I am having issues configuring Duo MFA with Splunk. Configuring per Splunk Docs via the UI yields
Encountered the following error while trying to save: Current Duo configuration cannot be verified by the Duo server. Please check and re-enter it again
... and configuring via
authentication.conf per Splunk Docs yields
Login failed due to incorrectly configured Multifactor authentication. Contact Splunk support for resolving this issue
I have verified per Duo Docs that my server time is correct by running date in bash, and I can confirm that the ikey, skey, and api_host are correct because I am using these same parameters to actively ingest data from Duo on a separate Splunk server.
Does anyone have any tips or experience, or is this a support ticket?