SPLUNK_HOME
environment variable is pointing to the root directory of your Splunk instance.Settings -> Data -> Data inputs
name
, domain
, global client ID
, global client secret
and interval
(under "More settings" section)Global client ID and secret can be found from https://docs.auth0.com/api
$SPLUNK_HOME/var/lib/splunk/modinputs/{AUTH0_DOMAIN}-log-checkpoint.txt
$SPLUNK_HOME/var/log/splunk/audit.log
$SPLUNK_HOME/var/log/splunk/splunkd.log
Settings -> Data -> Data inputs -> Auth0
and delete the data input$SPLUNK_HOME/var/lib/splunk/modinputs/{AUTH0_DOMAIN}-log-checkpoint.txt
sourcetype="auth0_logs" | delete
source=auth0://{DATA_INPUT_NAME} | delete
If you have insufficient privileges to delete events (and assuming you are an admin), go to
Settings -> Users and authentication -> Access controls -> Roles -> admin
and add thedelete_by_keyword
capability underCapabilities
section.
Minor improvements
Improve setup process.
Added compatibility to Splunk 6.2
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.