mbegan / Okta-Identity-Cloud-for-Splunk

Public REPO for splunkbase app
https://splunkbase.splunk.com/app/3682/
Other
19 stars 13 forks source link

Fixes #22 - system@okta.com being tagged as authentication #25

Closed simonsigre closed 1 year ago

simonsigre commented 4 years ago

Changes applied eventtypes.conf file: -disabling eventtype okta_log -split authentication events from change events based on event_type matched via automatic lookup okta2_eventtype_lookup

props.conf file: -reasigning user account from actor system@okta.com to target alternateId user account -matching user_id with new user account captured from target alternateId

tags.conf file: -adjustments made based on new splitting authentication events from change events -new tag change