Splunk® Supported Add-ons

Splunk Add-on for Okta Identity Cloud

Performance Statistics for Okta System Logs Data Collection through Modinput

The following tables contain reference information about performance statistics of the Okta inputs in the Splunk Add-on for Okta Identity Cloud.


The table below indicates the variables used for this performance analysis.

Variable configured in Variable Value
Add-on Log Limit (Configurable from Additional Settings Page of the add-on) 1000
Add-on Rate Limit Percentage (Configurable from Additional Settings Page of the add-on) 100
Okta Identity Cloud % Utilization of requests (Configurable from Rate Limit section of the Okta) 100%


Note: These statistics are recorded for the maximum availability of API requests for an Okta Account

Data Ingestion Time considering the above parameters :

Number of System Log Events Ingested Throttling Data Ingestion Time
~1Million Static Throttling ~18 minutes
Dynamic Throttling ~22 minutes
~2.5Million Static Throttling ~45 minutes
Dynamic Throttling ~50 minutes
~5Million Static Throttling ~1 hour 30 minutes
Dynamic Throttling ~1 hour 40 minutes


The average events ingestion time for ~5M events is ~90 mins using all the available API limits. These statistics indicate the capacity of the add-on to ingest the data corresponding to a customer's real-time use case.

Note: The performance statistics represent reference information and do not represent performance in all environments. Many factors impact performance results, including permissible API calls to the user's account, network connectivity, and hardware. Results may vary for different users.

Last modified on 03 September, 2024
CIM compatibility of Okta System Logs   Release notes for the Splunk Add-on for Okta Identity Cloud

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters