Splunk® Enterprise

Developing Views and Apps for Splunk Web

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Migration Issues

This release contains various changes with respect to app development. This topic discusses migration issues from Splunk 5.x to Splunk 6 for app developers.

Flash charting not available in simple XML dashboards

Flash charting that is available in both simple XML and advanced XML in Splunk 5.x is no longer supported in Splunk 6.x.

This change provides a more consistent dashboard user experience for iOS devices and PDF generation.

Splunk software silently ignores any charting options that previously triggered the rendering of FlashCharts. Some charts may render differently in Splunk 6.x as a result.

Redesign charts using JavaScript charting or export the dashboard as HTML and reimpelement using JavaScript.

However, exporting a dashboard as HTML can affect integrated PDF generation.

JavaScript and CSS support changes

The rendering engine for simple XML dashboards has been completely refactored in Splunk 6. Many of the function calls that are used in application.js and application.css no longer work.

For backward compatibility, in Splunk 6, simple xml dashboards no longer load application.js and application.css automatically. Instead, simple XML dashboards in Splunk 6 load dashboard.js and dashboard.css.

You can control the loading of specific JavaScript and CSS files within the configuration of each simple xml dashboard using the script and stylesheet attributes to the dashboard element. For example:

<dashboard script="myJavaScript.js" stylesheet="myStylesheet.css">. . .

For dashboards prior to Splunk 6, you can import application.js and application.css files using the dashboard element attributes, as shown in the above example.

Viewstates are no longer supported in simple XML

Chart options that were saved in viewstates are no longer layered in dashboard rendering.

Dynamic chart resizing no longer persists beyond the page view.

You need to manually migrate these chart options to the simple xml view configuration.

Implement persistence in charts using simple xml options. For example:

<chart>. . .

 <option name="height">300px</option>
 . . .

JavaScript is no longer available within navigation menus

For security purposes, JavaScript is no longer allowed with nav default.xml.

For example, the Search app packaged with Splunk 5.x contain a navigation item with the link Create new dashboard.... In Splunk 6, this link would not be functional.

Remove any JavaScript in the default.xml configuration and redesign access to any link previously supported.

App icon directory has changed

The directory Splunk Web looks for appIcon.png has changed.

In Splunk 6:


Previously, in Splunk 5.x:


Place app icons in the new location for Splunk 6.

New Splunk Search view page

Splunk 6.0 introduces a new search page search as a replacement to the existing flashtimeline.

While flashtimeline is still packaged in the product, all references to flashtimeline within an app should be changed to now reference search.

This includes references within nav default.xml and references within any dashboard views (mainly linkView options).

New global pages available to add to your app

Splunk 6 provides easier access to reports, alerts, dashboards, and data models packaged within your app.

This access is provided using new listing pages: Dashboards, Reports, Alerts, Data Models

You can add navigation to these views in your apps and also to nav default.xml.

Home page searchability for your app

Splunk 6 enables users to run a search query from within the home page, and target specific apps.

To allow users to directly target your app, this must be configured within your app's nav default.xml. Edit nav default.xml with the target view (<nav search_view="search">).

Data Models

Splunk 6.0 introduces data models that can be packaged within apps. Data Models are packaged within:


Custom HTML dashboards

Added knowledge object to be included in default.meta.

Splunk 6.0 suports dashboard views written entirely in HTML (leveraging the new splunkjs library).

Custom HTML dashboards are packaged here:  :$SPLUNK_HOME/etc/apps/<app_name>/default/data/ui/html

These custom HTML dashboards can be referenced in default.meta with the object name [html].

AppBar styling is more restrictive

For consistency between apps, Splunk 6.0 now constrains AppBar customization to color and logo.

To set color, use the color option to the nav element in default.xml. For example:

<nav color="#0072C6">

To set a logo, package appLogo.png within $SPLUNK_HOME/etc/apps/<app_name>/static

Here are the specifications to use for appLogo.png:

Specification Description
Background Transparent
Width variable
Height 40px (80px @2x)
Margins ~10px top and bottom (20px @2x)

The 40px width should a 10px space at the top and bottom, so the logo should be 20px tall.

However, there is some leeway to go into the margin area, particularly if the logo has any bits that project up or down or it is particularly complex, square or round.

Search page restyling no longer supported

Splunk 6.0 new search page cannot be customized as it does not load any custom javaScript or CSS.

Last modified on 18 August, 2016
Apps and add-ons: an introduction
Step 1: Getting started

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters