HI,
I am trying to use the Okta App for Splunk with the latest Splunk release. Installed test instance this week.
When I restart Splunk and trace Okta, I always get the following errors
WARN DateParserVerbose - Accepted time (Mon Feb 03 01:40:27 2014) is suspiciously far away from the previous event's time (Tue Feb 04 05:16:47 2014), but still accepted because it was extracted by the same pattern. Context: source::C:\Program Files\Splunk/etc/apps/okta/bin/okta.py|host::swglog01|exec|0
2014-02-19 18:11:54.383000 app=okta event_id=okta.api.user.start severity=informational subject="Requesting User Object with limit 1000" Traceback (most recent call last): File "C:\Program Files\Splunk\etc\apps\okta\bin\oktausr.py", line 54, in user[i][0] = evt['id'] KeyError: 'id'
In my Okta index there is no data 😞
Any idea what I am missing?
Thanks
Florian
... View more