Okta System Log

Pull sign-ins, MFA events and administrative changes from Okta.

What it collects

The connector polls the Okta System Log API and stores every event: sign-in success and failure, MFA challenges, session events, user and group changes, application assignments and administrator actions. Events arrive with event.module: okta, the acting user in user.name, the target in user.target.name where applicable, and the client address in source.ip.

Prerequisites

  • An Okta API token or an OAuth service application with permission to read the System Log.
  • Outbound HTTPS from the deployment to your Okta domain.

Configure

Settings › Integrations › Add › Okta. Enter the Okta domain and the credential, choose the organization the events belong to, and save. The connector starts from the current time; set an earlier start if you want history, within Okta's retention.

Health

The integration panel shows the last successful poll, the cursor position and lag. A stalled connector raises a notification and shows on the Overview page's data-source health panel.

Response

With a credential that also has user management rights, playbooks can disable an Okta user and revoke their sessions. Configure that permission only if you intend to use it; see Response actions.