Improving Security: Updates to Classic (SimpleXML) Dashboards Containing External Links or Content

Classic (SimpleXML) dashboards are a powerful tool for you to share information with users and can include links for users to continue their investigations in other pages. As you likely already know, you can include external content in your Classic dashboard using HTML panels. You can also include external links or configure drilldowns to external URLs.

At Splunk we are continuously working to improve security and prevent incidents. As part of this commitment to security, we want to ensure you have a chance to review and verify external content or links, and you will now see a modal requesting you to review and determine whether you trust the external content or link. In this blog, we'll cover the scenarios in which you will see a modal, and what actions you can take.

On Dashboard Load

When your Classic dashboard loads, if any external links are detected in an HTML panel, you will be prompted with a modal to review all the links and choose whether to load them in the dashboard or not.

Select "Continue" to load the dashboard with the external content or links. Select "Cancel" to load the dashboard without the external content or links. If you select Cancel, all other content will still load.

This modal will not show for www.splunk.com pages, and select subdomains, such as docs.splunk.com.

If there are links that you trust, you can work with your Splunk admin to add those domains or links to the Dashboards Trusted Domains list. We recommend using as specific of a link as possible. For example, www.splunk.com/products instead of www.splunk.com.

When Navigating to an External URL

Imagine you have a dashboard with a custom URL drilldown such as https://www.google.com/search?q=$click.name2$.

When you select an external link or a visualization with a custom URL drilldown, you will be prompted with a modal to review all the links and choose whether to navigate away from Splunk.

Select "Continue" to continue navigating to that URL. Select "Cancel" to stay on the Splunk dashboard. You can select "Don't show this again" to suppress the warning for the same URL. Note that if the URL changes, for example because token values change, the warning will display again.

We appreciate your understanding as we evolve our product with preventative mechanisms to provide our customers with a secure experience.

Related Articles

Announcing the General Availability of Splunk POD: Unlock the Power of Your Data with Ease
Platform
2 Minute Read

Announcing the General Availability of Splunk POD: Unlock the Power of Your Data with Ease

Splunk POD is designed to simplify your on-premises data analytics, so you can focus on what really matters: making smarter, faster decisions that drive your business forward.
Introducing the New Workload Dashboard: Enhanced Visibility, Faster Troubleshooting, and Deeper Insights
Platform
3 Minute Read

Introducing the New Workload Dashboard: Enhanced Visibility, Faster Troubleshooting, and Deeper Insights

Announcing the general availability of the new workload dashboard – a modern and intuitive dashboard experience in the Cloud Monitoring Console app.
Leading the Agentic AI Era: The Splunk Platform at Cisco Live APJ
Platform
5 Minute Read

Leading the Agentic AI Era: The Splunk Platform at Cisco Live APJ

The heart of our momentum at Cisco Live APJ is our deeper integration with Cisco, culminating in the Splunk POD and new integrations, delivering unified, next-generation data operations for every organization.
Dashboard Studio: Token Eval and Conditional Panel Visibility
Platform
4 Minute Read

Dashboard Studio: Token Eval and Conditional Panel Visibility

Dashboard Studio in Splunk Cloud Platform can address more complex use cases with conditional panel visibility, token eval, and custom visualizations support.
Introducing Resource Metrics: Elevate Your Insights with the New Workload Dashboard
Platform
4 Minute Read

Introducing Resource Metrics: Elevate Your Insights with the New Workload Dashboard

Introducing Resource Metrics in Workload Dashboard (WLD) – a modern and intuitive monitoring experience in the Cloud Monitoring Console (CMC) app.
Powering AI Innovation with Splunk: Meet the Cisco Data Fabric
Platform
3 Minute Read

Powering AI Innovation with Splunk: Meet the Cisco Data Fabric

The Cisco Data Fabric brings AI-centric advancements to the Splunk Platform, seamlessly connecting knowledge, business, and machine data.
Remote Upgrader for Windows Is Here: Simplifying Fleet-Wide Forwarder Upgrades
Platform
3 Minute Read

Remote Upgrader for Windows Is Here: Simplifying Fleet-Wide Forwarder Upgrades

Simplify fleet-wide upgrades of Windows Universal Forwarders with Splunk Remote Upgrader—centralized, signed, secure updates with rollback, config preservation, and audit logs.
Dashboard Studio: Spec-TAB-ular Updates
Platform
3 Minute Read

Dashboard Studio: Spec-TAB-ular Updates

Splunk Cloud Platform 10.0.2503 includes a number of enhancements related to tabbed dashboards, trellis for more charts, and more!
Introducing Edge Processor for Splunk Enterprise: Data Management on Your Premises
Platform
2 Minute Read

Introducing Edge Processor for Splunk Enterprise: Data Management on Your Premises

Announcing the introduction of Edge Processor for Splunk Enterprise 10.0, designed to help customers achieve greater efficiencies in data transformation and improved visibility into data in motion.