OneLogin

You can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):

Collection Method Description
Standard Collector overview Forward logs and data to Cortex XSIAM from OneLogin via the OneLogin REST APIs using the OneLogin data source.
Link to Standard Collector instructions <p>The following types of data can be ingested from OneLogin:</p><ul><li><p>Log collection</p><ul><li>Events: User logins, administrative operations, provisioning, and a list of all OneLogin event types</li></ul></li><li><p>Directory</p><ul><li>Users: Lists of users.</li><li>Groups: Lists of groups.</li><li>Apps: Lists of apps.</li></ul></li></ul><p>For more information, see Ingest logs and data from OneLogin.</p>
Link to content pack/integration details (onboarded prior to July 26, 2026) <p>The OneLogin content pack provides capabilities for simple customer authentication and streamlined workforce identity operations utilizing APIs. It includes one modeling rule for data normalization and the following integration:</p><ul><li>OneLogin Event Collector: Use this integration to gather simple customer authentication and streamlined workforce identity operations with the onelogin-get-events command.</li></ul>
Link to connector (onboarded after July 26, 2026) OneLogin