Archive

Having trouble in bringing events to Splunk app for Okta

New Member

Hi Team,

I have downloaded and configured the Splunk add-on for Okta and enabaled the saved searches for okta.i configured the data input as Events and users and saved the setting. as per the document they asked me hit the sourcetype=okta:im. when hit this in search bar i didnt get any results. And then i installed Splunk app for okta and tried setting the index as okta. Created a new in put using splunk add-on for okta and directed to this index.

When i tried hitting index=okta in Splunk app for okta i dint get any result.

Please help me on this

should i need to open any firewall between okta and splunk.?

Tags (1)
0 Karma

SplunkTrust
SplunkTrust

Did you check the indexes settings page, to see if the index okta contains any events?

0 Karma

New Member

Thanks for the response. No the index okta doesnt contains any event. Should i need to open firewall between okta and Splunk to get the data

0 Karma

SplunkTrust
SplunkTrust

I haven't used the Okta app before, but the docs have this part about setting up a proxy.
Therefore, it's very likely the app accesses an API on the internet, and you need to make sure that such access is possible, either by changing firewall rules, or using your proxy server. I'd have a chat with my network security people. 😉

Hope that helps!

0 Karma