Hi Team,
I have downloaded and configured the Splunk add-on for Okta and enabaled the saved searches for okta.i configured the data input as Events and users and saved the setting. as per the document they asked me hit the sourcetype=okta:im. when hit this in search bar i didnt get any results. And then i installed Splunk app for okta and tried setting the index as okta. Created a new in put using splunk add-on for okta and directed to this index.
When i tried hitting index=okta in Splunk app for okta i dint get any result.
Please help me on this
should i need to open any firewall between okta and splunk.?
Did you check the indexes settings page, to see if the index okta contains any events?
Thanks for the response. No the index okta doesnt contains any event. Should i need to open firewall between okta and Splunk to get the data
I haven't used the Okta app before, but the docs have this part about setting up a proxy.
Therefore, it's very likely the app accesses an API on the internet, and you need to make sure that such access is possible, either by changing firewall rules, or using your proxy server. I'd have a chat with my network security people. 😉
Hope that helps!