A selection of users in Bogota, Colombia are getting:
IDP failed to authenticate request. Status code="Responder" Check splunkd.log for more information about the failure.
Multiple users here in Raleigh, NC can access the logs fine.
I have read several articles indicating this is an SSO issue
But we are not doing SSO with Splunk
I do not know how to look at this splunkd.log either
Open a ticket - its likely an issue on Splunks side
Is this Splunk Cloud?
Yes, this is spunk Cloud
what is your authentication method?