mbegan / Okta-Identity-Cloud-for-Splunk

Public REPO for splunkbase app
https://splunkbase.splunk.com/app/3682/
Other
19 stars 13 forks source link

Fixes #22 - system@okta.com being tagged as authentication #24

Closed simonsigre closed 1 year ago

simonsigre commented 4 years ago

Changes applied eventtypes.conf file: -disabling eventtype okta_log -split authentication events from change events based on event_type matched via automatic lookup okta2_eventtype_lookup

props.conf file: -reasigning user account from actor system@okta.com to target alternateId user account -matching user_id with new user account captured from target alternateId

tags.conf file: -adjustments made based on new splitting authentication events from change events -new tag change

simonsigre commented 4 years ago

@mbegan merged back what was in the public TA back into your dev branch.. looking at the changes .. pretty massive, ill issue a PR into MASTER and if need be you can just cherrypick the changes you want.. They are also here (built from 22519)

https://gitlab.com/enosysau_socgroup-public/TA-Okta_Identity_Cloud_for_Splunk/-/commit/8118c34990fbd555aea34e8ad872d2b281622abe