Configured Splunk Add-On in our tenant as per the doc below
We receive timeout errors sometimes accessing the API's and due to which some events generated in Saviynt are missed to be pushed. Is the Splunk Add-on not have the capability of retrying the call if the original call times out?
urllib3.exceptions.ReadTimeoutError: HTTPSConnectionPool(host='myhost.mydomain.com', port=443): Read timed out. (read timeout=120.0)
Increasing the timeout in the Add-on Settings did not resolve the issue as well. Proper retry needs to be configured to avoid events missed to be pushed to SIEM.
@Sivagami i believe this splunk addon was community developed and certified by Saviynt, I will check if it can be enhanced to add retry logic.
Regarding the original issue - it should not take more than 120 seconds to return around 50 records. Can you try running from postman few times and see what is the response time?
Also when timeout occurs do you see any error on Saviynt application log?