Splunk ISC Addon for audit

After long hours of debugging, I was able to resolve the issue by performing the following actions:

  1. Removed the DATETIME_CONFIG parameter from the file “$SplunkHome/etc/apps/TA-sailpoint-identitynow-auditevent-add-on/default/props.conf”.

  2. Added the following elements to the file “etc/apps/TA-sailpoint-identitynow-auditevent-add-on/local/ta_sailpoint_identitynow_auditevent_add_on_settings.conf”:

[proxy]
proxy_password = NONE
proxy_type =

@colin_mckibben may be you can transfert this elements to your team who are developped this plugin may be they have an explanation.

1 Like