Okta Event Collector
Collects the events log for authentication and Audit provided by Okta admin API.
Analytics & SIEM · Okta
Details
| ID | Okta Event Collector |
|---|---|
| Provider | Okta |
| Category | Analytics & SIEM |
| From Version | 6.8.0 |
| Docker Image | demisto/fastapi:0.125.0.10158186 |
| Supported Modules | Agentix Cloud Runtime Security Cloud Posture Security XSIAM EDR Cortex Cloud |
README
Collects the events log for authentication and Audit provided by Okta admin API
This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.
Configure Okta Log in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL | Okta URL (https://yourdomain.okta.com) | True |
| Number of incidents to fetch per fetch | The total number of incidents to retrieve in each fetch cycle | True |
| proxy | Use system proxy settings | False |
| API key | The request API key | True |
| First fetch time interval | The period (in days) to retrieve events from, if no time is saved in the system | True |
| Fetch events | Whether to fetch events from Okta | False |
| Events Fetch Interval | The interval (in minutes) between fetch cycles | False |
Commands
You can execute these commands in a playbook.
okta-get-events
Manual command to fetch events and display them. Use for development and debugging only, as it may produce duplicate events or disrupt the fetch mechanism.
Base Command
okta-get-events
Input
| Argument Name | Description | Required |
|---|---|---|
| should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. Possible values are: True, False. Default is False. | Required |
| start_time | The start time from which to retrieve events. Supports relative time (for example, “5 minutes ago”, “3 days ago”) or ISO 8601 (for example, “2026-01-01T10:00:00Z”). Default is 5 minutes ago. | Optional |
| end_time | The end time until which to retrieve events. Supports relative time (for example, “1 hour ago”) or ISO 8601 (for example, “2026-01-01T12:00:00Z”). Defaults to the present moment. | Optional |
| limit | The maximum number of events to retrieve. Defaults to the instance level limit. | Optional |
| from_date | Deprecated. Use the start_time argument instead. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| Okta.Event.uuid | String | Unique identifier of the event. |
| Okta.Event.published | Date | Timestamp when the event was published. |
| Okta.Event.eventType | String | The type of the event. |
| Okta.Event.displayMessage | String | Human readable description of the event. |
| Okta.Event.severity | String | The severity of the event. |
Configuration parameters
url— Server URL (required)api_key— (required)limit— Number of events to fetch per fetch (required)after— First fetch from API time (required)verify— Trust any certificate (not secure)proxy— Use system proxy settingsisFetchEvents— Fetch eventseventFetchInterval— Events Fetch Interval
Commands (1)
-
okta-get-eventsManual command to fetch events and display them. Use for development and debugging only, as it may produce duplicate events or disrupt the fetch mechanism.
Okta Events collector XSIAM - Collects the events log for authentication and Audit provided by Okta admin API --- * **Server URL** - The API domain URL for Okta. * **API key** - The request API key. * **Number of incidents to fetch per fetch** - The total number of incidents to retrieve in each fetch cycle. * **First fetch time interval** - The period (in days) to retrieve events from, if no time is saved in the system. ## Step by step configuration **Server URL** - `https://<domain>.com` (where `domain` is your domain name). Do **not** append `/api/v1/logs` to the URL; the integration adds it automatically. To get help finding your domain, see: [https://developer.okta.com/docs/guides/find-your-domain/main/](https://developer.okta.com/docs/guides/find-your-domain/main/) **API key** - your API key **Number of incidents to fetch per fetch** - 10000 **Events fetch interval** - 01 Minutes **Fetches events** - True