Dashboards & Visualizations

Why is an embedded dashboard in iframe not working for Chrome?

fralcalde
Explorer

Hello,
We have a simple XML dashboard in our splunk implementation which works fine when browsing splunk web.
We embedded this dashboard in another web through an iframe like follows:

 

<iframe src="https://Splunk-Server:8000/account/insecurelogin?username=USER&password=PASWROD&return_to=/app/My-App/Dashboard-to-embed"></iframe>

 

This works fine on firefox, but chrome doesn't load it.
We suspect that chrome is blocking the iframe contents because it won't load splunk's cookies in a third-party web-page, as per this article: https://blog.heroku.com/chrome-changes-samesite-cookie

In short, we don't know how to configure splunk's cookie flags to allow them being loaded cross-domain. (SameSite=None, Secure)
Or really, if this is the problem at all...
We would apreciate any help you can provide. Thank you.

Labels (1)
0 Karma

lucasgraf
New Member

I know this is an old post, but did you ever figure out how to get this to work? I am having the same problem.

0 Karma

fralcalde
Explorer

@lucasgraf 
It's been very long and my memory may be wrong but I think what solved this were some simple configurations in the web.conf file.
$SPLUNK_HOME/etc/system/local/web.conf:

[settings]
x_frame_options_sameorigin = false
verifyCookiesWorkDuringLogin = false
dashboard_html_allowed_domains = XXX.XXX.XXX.XXX,*.your-domain.com



Where XXX.XXX.XXX.XXX is some IP. It accepts wildcards.
I recommend you take a look at the docs about these settings before taking my word for it.
https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Webconf

Hope I was able to help. Good Luck.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...