In the first post about Splunk Cloud Gateway I talked about not being able to use Saved Searches with the Splunk Cloud Gateway. I worked with Splunk and got the official response back about the issue.
So you discovered a bug! I will have a fix for this before the next release of the Cloud gateway app. The issue is with the name of the saved search. We are not url encoding the ref string when we should be which is causing the parser to fail. If you want to work around this issue use a name for the saved search that doesn’t have any spaces.
After working with Splunk, I can confirm that this works. Using camel case (CamelCaseWorks) is a great way to accomplish this without spaces.
So you have downloaded Splunk Cloud Gateway (https://splunkbase.splunk.com/app/4250/) and you are ready to go on your Mobile Device or Apple TV, but when you check your app your dashboard(s) do not show up in the list. Oh no! Here is a couple things to check and I am sure this article will be updated as more information is learned.
Check the internals!
A great place to start is the internal logs of Splunk. In this case:
This will let you see what is going on inside the Cloud Gateway app. Now we can start to search what what is going on in the dashboard by adding the name of your dashboard in to the search.
index=_internal source=”/opt/splunk/var/log/splunk/splunk_app_cloudgateway*” “awesome_dashboard”
There can be a lot of see so we might want to narrow it down to just the errors and warnings.
index=_internal source=”/opt/splunk/var/log/splunk/splunk_app_cloudgateway*” (log_level=WARNING OR log_level=ERROR) “awesome_dashboard”
Now we can start to get some where.
My error happened to be:
WARNING [dashboard_request_processor] [dashboard_request_processor] [fetch_dashboard_descriptions]  Unable to parse dashboard description dashboard_id=https://127.0.0.1:8089/servicesNS/nobody/myapp/data/ui/views/mobile_today_01, request_id=ABC12345-6789-DEFG-HI01-JKLMNO234567 device_id=ABCDEFGHIJKLMNOPQRSTUVWXYZ12345678901234567= current_user=myuser is_alert=False
Ok, so Splunk can’t parse the dashboard. I checked the dashboard and made sure the role “cloudgateway” had access but still no luck. I even checked that the schedule search gave read permission to the role. No dice. Just by chance I created a new dashboard and happened to not use Scheduled Searches. I checked the mobile app and there it was, my awesome dashboard. Just to make sure I wasn’t seeing things I converted the inline to a saved search and then I got the errors again. Converted back to an inline search and there it was on my device. So just a helpful hint, if your dashboard isn’t showing up, check if there is scheduled searches.
Continue to Part 2, setting up Splunk TV.