
v6mlp (v6mlp) asked a question.
Our organisation has suddenly started getting 60% rate limit warning emails that we haven't seen before, for endpoint "/api/v1/apps/<appid>/skinny_users". Has anyone else seen this start happening? We don't explicitly call the "skinny_users" endpoint, so where is this coming from?

Hi Andrew !
Thank you for posting on our Community forums !
The requests could be coming from any API integration's you've made with a security token.
Please raise a Support Ticket, letting us know your organization's subdomain, and we can investigate logs to find out more about the requests, based on their IP/UserAgent
With the help of Okta support, I realised that another part of our organisation had set up Splunk polling of the system logs which was getting close to exceeding rate limits. The solution was to reduce the frequency of the Splunk polling.