I have installed the Okta Identity Cloud Add-On into Splunk Cloud. I have setup individual indexes for each of the log types and accounts that I am ingesting. I can see that the Okta logs are being ingested correctly but none of the default searches work. By default they do a search on "sourcetype" however this returns no results: sourcetype="oktaim2:log" event_type="okta_event_authentication" (host="*") If I manually add the index to the search, then it works: index="okta-*" sourcetype="oktaim2:log" event_type="okta_event_authentication" (host="*") I can't find anywhere to set the default index. If I do a plain search for sourcetype="oktaim2:log" it also returns no results. Is this an error when Splunk have installed the add-on, or a configuration I have missed, or do I just have to manually adjust all of the views ? Any thoughts appreciated.
... View more