All Apps and Add-ons

Filter the data for OKTA application

rashi83
Path Finder

Hi ,
On a standalone SH , we are pulling OKTA logs using OKTA Identity cloud app.
Need to filter events based on the email address . For example anything with *gmail.com should not be indexed.

Put props.conf and transforms .conf in location -
C:\Program Files\Splunk\etc\apps\TA-Okta_Identity_Cloud_for_Splunk\local

props.conf
[OktaIM2:log]
TRANSFORMS-set= setnull

transforms.conf
[setnull]
REGEX=gmail.com
DEST_KEY=queue
FORMAT=nullQueue

But still events are not getting filtered . Any suggestions?

0 Karma

to4kawa
Ultra Champion

Have you reboot splunk?

0 Karma

rashi83
Path Finder

Yes I did .

0 Karma
Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...