Okta Security

eventTypeDescriptionSampleRule
security.attack.endFired when Threat Insight detects that an org is no longer under attack.NY
security.attack.startFired when Threat Insight detects that an org is under attack.NY
security.attack_protection.settings.updateTriggered when settings to protect against password-based attacks are updated.NN
security.authenticator.lifecycle.activateFired when an admin activates an authenticator for the org.YN
security.authenticator.lifecycle.createFired when an admin creates an authenticator for the org.NN
security.authenticator.lifecycle.deactivateFired when an admin deactivates an authenticator for the org.NN
security.authenticator.lifecycle.updateFired when an admin updates an authenticator in the org.YN
security.behavior.settings.createBehavior settings create.NN
security.behavior.settings.deleteBehavior settings delete.NN
security.behavior.settings.updateBehavior settings update.NN
security.breached_credential.detectedA credential, such as a password, which is associated with a known breach was used during an authentication flow.NN
security.device.add_request_blacklist_policyAdded request blacklist to request blacklist policies.NN
security.device.remove_request_blacklist_policyRemoved request blacklist from request blacklist policies.NN
security.device.temporarily_disable_blacklistingTemporarily disabling blacklisting.NN
security.events.provider.activateActivate a security events provider.NN
security.events.provider.createCreate a security events provider.NN
security.events.provider.deactivateDeactivate a security events provider.NN
security.events.provider.deleteDelete a security events provider.NN
security.events.provider.receive_eventAppears when a security events provider submits a valid event for each known detection.NN
security.events.provider.updateUpdate a security events provider.NN
security.events.transmitter.createCreate security events transmitter.NN
security.events.transmitter.deleteDelete security events transmitter.NN
security.events.transmitter.updateUpdate security events transmitter.NN
security.protected_action.attemptProtected action attempted.YN
security.protected_action.settings.updateProtected action setting disabled.NN
security.request.blockedSecurity request blocked.YN
security.session.detect_client_roamingRoaming session detected for user.NN
security.session_protection.status.updateSession Protection status was updated to monitoring or enforced.NN
security.threat.configuration.updateFired when a ThreatInsight configuration has been updated.NN
security.threat.detectedRequest from an IP identified as malicious by Okta ThreatInsight.YY
security.trusted_origin.activateA trusted origin is activated.YN
security.trusted_origin.createA trusted origin is created.YN
security.trusted_origin.deactivateA trusted origin is deactivated.YN
security.trusted_origin.deleteA trusted origin is deleted.YN
security.trusted_origin.updateA trusted origin is updated.YN
security.voice.add_country_blacklistFired when a country has been added to the voice call blacklist.NN
security.voice.remove_country_blacklistFired when a country has been removed from the voice call blacklist.NN
security.zone.make_blacklistAdded IPs to blacklist zone.NN
security.zone.remove_blacklistRemoved IPs from blacklist zone.NN

security.attack.end

#

Description

Fired when Threat Insight detects that an org is no longer under attack. This can be used to monitor when our models no longer detect an attack on an org. When this event is fired, Threat Insight will stop being extra aggressive in logging and/or blocking suspicious requests. This is fired from within an internal Okta context and therefore will not have any request level context information.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::client.ipAddress (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

security.attack.start

#

Description

Fired when Threat Insight detects that an org is under attack. This can be used to monitor attacks against your organization. When this event is fired, Threat Insight will automatically become more aggressive in logging and/or blocking suspicious requests. This is fired from within an internal Okta context and therefore will not have any request level context information.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
okta::client.ipAddress (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

YARA-L #

References #

security.attack_protection.settings.update

#

Description

Triggered when settings to protect against password-based attacks are updated. Useful for monitoring potential intrusion if the change was not planned. Covered features include Require possession factor before password during MFA and Block suspicious password attempts from unknown devices.

References #

security.authenticator.lifecycle.activate

#

Description

Fired when an admin activates an authenticator for the org. This event can be used to identify who activated an authenticator and which authenticator was activated. When fired, this event contains information about the authenticator type that was activated and the actor who activated the authenticator. Authenticator activation occurs when an authenticator is added. Related events include security.authenticator.lifecycle.deactivate.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

Example System Log Event #

{
  "published": 1784656596948,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000079",
  "actor": {
    "id": "00u00000000000000026",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000027"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "aut00000000000000280",
      "type": "Authenticator",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 93",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "security.authenticator.lifecycle.activate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000040",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "authenticatorKey": "webauthn",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000040",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000003",
      "url": "00000000000000000000000000000000000000000000000000000000000003?"
    }
  },
  "displayMessage": "Authenticator activated",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Device",
        "id": "bhv00000000000000031",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000032",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000033",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000034",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000035",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000036",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000037",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000038",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000281",
    "externalSessionId": "10200000000000000281"
  }
}

References #

security.authenticator.lifecycle.create

#

Description

Fired when an admin creates an authenticator for the org. This event can be used to identify who created an authenticator and which authenticator was created. The actor specifies the user that created the authenticator and the target specifies the authenticator name and the id. This event could also contain some authenticator specific information. Authenticator creation occurs when an authenticator is added. Related events include security.authenticator.lifecycle.update.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

security.authenticator.lifecycle.deactivate

#

Description

Fired when an admin deactivates an authenticator for the org. This event can be used to identify who deactivated an authenticator and which authenticator was deactivated. When fired, this event contains information about the authenticator type that was deactivated and the actor who deactivated the authenticator. Authenticator deactivation occurs when an authenticator is removed. Related events include security.authenticator.lifecycle.activate.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

References #

security.authenticator.lifecycle.update

#

Description

Fired when an admin updates an authenticator in the org. This event can be used to identify who updated an authenticator and which authenticator was updated. The actor specifies the user that updated the authenticator and the target specifies the authenticator name and the ID. There may be a second target with details of any authenticator method updates. This event could also contain authenticator specific information. Authenticator update occurs when an authenticator is edited. Related events include security.authenticator.lifecycle.create.

Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.

Example System Log Event #

{
  "published": 1780401778564,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000080",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "aut00000000000000282",
      "type": "Authenticator",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 94",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "security.authenticator.lifecycle.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000041",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "authenticatorKey": "okta_verify",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000041",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "0000000000000000000000000000000000000000013",
      "url": "0000000000000000000000000000000000000000013?"
    }
  },
  "displayMessage": "Authenticator updated",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000283",
    "externalSessionId": "10200000000000000283"
  }
}

References #

security.behavior.settings.create

#

Description

Behavior settings create. This can also be used to identify when a behavior setting is created. When fired, this event contains information about a created setting.

References #

security.behavior.settings.delete

#

Description

Behavior settings delete. This can also be used to identify when a behavior setting has been deleted. When fired, this event contains information about a delete setting.

References #

security.behavior.settings.update

#

Description

Behavior settings update. This can also be used to identify when a behavior setting has been changed. When fired, this event contains information about a updated setting.

References #

security.breached_credential.detected

#

Description

A credential, such as a password, which is associated with a known breach was used during an authentication flow. Used to identify users for whom credential rotation or other risk mitigation is necessary. The actor is the user with the breached credential. For Identity Engine, a target will indicate the specific credential associated with the breach. The outcome for this event will always be SUCCESS with a severity level of WARN. If breached credential protection is enabled, auser.session.clear will also be fired. These two events can be correlated by the Request ID.

References #

security.device.add_request_blacklist_policy

#

Description

Added request blacklist to request blacklist policies.

References #

security.device.remove_request_blacklist_policy

#

Description

Removed request blacklist from request blacklist policies.

References #

security.device.temporarily_disable_blacklisting

#

Description

Temporarily disabling blacklisting.

References #

security.events.provider.activate

#

Description

Activate a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is activated.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the activated security events provider.

References #

security.events.provider.create

#

Description

Create a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is created.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the created security events provider.

References #

security.events.provider.deactivate

#

Description

Deactivate a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is deactivated.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the deactivated security events provider.

References #

security.events.provider.delete

#

Description

Delete a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is deleted.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the deleted security events provider.

References #

security.events.provider.receive_event

#

Description

Appears when a security events provider submits a valid event for each known detection. The event helps admins debug or monitor SSF provider submissions. The event contains debug context data about the provider's risk report.

References #

security.events.provider.update

#

Description

Update a security events provider. Appears when an update is made to an authorized security events provider,such as the Shared Signals Framework (SSF) transmitter.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the updated security events provider.

References #

security.events.transmitter.create

#

Description

Create security events transmitter. Appears when a specific security events transmitter, such as the Shared Signals Framework (SSF) transmitter, is created. This event helps admins troubleshoot issues with event delivery to security event receivers. This event contains configuration details of the created security events transmitter.

References #

security.events.transmitter.delete

#

Description

Delete security events transmitter. Appears when a specific security events transmitter, such as the Shared Signals Framework (SSF) transmitter, is deleted. This event helps admins troubleshoot issues with event delivery to security events receivers. This event contains configuration details of the deleted security events transmitter.

References #

security.events.transmitter.update

#

Description

Update security events transmitter. Appears when there is an update to a specific security events transmitter, such as the Shared Signals Framework (SSF) transmitter. This event helps admins troubleshoot issues with event delivery to security events receivers. This event contains configuration details of the updated security events transmitter.

References #

security.protected_action.attempt

#

Description

Protected action attempted. This event can be used to track and audit when a protected action is attempted. When fired this event contains information about what protected action is attempted.

Example System Log Event #

{
  "published": 1785258176522,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000081",
  "actor": {
    "id": "00u00000000000000093",
    "type": "User",
    "alternateId": "user20@dw-harness.example",
    "displayName": "DW Harness 30",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0000000000000000000002",
      "type": "Protected Action",
      "alternateId": null,
      "displayName": "DW Harness 95",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "CHALLENGE",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "security.protected_action.attempt",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000042",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000042",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "000000000000000000000000000000000000000000000000000000000000002",
      "url": "000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Protected action attempted",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000142",
    "externalSessionId": "10200000000000000142"
  }
}

References #

security.protected_action.settings.update

#

Description

Protected action setting disabled. This event can be used to track and audit when a protected action setting is updated. When fired this event contains information about what protected action setting is updated.

References #

security.request.blocked

#

Description

Security request blocked.

Example System Log Event #

{
  "published": 1784429967280,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000082",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "app.example.com.android.auth/9.1.0 Android/16 samsung/SM-A566E XFTdLJQkTJmamujxdFhubw",
      "os": "Android",
      "browser": "UNKNOWN"
    },
    "zone": "DefaultEnhancedDynamicZone",
    "device": "Mobile",
    "id": null,
    "ipAddress": "192.0.2.28",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "nzo00000000000000284",
      "type": "Blocklist",
      "alternateId": null,
      "displayName": "DW Harness 96",
      "detailEntry": {
        "zoneNameMatch": "DefaultEnhancedDynamicZone"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": "NETWORK_ZONE_BLOCKLIST"
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.28",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "ipServiceCategories": [
            {
              "type": "VPN",
              "isAnonymous": true
            },
            {
              "operator": "NORD_VPN",
              "type": "VPN",
              "isAnonymous": true
            }
          ]
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "security.request.blocked",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000043",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "tunnels": [
        {
          "anonymous": true,
          "operator": "NORD_VPN",
          "type": "VPN"
        }
      ],
      "requestId": "00000000000000000000000000000043",
      "requestUri": "/.well-known/ov-configurations",
      "url": "/.well-known/ov-configurations?"
    }
  },
  "displayMessage": "Blocked request from IP: 192.0.2.29, IPServiceCategory: NORD_VPN",
  "gatewayContext": null,
  "legacyEventType": "security.zone.request.blocked",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": true,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "ipServiceCategories": [
        {
          "type": "VPN",
          "isAnonymous": true
        },
        {
          "operator": "NORD_VPN",
          "type": "VPN",
          "isAnonymous": true
        }
      ]
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

References #

security.session.detect_client_roaming

#

Description

Roaming session detected for user.

References #

security.session_protection.status.update

#

Description

Session Protection status was updated to monitoring or enforced. Indicates a change in the Session Protection status - (monitoring or enforced).

References #

security.threat.configuration.update

#

Description

Fired when a ThreatInsight configuration has been updated. This can be used to identify when an existing ThreatInsight configuration has been updated. An update can be updating the action or the excluded zones. When fired, this event contains information about who made the update to the configuration.

References #

security.threat.detected

#

Description

Request from an IP identified as malicious by Okta ThreatInsight. This can be used to monitor and act on credential based attacks (such as Brute Force, Password Spray) on your organization. The reasons why the request was classified as malicious can be found in the outcome.reason field. The outcome.result field will be 'ALLOW', 'DENY' or 'RATE_LIMIT' based on whether Okta Threat Insight is configured in log mode or log and enforce mode, where 'ALLOW' means the request continued, 'DENY' means the request was blocked and 'RATE_LIMIT' means we protected your org from exceeding your rate limit by not allowing suspicious activity to count towards your rate limit.

Example System Log Event #

{
  "actor": {
    "alternateId": "user07@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 17",
    "id": "000000000066",
    "type": "IP address"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": null,
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Mobile",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.9",
    "userAgent": {
      "browser": "CHROME",
      "os": "Android",
      "rawUserAgent": "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Mobile Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000067",
      "requestId": "00000000000000000000000000000068",
      "requestUri": "/api/internal/brand/theme/style-sheet",
      "threatDetections": {
        "Login Failures": "HIGH"
      },
      "threatSuspected": "true",
      "url": "/api/internal/brand/theme/style-sheet?touch-point=ERROR_PAGE&v=000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003"
    }
  },
  "device": null,
  "displayMessage": "Request from suspicious actor",
  "eventType": "security.threat.detected",
  "legacyEventType": "security.threat.detected",
  "outcome": {
    "reason": "Login Failures",
    "result": "DENY"
  },
  "published": "2024-03-28T08:39:54.374Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.9",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "WARN",
  "target": null,
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000068",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000009",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeeqsecurity.threat.detected2 rulessigma, splunk
okta::client.ipAddress (kusto rule field)is_not_null1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Okta ThreatInsight Threat Suspected Promotion source medium: Okta ThreatInsight is a feature that provides valuable debug data regarding authentication and authorization processes, which is logged in the system. Within this data, there is a specific field called threat_suspected, which represents Okta's internal evaluation of the authentication or authorization workflow. When this field is set to True, it suggests the presence of potential credential access techniques, such as password-spraying, brute-forcing, replay attacks, and other similar threats.

Splunk #

  • Okta ThreatInsight Threat Detected source: The following analytic identifies threats detected by Okta ThreatInsight, such as password spraying, login failures, and high counts of unknown user login attempts. It leverages Okta Identity Management logs, specifically focusing on…T1078, T1078.004

Kusto #

YARA-L #

Panther #

References #

security.trusted_origin.activate

#

Description

A trusted origin is activated. When an event is emitted upon the activation of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is activated.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000069",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "A trusted origin is activated",
  "eventType": "security.trusted_origin.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": "trusted origin is activated"
  },
  "published": "2026-07-02T18:55:00.403Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/activate",
      "url": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/activate?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "TrustedOrigin",
      "alternateId": null,
      "displayName": "DW Harness",
      "detailEntry": {
        "trustedOriginStatus": "INACTIVE",
        "trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
        "trustedOriginScopes": [
          {
            "type": "CORS"
          },
          {
            "type": "REDIRECT"
          }
        ]
      },
      "changeDetails": {
        "from": {
          "trustedOriginStatus": "INACTIVE"
        },
        "to": {
          "trustedOriginStatus": "ACTIVE"
        }
      }
    }
  ]
}

References #

security.trusted_origin.create

#

Description

A trusted origin is created. When an event is emitted upon the creation of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is created.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000070",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "A trusted origin is created",
  "eventType": "security.trusted_origin.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": "trusted origin is created"
  },
  "published": "2026-07-02T18:55:00.241Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/trustedOrigins",
      "url": "/api/v1/trustedOrigins?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "TrustedOrigin",
      "alternateId": null,
      "displayName": "DW Harness",
      "detailEntry": {
        "trustedOriginStatus": "ACTIVE",
        "trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
        "trustedOriginScopes": [
          {
            "type": "CORS"
          },
          {
            "type": "REDIRECT"
          }
        ]
      }
    }
  ]
}

References #

security.trusted_origin.deactivate

#

Description

A trusted origin is deactivated. When an event is emitted upon the deactivation of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is deactivated.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000071",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "A trusted origin is deactivated",
  "eventType": "security.trusted_origin.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": "trusted origin is deactivated"
  },
  "published": "2026-07-02T18:55:00.554Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/deactivate",
      "url": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/deactivate?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "TrustedOrigin",
      "alternateId": null,
      "displayName": "DW Harness",
      "detailEntry": {
        "trustedOriginStatus": "ACTIVE",
        "trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
        "trustedOriginScopes": [
          {
            "type": "CORS"
          },
          {
            "type": "REDIRECT"
          }
        ]
      },
      "changeDetails": {
        "from": {
          "trustedOriginStatus": "ACTIVE"
        },
        "to": {
          "trustedOriginStatus": "INACTIVE"
        }
      }
    }
  ]
}

References #

security.trusted_origin.delete

#

Description

A trusted origin is deleted. When an event is emitted upon the deletion of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is deleted.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000072",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "A trusted origin is deleted",
  "eventType": "security.trusted_origin.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": "trusted origin is deleted"
  },
  "published": "2026-07-02T18:55:00.638Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/trustedOrigins/tos00000000000000009",
      "url": "/api/v1/trustedOrigins/tos00000000000000009?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "TrustedOrigin",
      "alternateId": null,
      "displayName": "DW Harness",
      "detailEntry": {
        "trustedOriginStatus": "INACTIVE",
        "trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
        "trustedOriginScopes": [
          {
            "type": "CORS"
          },
          {
            "type": "REDIRECT"
          }
        ]
      },
      "changeDetails": {
        "from": {
          "displayName": "DW Harness",
          "trustedOriginScopes": [
            {
              "type": "CORS"
            },
            {
              "type": "REDIRECT"
            }
          ],
          "trustedOriginStatus": "INACTIVE",
          "trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com"
        },
        "to": null
      }
    }
  ]
}

References #

security.trusted_origin.update

#

Description

A trusted origin is updated. When an event is emitted upon the modification of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is updated.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000073",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "A trusted origin is updated",
  "eventType": "security.trusted_origin.update",
  "outcome": {
    "result": "SUCCESS",
    "reason": "trusted origin is updated"
  },
  "published": "2026-07-02T18:55:00.485Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/trustedOrigins/tos00000000000000009",
      "url": "/api/v1/trustedOrigins/tos00000000000000009?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "TrustedOrigin",
      "alternateId": null,
      "displayName": "DW Harness",
      "detailEntry": {
        "trustedOriginStatus": "ACTIVE",
        "trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
        "trustedOriginScopes": [
          {
            "type": "CORS"
          },
          {
            "type": "REDIRECT"
          }
        ]
      },
      "changeDetails": {
        "from": {
          "displayName": "DW Harness"
        },
        "to": {
          "displayName": "DW Harness"
        }
      }
    }
  ]
}

References #

security.voice.add_country_blacklist

#

Description

Fired when a country has been added to the voice call blacklist. This can be used to identify when a country has been blacklisted for voice call. When fired, this event contains information about the country that was added to the blacklist.Related events include security.voice.remove_country_blacklist.

References #

security.voice.remove_country_blacklist

#

Description

Fired when a country has been removed from the voice call blacklist. This can be used to identify when a country has been removed from voice call blacklist. When fired, this event contains information about the country that was removed from the blacklist.Related events include security.voice.add_country_blacklist.

References #

security.zone.make_blacklist

#

Description

Added IPs to blacklist zone.

References #

security.zone.remove_blacklist

#

Description

Removed IPs from blacklist zone.

References #