All Apps and Add-ons

How to get the Splunk App and Add-on for Okta to stop pulling duplicate data?

butzowj
Path Finder

Hello -

I am working on getting the Splunk App and Add-on for Okta working for Splunk 6.2.4. Currently I am pulling in some data with the okta:user sourcetype, but I just keep pulling back the same records...

What can I do to get the app to stop pulling in duplicate records?

Thanks!

0 Karma
1 Solution

rwang_splunk
Splunk Employee
Splunk Employee

Hi butzowj

The sourcetype okta:user is designed to retrieve all user data from Okta system on a certain interval time. It will pull the same data from the Okta system if the user information does not change. I think you can either disable the inputs after pulling the data, and enable it whenever you want to, or set a longer interval time to prevent frequent data duplication.

View solution in original post

rwang_splunk
Splunk Employee
Splunk Employee

Hi butzowj

The sourcetype okta:user is designed to retrieve all user data from Okta system on a certain interval time. It will pull the same data from the Okta system if the user information does not change. I think you can either disable the inputs after pulling the data, and enable it whenever you want to, or set a longer interval time to prevent frequent data duplication.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...