
RashidA.42734 (Customer) asked a question.
We are getting rate limit threshold warning for /api/v1/apps*. The log entry just gives details about the user and IP where the request originates and Target says "URL Pattern". How to further investigate such cases. I see there is another question like this "https://support.okta.com/help/s/question/0D51Y0000AYo9cuSQB/how-to-find-cause-of-rate-limit-warning-raised-by-okta-system-systemprincipal?language=en_US" but no answer on that one.

Hi @RashidA.42734 (Customer) , Thank you for reaching out to the Okta Community!
You will need to confirm if the user is valid, a service account or malicious. You should also confirm that the IP is from a trusted source, perhaps it is an automation your company implemented and is misconfigured causing it to exceed the request limit.
If you have an account with us, please open a case to work with my colleagues from the Support Team. They'll be able to access additional tools and resources to help you get to the bottom of it.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Join the discussion for the Ask Me Anything online event on May 23, 2024 with Okta Tactical Edge Product Experts