admin has set up MDM and in-app registration.

For admin MDM setup, see Set up MDM and in-app registration for iOS devices or Set up MDM and in-app registration for Android devices..

Log in with an iOS MDM-distributed device

If you're using an iOS device, follow these steps to log in with your MDM-distributed device:

  1. If you're using an iOS device, log in to your MDM provider website on your device. This installs an MDM profile on your device and redirects you to the App Store or Playstore.
  2. Download the MDM provider's catalog app.
  3. In the MDM providers' catalog app, download the Splunk Connected Experiences app.
  4. In the Splunk Connected Experiences app, tap the Splunk platform instance that you want to log in to.
  5. Select Local sign on or Single Sign On.
  6. Enter your Splunk platform instance or SSO credentials to register.

Alternatively, tap Log in with Code to log in using a provided authentication code in Splunk Secure Gateway.

Log in with an Android MDM-distributed device

If you're using an Android device, follow these steps to log in with your MDM-distributed device:

  1. Download your MDM provider app from the Play Store.
  2. Log into the MDM provider app with your MDM credentials. This installs an MDM profile on your device.
  3. Download the Splunk Connected Experiences app from the Play Store.
  4. Select Local sign on or Single Sign On.
  5. Enter your Splunk platform instance or SSO credentials to register.

Alternatively, tap Log in with Code to log in using a provided authentication code and Splunk Cloud Gateway, or tap Log in with SSO to log in using SAML authentication with a hostname.

Log in if your organization uses both SAML authentication and an MDM provider

If your organization uses both SAML authentication and an MDM provider, select SSO Sign On and log in with your organization credentials.

Log in to multiple Splunk instances

You can get data from multiple Splunk platform instances on your device when you log in to more than one Splunk platform instances.

  1. Navigate to Settings > Manage Instances. Or if you're using Splunk Mobile, tap the Secure Gateway ID dropdown arrow.
  2. Tap Edit > Log in.
  3. Log in using any authentication method.

To navigate between Splunk platform instances in the Splunk Mobile app, tap the Secure Gateway ID dropdown and select the instance that you want to view data from.

The Secure Gateway ID is randomly generated when you first launch Splunk Secure Gateway. Admins can define this Secure Gateway ID in the Configure tab of Splunk Secure Gateway or in the securegateway.conf file so you can quickly identify your Splunk platform instances.

Unregister a device

You can unregister a device in Splunk Secure Gateway or in the Connected Experiences mobile app on the device.

Here's how to unregister a device in Splunk Secure Gateway:

  1. Navigate the Devices tab in Splunk Secure Gateway.
  2. Next to the device you want to remove, click Remove.

Here's how to unregister a device in the Connected Experiences mobile apps:

  1. Navigate to Settings.
  2. Click Manage instances.
  3. Click Edit.
  4. Click the X button next to the instance you want to unregister from.
  5. Click Unregister to confirm.
Last modified on 19 April, 2021
  NEXT
Select which Splunk apps to show dashboards from in the mobile apps

This documentation applies to the following versions of Splunk® Secure Gateway: 2.0.1000, 2.0.2, 2.5.4


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters