You can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:
| Collection Method | Description |
| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard Collector overview | Forward logs and data to Cortex XSIAM from Okta using the Okta data source. |
| Link to Standard Collector instructions | <p>The following types of logs can be ingested from Okta:</p><ul><li>Activity logs</li></ul><p>For more information, see <a href="okta/ingest-logs-and-data-from-okta">Ingest logs and data from Okta</a>.</p> |
| Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/Okta/">Okta</a> content pack integrates with Okta's cloud-based identity management service to provide identity-centric visibility, enrichment, and automated response capabilities against threats. It contains automations, classifiers, modeling rules, parsing rules, playbooks, and scripts. It also includes the following integrations:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/okta-iam">Okta IAM</a>: Use this integration to interact with Okta's Identity Access Management service for executing CRUD operations related to employee lifecycle processes. It supports commands for selected features, such as those related to the Preference Center.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/okta-v2">Okta v2</a>: Use this integration to integrate with Okta's cloud-based identity management service. It includes commands such as <strong><code>okta-expire-password</code></strong>, which can optionally revoke existing sessions and require a password change at next login, and supports updating network zones and getting user information by email.</li><li><a href="https://xsoar.pan.dev/docs/reference/integrations/okta-event-collector">Okta Event Collector</a>: Use this integration to collect event logs for authentication and Audit provided by the Okta admin API. It supports fetching events and includes commands related to date parsing.</li></ul> |
| Link to connectors | <ul><li><a href="okta/okta-automation-and-collection">Okta Automation and Collection</a> (onboarded after July 26, 2026)</li><li><a href="okta/okta-connector">Okta connector</a></li></ul> |