OneLogin

You can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):

| Collection Method | Description |
| --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard Collector overview | Forward logs and data to Cortex XSIAM from OneLogin via the OneLogin REST APIs using the OneLogin data source. |
| Link to Standard Collector instructions | <p>The following types of data can be ingested from OneLogin:</p><ul><li><p>Log collection</p><ul><li>Events: User logins, administrative operations, provisioning, and a list of all OneLogin event types</li></ul></li><li><p>Directory</p><ul><li>Users: Lists of users.</li><li>Groups: Lists of groups.</li><li>Apps: Lists of apps.</li></ul></li></ul><p>For more information, see <a href="onelogin/ingest-logs-and-data-from-onelogin">Ingest logs and data from OneLogin</a>.</p> |
| Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/OneLogin">OneLogin</a> content pack provides capabilities for simple customer authentication and streamlined workforce identity operations utilizing APIs. It includes one modeling rule for data normalization and the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/one-login-event-collector">OneLogin Event Collector</a>: Use this integration to gather simple customer authentication and streamlined workforce identity operations with the <strong><code>onelogin-get-events</code></strong> command.</li></ul> |
| Link to connector (onboarded after July 26, 2026) | [OneLogin](onelogin/onelogin) |

Sub-topics