<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008kuDfnCAEOkta Classic EngineInsights and ReportingAnswered2023-02-04T00:57:43.000Z2023-02-02T08:49:47.000Z2023-02-04T00:57:43.000Z

YashS.48364 (Customer) asked a question.

Utilizing Okta Log Streaming on Splunk Cloud

Hi Community, this is regarding an early access feature for one of my "oktapreview" account

I have configured Log Streaming in Splunk Cloud using this document as a reference - https://help.okta.com/oie/en-us/Content/Topics/Reports/log-streaming/add-splunk-log-stream.htm

When I enter the "Host" field value with the hostname - <part1>.<part2>.stg.splunkcloud.com, I am getting an error that states "Host should be a domain without http or https. For example: acme.splunkcloud.com"

/help/servlet/rtaImage?refid=0EM4z000004fHop

 

Then I entered another instance's hostname - <stackname>.splunkcloud.com, the error was resolved but I am not able to see logs in my Splunk Cloud instance although there are Logs in my account and the Log Stream is active.

 

My concerns are:

  1. Why did the first hostname not work while configuring the log stream? Does the Host field have a specific format for its value to be accepted?
  2. Even after configuring the log stream, I am not able to see the logs. What am I missing here? How can I debug this?

This question is closed.
Loading
Utilizing Okta Log Streaming on Splunk Cloud