1) props.conf for sourcetype [sailpoint_identitynow], TIME_PREFIX is correct with "created" field, TIME_FORMAT is incorrect, possibly needs a ".%Q" added for milliseconds, and DATETIME_CONFIG is preempting all other settings and setting the timestamp as _indextime. I fixed it on both our HF & Cloud instance by removing both TIME_FORMAT & DATETIME_CONFIG.
2) The app isn't compatible with Splunk versions 9.x, both Cloud & Enterprise, so for our fully-managed-by-Splunk version of Splunk Cloud running on 9.3.x we can't install the app at all.
3) ISC configuration settings (org name, client ID & client secret) are required in 2 different places?!?! Config tab needs to be filled in otherwise Input doesn't work. No support for multiple orgs? We are currently connected with our dev org, however anticipating a problem of adding a production org in the very near future, would need to have the TA installed on 2 different HFs?
Hi @samejgink
thanks for taking your time to update this feedback, much appreciated.
as @livehybrid suggested, the only way to get the Add-on updated would be thru the Add-on developers. Could you pls email the add-on dev guys (if no reply for you, pls update here as well. Someone from the community can reach out the sailpoint add-on team for you and everyone)
hoping for faster resolution, thanks.
Hi @samejgink
I would suggest emailing the app author at : support.idplusa@sailpoint.com to see if they can update the app.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.