Skip to main content
Warning
This app is archived. App archiving documentation
Splunk Add-on for Okta app icon

Splunk Add-on for Okta

Important: On March 18, 2019, this add-on has been deprecated and has been transferred to partner support. For more information about the end of availability and support for this add-on, see https://www.splunk.com/blog/2019/03/18/end-of-availability-splunk-built-apps-and-add-ons.html.Built by Splunk Works
splunk product badge

Default Version 1.3.0

December 28, 2016

Compatibility

Splunk Enterprise

CIM Version: 4.x

Rating
3
(7)

Log in to rate this app

Support
Archived Add-on

Important: On March 18, 2019, this add-on has been deprecated and has been transferred to partner support. For more information about the end of availability and support for this add-on, see https://www.splunk.com/blog/2019/03/18/end-of-availability-splunk-built-apps-and-add-ons.html. The Splunk Add-on for Okta allows a Splunk software administrator to collect data from Okta. The add-on collects event information, user information, group information, and application information using Okta Identity Management REST APIs. This add-on also supports remediation commands that allow you to add a user to an Okta group, remove a user from an Okta group, deactivate an Okta user account from the Splunk platform and create custom alert. After the Splunk platform indexes the events, you can consume the data using the prebuilt panels included with the add-on. This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.