Ingest Authentication Logs and Data from Okta

Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
Ingesting external logs and data requires a Cortex XDR Pro per TB license.
To receive authentication logs and data from Okta, you must first configure the Data Collection settings in Cortex XDR. After you set up data collection, Cortex XDR immediately begins receiving new authentication logs and data from the source. The information from Okta is then searchable in Cortex XDR and can be included in authentication stories.
  1. Identify the domain name of your Okta service.
    From the Dashboard of your Okta console, note your
    Org URL
    .
    For more information, see the Okta Documentation.
  2. Obtain your authentication token in Okta.
    1. Select
      API
      Tokens
      .
    2. Create Token
      and record the token value.
      This is your only opportunity to record the value.
  3. Select
    Settings ( )
    Configurations
    Data Collection
    Collection Integrations
    .
  4. Integrate the Okta authentication service with Cortex XDR.
    1. Enter the
      OKTA DOMAIN
      (Org URL) that you identified on your Okta console.
    2. Enter the
      TOKEN
      used to authenticate with Okta.
    3. Test
      the connection settings.
    4. If successful,
      Enable
      Okta log collection.
  5. After Cortex XDR begins receiving information from the authentication service, you can Create an Authentication Query or Create an XQL Query to search for specific authentication data.

Recommended For You