Okta System

eventTypeDescriptionSampleRule
system.agent.ad.config_change_detectedA monitored variable in an AD agent configuration file has changed.NY
system.agent.ad.connectConnect AD agent to Okta.NN
system.agent.ad.createCreate AD agent.NN
system.agent.ad.deactivateDeactivate AD agent.NN
system.agent.ad.deleteDelete AD agent.NN
system.agent.ad.dirsync.verifyVerify AD agent compatibility for DirSync-based imports.NN
system.agent.ad.import_ouPerform import OU by AD agent.NN
system.agent.ad.import_userPerform import user by AD agent.NN
system.agent.ad.invoke_dirPerform directory invoke command by AD agent.NN
system.agent.ad.reactivateReactivate AD agent.NN
system.agent.ad.read_configPerform config read by AD agent.NN
system.agent.ad.read_dirsyncPerform dirsync read by AD agent.NN
system.agent.ad.read_ldapPerform LDAP read by AD agent.NN
system.agent.ad.read_schemaPerform schema read by AD agent.NN
system.agent.ad.read_topologyDirectory agent performed topology import operation.NN
system.agent.ad.realtimesyncPerform RealTimeSync by AD agent.NN
system.agent.ad.reset_user_passwordPerform user password reset by AD agent.NN
system.agent.ad.startStart AD agent.NN
system.agent.ad.unlock_user_accountPerform unlock user account by AD agent.NN
system.agent.ad.updateUpdate AD agent configuration.NN
system.agent.ad.update_userUser Auth and Update.NN
system.agent.ad.upgradeUpgrade AD agent.NN
system.agent.ad.upload_iwa_logFired when an AD agent has fetched and uploaded IWA agent log file.NN
system.agent.ad.upload_logUpload AD agent log.NN
system.agent.ad.write_ldapPerform LDAP write by AD agent.NN
system.agent.auto_updateFired when an individual agent auto-update succeeds or fails.NN
system.agent.connector.connectConnect connector agent to Okta.NN
system.agent.connector.deactivateDeactivate connector agent.NN
system.agent.connector.deleteDelete connector agent.NN
system.agent.connector.reactivateReactivate connector agent.NN
system.agent.ldap.change_user_passwordPerform change user password by LDAP agent.NN
system.agent.ldap.config_change_detectedA monitored variable in an LDAP agent configuration file has changed.NN
system.agent.ldap.create_user_JITPerform create user JIT by LDAP agent.NN
system.agent.ldap.disconnectDisconnect LDAP agent from Okta.NN
system.agent.ldap.realtimesyncFired when LDAP Delegated Authentication is used to sign in and a user profile is updated using RealTimeSync action.NN
system.agent.ldap.reconnectReconnect LDAP agent to Okta.NN
system.agent.ldap.reset_user_passwordLDAP agent performed a password reset.NN
system.agent.ldap.unlock_user_accountLDAP agent performed account unlock for User.NN
system.agent.ldap.update_userFired when LDAP Delegated Authentication is used to sign in and a user profile is updated.NN
system.agent.ldap.update_user_passwordPerform update user password by LDAP agent.NN
system.agent.registerAgent was registered.NN
system.agent_pools.auto_updateFired when the status of an agent pool auto-update is changed.NN
system.api_token.createCreate API token.YY
system.api_token.enableEnable API token.NN
system.api_token.request_outside_allowed_rangeRequest with API tokens made from outside the allowed network zone.NN
system.api_token.revokeRevoke API token.YY
system.api_token.updateAn API token has been updated.YN
system.beta.feature.enableFired when an admin has enabled a BETA feature.NN
system.brand.createThis event is fired when the brand resource is created.NN
system.brand.deleteThis event is fired when a brand resource is deleted.NN
system.brand.updateThis event is fired when the brand resource is updated.NN
system.captcha.createA captcha instance is created for Sign-in Widget.NN
system.captcha.deleteA captcha instance is deleted.NN
system.captcha.updateA captcha instance is updated.NN
system.client.concurrency_rate_limit.notificationNotify when too many requests in flight for client.NN
system.client.concurrency_rate_limit.violationToo many requests in flight for client.YY
system.client.rate_limit.notificationNotify when client rate limits are exceeded.NN
system.client.rate_limit.violationClient rate limit violation.YY
system.csv.import_userImport of user from CSV is skipped.NN
system.custom_email_server.lifecycle.activateEnable a custom email server.NN
system.custom_email_server.lifecycle.createCreate a custom email server.NN
system.custom_email_server.lifecycle.deactivateDisable a custom email server.NN
system.custom_email_server.lifecycle.deleteDelete a custom email server.NN
system.custom_email_server.lifecycle.updateUpdate a custom email server.NN
system.custom_error.deleteCustom error page is deleted.NN
system.custom_error.updateCustom error page is updated.NN
system.custom_signin.deleteCustom sign-in page is deleted.NN
system.custom_signin.updateCustom sign-in page is updated.NN
system.custom_signout.updateCustom sign-out page is updated.NN
system.custom_url_domain.cert_renewOkta managed certificates for custom domain are renewed.NN
system.custom_url_domain.cert_uploadCustom domain certificates are uploaded by an admin or generated by Okta.NN
system.custom_url_domain.deleteCustom domain is deleted.NN
system.custom_url_domain.initiateCustom domain setup is initiated.NN
system.custom_url_domain.updateCustom domain brand association is updated.NN
system.custom_url_domain.verifyVerify custom domain ownership.NN
system.directory.debugger.extendExtend Directory Debugger access for Okta support.NN
system.directory.debugger.grantGrant Directory Debugger access for Okta support.NN
system.directory.debugger.query_executedA read-only query executed against AD/LDAP instance by Okta support using the Directory Debugger tool.NN
system.directory.debugger.revokeRevoke Directory Debugger access for Okta support.NN
system.dr.failbackThe Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated.NN
system.dr.failoverThe Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated.NN
system.email.account_unlock.sent_messageSend self-service account unlock email.NY
system.email.bounce.removalAttempted removal of one or more emails from bounce list.NN
system.email.challenge_factor_redeemedUser completed an email factor challenge.YN
system.email.deliveryAn email's delivery status was updated.YN
system.email.mfa_enroll_notification.sent_messageMFA enrollment notification email sent.YN
system.email.mfa_reset_notification.sent_messageMFA reset notification email sent.YN
system.email.new_device_notification.sent_messageNew device signin notification email sent.YN
system.email.password_reset.sent_messageSend self-service password reset email.YY
system.email.send_factor_verify_messageAn email was sent to a user for verification.NN
system.email.template.createThis event is fired when a custom email template is created.NN
system.email.template.deleteThis event is fired when a custom email template is deleted.NN
system.email.template.settings_changedThis event is fired when the settings for an email template is changed.NN
system.email.template.updateThis event is fired when a custom email template has been updated.NN
system.email_domain.createEmail domain is created.NN
system.email_domain.deleteEmail domain is deleted.NN
system.email_domain.updateEmail domain is updated.NN
system.email_domain.verifyVerify email domain.NN
system.feature.disableFired when self service features are requested to be disabled by admins.NN
system.feature.ea_auto_enrollFired when an org has subscribed to or unsubscribed from EA Feature Auto Enroll.NN
system.feature.enableFired when self service features are requested to be enabled by admins.NN
system.hook.key.createdCreate a new hook key.NN
system.hook.key.deletedDelete a hook key.NN
system.hook.key.updatedUpdate a hook key.NN
system.identity_sources.bulk_deleteUpload bulk delete data.NN
system.identity_sources.bulk_group_deleteUpload bulk groups delete data.NN
system.identity_sources.bulk_group_membership_deleteUpload bulk group membership delete data.NN
system.identity_sources.bulk_group_membership_upsertUpload bulk group membership upsert data.NN
system.identity_sources.bulk_group_upsertUpload bulk groups upsert data.NN
system.identity_sources.bulk_upsertUpload bulk upsert data.NN
system.identity_sources.group.createCreate an identity source group.NN
system.identity_sources.group.deleteDelete an identity source group.NN
system.identity_sources.group.updateUpdate an identity source group.NN
system.identity_sources.group.user.assignAssign a user to an identity source group.NN
system.identity_sources.group.user.revokeRevoke a user from an identity source group.NN
system.identity_sources.user.createCreate an identity source user.NN
system.identity_sources.user.deleteDelete an identity source user.NN
system.identity_sources.user.updateUpdate an identity source user.NN
system.idp.key.createIdentity provider key credential created.NN
system.idp.key.deleteIdentity provider key credential deleted.NN
system.idp.key.updateIdentity provider key credential updated.NN
system.idp.lifecycle.activateIdentity provider activated.YY
system.idp.lifecycle.createIdentity provider created.YY
system.idp.lifecycle.deactivateIdentity provider deactivated.YY
system.idp.lifecycle.deleteIdentity provider deleted.YY
system.idp.lifecycle.read_client_secretIdentity provider(s) with a client secret is read.YY
system.idp.lifecycle.updateIdentity provider updated.YY
system.import.clear.unconfirmed.users.summaryClear Unconfirmed Imported Users.NN
system.import.completeImport process complete.YN
system.import.complete_batchBatch import process complete.YN
system.import.custom_object.completeImport of custom objects completed.YN
system.import.custom_object.createCreate custom object triggered by import process.NN
system.import.custom_object.deleteDelete custom object triggered by import process.NN
system.import.custom_object.updateUpdate custom object triggered by import process.NN
system.import.download.completeFired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import.YN
system.import.download.startFired at the start of the download objects phase, when the objects (users, groups, devices) to be imported are being downloaded from the system of record.YN
system.import.entitlementEmitted during the entitlement discovery process to identify entitlement schemas, excluding assignments.NN
system.import.entitlement.mismatchSkipping of entitlement during import of an user.NN
system.import.group.completeImport of groups completed.YN
system.import.group.createCreate group triggered by import process.NN
system.import.group.deleteRemove group triggered by import process.NN
system.import.group.startStart importing groups from refreshing AppGroups.YN
system.import.group.updateUpdate group triggered from import process.NN
system.import.group_membership.completeImport of application group members completed.YN
system.import.implicit_deletion.completeFired upon completion of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects.YN
system.import.implicit_deletion.startFired at the start of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects.YN
system.import.import_profileImport user profile triggered by import process.NN
system.import.import_provisioning_infoImport provisioning info triggered by import process.YN
system.import.membership_processing.completeFired upon completion of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from.YN
system.import.membership_processing.startFired at the start of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from.YN
system.import.object_creation.completeFired upon completion of the object creation phase, when the first batch of objects is created/updated.YN
system.import.object_creation.startFired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import.YN
system.import.roadblockImport roadblock triggered due to exceeded threshold.NN
system.import.roadblock.reschedule_and_resumeThe affected import from AppInstance has been rescheduled.NN
system.import.roadblock.resumeThe affected import from AppInstance has been canceled.NN
system.import.roadblock.updatedFired when an import roadblock (aka, Import Safeguard) has been updated.NN
system.import.scheduleImport process was scheduled.YN
system.import.session.cancelledImport session for identity source canceled.NN
system.import.session.createdCreate new import session for identity source.NN
system.import.session.expiredImport session for identity source expired.NN
system.import.session.triggeredTriggered import session for identity source.NN
system.import.startimport started.YN
system.import.user.completeImport of user completed.YN
system.import.user.createCreate user triggered by import process.YN
system.import.user.deleteDelete user triggered by import process.YN
system.import.user.matchAssign user triggered by import process with callback.NN
system.import.user.startStart importing users triggered import process.NN
system.import.user.suspendSuspend user triggered by import process.NN
system.import.user.unsuspendUnsuspend user triggered by import process.NN
system.import.user.unsuspend_after_confirmNN
system.import.user.updateUpdate user triggered by import process.YN
system.import.user.update_user_lifecycle_from_masterUpdate user status triggered by import process.NN
system.import.user_csv.completeBulk Import users from CSV is completed.NN
system.import.user_csv.startBulk Import of users from CSV is started.NN
system.import.user_match.confirmImport user matching assignment confirmed.YN
system.import.user_match.unignoreAssignment was unignored.NN
system.import.user_match.updateAssignment was modified.NN
system.import.user_matching.completeFired upon completion of the user matching phase, when Okta attempts to match imported users to existing Okta users.YN
system.import.user_matching.startFired at the start of the user matching phase, when Okta attempts to match imported users to existing Okta users.YN
system.iwa.createCreate IWA agent.NN
system.iwa.go_offlineIWA going offline.NN
system.iwa.go_onlineIWA going online.NN
system.iwa.promote_primaryPromote IWA agent to primary.NN
system.iwa.removeRemove IWA agent.NN
system.iwa.updateUpdate IWA agent.NN
system.iwa.use_defaultNo primary IWA app found.NN
system.iwa_agentless.authAgentless IWA authentication.NN
system.iwa_agentless.auth_after_redirectFired after redirection from Agentless DSSO failure.NN
system.iwa_agentless.redirectFired when an Agentless DSSO authentication request is redirected to an onprem IWA authentication or the default login page.NN
system.iwa_agentless.updateUpdate to agentless IWA.NN
system.iwa_agentless.user.not_foundFired when a user could not be found during Agentless DSSO authentication, resulting in an authentication failure.NN
system.iwa_agentless_kerberos.updateFires when a Kerberos realm settings is updated by an admin.NN
system.ldapi.admin_limit_exceededThis event indicates that an administrative limit was exceeded when processing an LDAP interface operation.NN
system.ldapi.bindFired when a user performs a BIND to LDAP Interface.NN
system.ldapi.searchFired when a user performs a SEARCH to LDAP Interface.NN
system.ldapi.unbindFired when a user performs an UNBIND to LDAP Interface.NN
system.log_stream.lifecycle.activateLog stream activated.YN
system.log_stream.lifecycle.createLog stream created.YN
system.log_stream.lifecycle.deactivateLog stream deactivated.YN
system.log_stream.lifecycle.deleteLog stream deleted.YN
system.log_stream.lifecycle.updateLog stream updated.YN
system.mfa.factor.activateActivate a new authentication factor.YN
system.mfa.factor.deactivateDeactivate MFA factor.NY
system.oauth2.token.request_outside_allowed_rangeRequest with valid bearer tokens made from outside the allowed network zone.NN
system.operation.concurrency_limit.violationOperation concurrency limit violation.YN
system.operation.rate_limit.violationOperation rate limit violation.YY
system.operation.rate_limit.warningOperation rate limit warning.NN
system.org.captcha.activateEnable org-wide captcha support.NN
system.org.captcha.deactivateDisable org-wide captcha support.NN
system.org.lifecycle.createOrg creation.NN
system.org.rate_limit.burstFired when burst rate limit capacity is activated.YN
system.org.rate_limit.expiration.warningRate limit approaching expiration date.NN
system.org.rate_limit.violationRate limit violation.YY
system.org.rate_limit.warningRate limit warning.YY
system.org.task.removeTasks removed.NN
system.push.send_factor_verify_pushFired when a Push notification is sent to a device.YY
system.rate_limit.configuration.updateRate limit configuration update.NN
system.self_service.configuration.updateSelf-service for apps configuration updated.YN
system.sms.receive_statusFired when receiving a status update on SMS message from provider.NN
system.sms.send_account_unlock_messageSend self-service account unlock SMS message.NY
system.sms.send_factor_verify_messageSend second factor auth SMS.NN
system.sms.send_okta_push_verify_messageSend activate Okta Verify Push for mobile SMS.NN
system.sms.send_password_reset_messageSend self-service password reset SMS message.NY
system.sms.send_phone_verification_messageSend phone verification SMS message.NN
system.theme.updateThis event is fired when the theme resource is updated.NN
system.voice.receive_statusFired when receiving a status update on voice call from provider.NN
system.voice.send_account_unlock_callSend self-service account unlock call.NY
system.voice.send_callSend phone call.NN
system.voice.send_mfa_challenge_callSend second factor auth call.NN
system.voice.send_password_reset_callSend self-service password reset call.NY
system.voice.send_phone_verification_callSend phone verification call.NN
system.well_known_uri.updateThe well-known URI was updated.NN
system.identity_sources.bulk_device_deleteUpload bulk devices delete data.NN
system.identity_sources.bulk_device_upsertUpload bulk devices upsert data.NN

system.agent.ad.config_change_detected

#

Description

A monitored variable in an AD agent configuration file has changed. This can be used to audit that a customer's AD agent configuration file has changed. This event occurs when a monitored variable in an AD agent configuration file has changed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Okta AD Agent Token Abuse - Behavioral source high linked query: Query.Okta.ADAgentTokenAbuseBehavioral: Detects potential Okta AD Agent token theft and abuse using behavioral analysis. Instead of relying on hardcoded service account patterns, this detection identifies when AD agent-related activities (API token creation, agent registration, config changes) occur from previously unseen IP addresses or user agents. This behavioral approach adapts to your environment and catches anomalous access patterns that may indicate compromised credentials or unauthorized token generation. What This Detection Catches: - API token creation from new IPs or user agents - New AD agent registrations from unexpected sources - AD agent configuration changes from new locations Complementary Detection: Use alongside Okta.ADAgent.AuthenticationAnomaly.ZScore which detects the actual USE of stolen tokens through authentication pattern anomalies.T1098, T1528↳ also matches system.api_token.create
  • Query.Okta.ADAgentTokenAbuseBehavioral source: Detects API token creation and AD agent activity from previously unseen IP addresses or user agents. Uses behavioral analysis to identify anomalous token creation patterns.↳ also matches system.api_token.create

References #

system.agent.ad.connect

#

Description

Connect AD agent to Okta.

References #

system.agent.ad.create

#

Description

Create AD agent.

References #

system.agent.ad.deactivate

#

Description

Deactivate AD agent.

References #

system.agent.ad.delete

#

Description

Delete AD agent.

References #

system.agent.ad.dirsync.verify

#

Description

Verify AD agent compatibility for DirSync-based imports. Use this event to audit which AD agents meet DirSync requirements, set up alerts when agents need remediation before DirSync-based imports can run, and troubleshoot import failures related to agent version or configuration gaps. outcome.result = SUCCESS indicates the agent meets all DirSync requirements. FAILURE indicates the agent requires intervention, such as a version upgrade (minimum 3.20.0) or service account permission changes.

References #

system.agent.ad.import_ou

#

Description

Perform import OU by AD agent.

References #

system.agent.ad.import_user

#

Description

Perform import user by AD agent.

References #

system.agent.ad.invoke_dir

#

Description

Perform directory invoke command by AD agent.

References #

system.agent.ad.reactivate

#

Description

Reactivate AD agent.

References #

system.agent.ad.read_config

#

Description

Perform config read by AD agent.

References #

system.agent.ad.read_dirsync

#

Description

Perform dirsync read by AD agent.

References #

system.agent.ad.read_ldap

#

Description

Perform LDAP read by AD agent.

References #

system.agent.ad.read_schema

#

Description

Perform schema read by AD agent.

References #

system.agent.ad.read_topology

#

Description

Directory agent performed topology import operation.

References #

system.agent.ad.realtimesync

#

Description

Perform RealTimeSync by AD agent.

References #

system.agent.ad.reset_user_password

#

Description

Perform user password reset by AD agent.

References #

system.agent.ad.start

#

Description

Start AD agent.

References #

system.agent.ad.unlock_user_account

#

Description

Perform unlock user account by AD agent.

References #

system.agent.ad.update

#

Description

Update AD agent configuration.

References #

system.agent.ad.update_user

#

Description

User Auth and Update.

References #

system.agent.ad.upgrade

#

Description

Upgrade AD agent.

References #

system.agent.ad.upload_iwa_log

#

Description

Fired when an AD agent has fetched and uploaded IWA agent log file. This event fires when the log file upload is successful or fails. This can be used to audit that logs files are being fetched successfully, have been uploaded successfully, and troubleshoot why an IWA log upload has failed. When fired, this event indicates whether a log file upload has been successful or failed. This event also indicates whether the event was initiated by the Okta system or a user. Related events: none, all debugging context is included in this event.

References #

system.agent.ad.upload_log

#

Description

Upload AD agent log.

References #

system.agent.ad.write_ldap

#

Description

Perform LDAP write by AD agent.

References #

system.agent.auto_update

#

Description

Fired when an individual agent auto-update succeeds or fails. Confirms a successful agent auto-update, or provides troubleshooting information when the agent auto-update is unsuccessful. Indicates when an agent auto-update is successful or unsuccessful.

References #

system.agent.connector.connect

#

Description

Connect connector agent to Okta.

References #

system.agent.connector.deactivate

#

Description

Deactivate connector agent.

References #

system.agent.connector.delete

#

Description

Delete connector agent.

References #

system.agent.connector.reactivate

#

Description

Reactivate connector agent.

References #

system.agent.ldap.change_user_password

#

Description

Perform change user password by LDAP agent.

References #

system.agent.ldap.config_change_detected

#

Description

A monitored variable in an LDAP agent configuration file has changed. This can be used to audit when a customer's LDAP agent configuration file has changed. This event occurs when a monitored variable in an LDAP agent configuration file has changed.

References #

system.agent.ldap.create_user_JIT

#

Description

Perform create user JIT by LDAP agent.

References #

system.agent.ldap.disconnect

#

Description

Disconnect LDAP agent from Okta.

References #

system.agent.ldap.realtimesync

#

Description

Fired when LDAP Delegated Authentication is used to sign in and a user profile is updated using RealTimeSync action. Can be used by admins to identify user profile changes resulting from corresponding changes in the LDAP directory. The previous name for this event was system.agent.ad.realtimesync.

References #

system.agent.ldap.reconnect

#

Description

Reconnect LDAP agent to Okta.

References #

system.agent.ldap.reset_user_password

#

Description

LDAP agent performed a password reset.

References #

system.agent.ldap.unlock_user_account

#

Description

LDAP agent performed account unlock for User.

References #

system.agent.ldap.update_user

#

Description

Fired when LDAP Delegated Authentication is used to sign in and a user profile is updated. Can be used by admins to identify user profile changes resulting from corresponding changes in the LDAP directory. The previous name for this event was system.agent.ad.update_user.

References #

system.agent.ldap.update_user_password

#

Description

Perform update user password by LDAP agent.

References #

system.agent.register

#

Description

Agent was registered. This event indicates that an agent (such as Okta Provisioning Agent, Okta RSA SecurID Agent, and so on) has been successfully registered with the Okta org. This also provides a signal to all admins of the Okta org that a new agent was registered, which improves the overall security posture. This event can be used to track the deployment and integration of Okta agents across an org's infrastructure. This information can be useful for security audits, compliance reporting, and managing the overall Okta ecosystem.

References #

system.agent_pools.auto_update

#

Description

Fired when the status of an agent pool auto-update is changed. Confirms an agent pool auto-update status change and provides troubleshooting information. Indicates when the status of an agent pool auto-update is changed.

References #

system.api_token.create

#

Description

Create API token. This event occurs when a new unscoped API token is generated within the system. The unscoped API token grants authenticated access to the system's API for automated tasks or integration purposes. Event log details include the token ID, the user, or service it was created for, and the time of creation. This information helps maintain a secure API access framework by allowing administrators to track token issuance. Administrators can also enforce least privilege access and promptly identify any unauthorized token creation.

Example System Log Event #

{
  "actor": {
    "alternateId": "user11@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 18",
    "id": "00u00000000000000017",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000074",
    "interface": null,
    "issuer": null
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.10",
    "userAgent": {
      "browser": "CHROME",
      "os": "Mac OS 14.3.1 (Sonoma)",
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "concurrencyPercentage": "50",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000075",
      "rateLimitPercentage": "50",
      "requestId": "00000000000000000000000000000076",
      "requestUri": "/api/internal/tokens",
      "url": "/api/internal/tokens?expand=user"
    }
  },
  "device": null,
  "displayMessage": "Create API token",
  "eventType": "system.api_token.create",
  "legacyEventType": "api.token.create",
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2024-03-06T20:08:34.848Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.10",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "INFO",
  "target": [
    {
      "alternateId": "user07@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 19",
      "id": "00T00000000000000018",
      "type": "Token"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000076",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000010",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeeqsystem.api_token.create2 rulespanther, sigma
okta::eventType (kusto rule field)insystem.api_token.create2 ruleskusto
okta::eventType (kusto rule field)inpolicy.evaluate_sign_on1 rulekusto
All_Changes.action (splunk rule field)eqcreated1 rulesplunk
outcome.result (panther rule field)eqSUCCESS1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • Attempt to Create Okta API Token source medium: Detects attempts to create an Okta API token. An adversary may create an Okta API token to maintain access to an organization's network while they work to achieve their objectives. An attacker may abuse an API token to execute techniques such as creating user accounts or disabling security rules or policies.T1098, T1098.001, T1136

Splunk #

  • Okta New API Token Created source: The following analytic detects the creation of a new API token within an Okta tenant. It uses OktaIm2 logs ingested via the Splunk Add-on for Okta Identity Cloud to identify events where the system.api_token.create command is executed.…T1078, T1078.001

Kusto #

  • High-Risk Admin Activity source medium: The Okta risk engine auto-assigns risk levels to each login attempt. This rule identifies successful admin operations that correlate with successful high-risk Okta authentication or session start events.T1078, T1078.004, T1098
  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches system.api_token.revoke, system.mfa.factor.deactivate

YARA-L #

Panther #

  • Okta API Key Created source informational: A user created an API Key in OktaT1528
  • Okta AD Agent Token Abuse - Behavioral source high linked query: Query.Okta.ADAgentTokenAbuseBehavioral: Detects potential Okta AD Agent token theft and abuse using behavioral analysis. Instead of relying on hardcoded service account patterns, this detection identifies when AD agent-related activities (API token creation, agent registration, config changes) occur from previously unseen IP addresses or user agents. This behavioral approach adapts to your environment and catches anomalous access patterns that may indicate compromised credentials or unauthorized token generation. What This Detection Catches: - API token creation from new IPs or user agents - New AD agent registrations from unexpected sources - AD agent configuration changes from new locations Complementary Detection: Use alongside Okta.ADAgent.AuthenticationAnomaly.ZScore which detects the actual USE of stolen tokens through authentication pattern anomalies.T1098, T1528↳ also matches system.agent.ad.config_change_detected
  • Query.Okta.ADAgentTokenAbuseBehavioral source: Detects API token creation and AD agent activity from previously unseen IP addresses or user agents. Uses behavioral analysis to identify anomalous token creation patterns.↳ also matches system.agent.ad.config_change_detected

References #

system.api_token.enable

#

Description

Enable API token.

References #

system.api_token.request_outside_allowed_range

#

Description

Request with API tokens made from outside the allowed network zone. Use to detect when an API token comes from an IP address that's outside of the specified allowed zone. Fired when an API token comes from an IP address that's outside of the specified allowed zone of the token.

References #

system.api_token.revoke

#

Description

Revoke API token.

Example System Log Event #

{
  "published": 1780768813892,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000085",
  "actor": {
    "id": "0000003",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00t00000000000000288",
      "type": "Token",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 99",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.api_token.revoke",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "00000000000000000000000000000045",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Revoke API token",
  "gatewayContext": null,
  "legacyEventType": "api.token.revoke",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventTypeeqsystem.api_token.revoke2 rulespanther, sigma
outcome.result (panther rule field)eqSUCCESS1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches system.api_token.create, system.mfa.factor.deactivate

Panther #

References #

system.api_token.update

#

Description

An API token has been updated. This event can be used to identify a change to an existing API token, such as a change to the applicable rate limits for the token. Details of the change can be found in the debugData. This event does not change whether the token is valid for use, for actions that impact validity see system.api_token.enable and system.api_token.revoke.

Example System Log Event #

{
  "published": 1784123665870,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000086",
  "actor": {
    "id": "00u00000000000000026",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000027"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00t00000000000000289",
      "type": "Token",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 100",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.api_token.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000046",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "concurrencyPercentage": "50",
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "includedNetworkZones": "[nzo00000000000000290]",
      "requestId": "00000000000000000000000000000046",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "origin": "https://app.example.com",
      "rateLimitPercentage": "50",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "networkConnection": "ZONE",
      "requestUri": "0000000000000000000000000000000000000000000000000000000002",
      "url": "0000000000000000000000000000000000000000000000000000000002?expand=Example App 61"
    }
  },
  "displayMessage": "Update API token",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Device",
        "id": "bhv00000000000000031",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000032",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000033",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000034",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000035",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000036",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000037",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000038",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000291",
    "externalSessionId": "10200000000000000291"
  }
}

References #

system.beta.feature.enable

#

Description

Fired when an admin has enabled a BETA feature. This can be used to understand the status of the BETA Feature and identify who has enabled it for an org. When fired, this event contains information about the enabled BETA Feature, as well as the admin who enabled it.

References #

system.brand.create

#

Description

This event is fired when the brand resource is created. Developer and org admins can use this event to identify when the brand resource was created. The event contains information about the created brand.

References #

system.brand.delete

#

Description

This event is fired when a brand resource is deleted. Developer and org admins can use this event to identify when a brand resource was deleted. The event contains information about a deleted brand.

References #

system.brand.update

#

Description

This event is fired when the brand resource is updated. Developer and org admins can use this event to identify when the brand resource was updated. The event contains information regarding specific updates made to brand like "customPrivacyPolicyUrl".

References #

system.captcha.create

#

Description

A captcha instance is created for Sign-in Widget. Indicates when a captcha instance was created. This event is fired when org admin creates a captcha instance.

References #

system.captcha.delete

#

Description

A captcha instance is deleted. Indicates when a captcha instance was deleted. This event is fired when org admin deletes a captcha instance.

References #

system.captcha.update

#

Description

A captcha instance is updated. Indicates when a captcha instance was updated. This event is fired when org admin updates a captcha instance.

References #

system.client.concurrency_rate_limit.notification

#

Description

Notify when too many requests in flight for client. This can be used to notify whenever there are too many concurrent requests from a client without enforcing any violation. When fired, this event contains information about the request such as client, device and ip details.

References #

system.client.concurrency_rate_limit.violation

#

Description

Too many requests in flight for client. This can be used to track if there are too many concurrent requests from a client. When fired, this event contains information about the request such as client, device and ip details.

Example System Log Event #

{
  "published": 1780867129756,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000087",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "fasthttp",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "192.0.2.36",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000292",
      "type": "PublicClientApp",
      "alternateId": null,
      "displayName": "DW Harness 101",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.36",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "system.client.concurrency_rate_limit.violation",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000047",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000292",
      "clientType": "OAUTH2",
      "requestId": "00000000000000000000000000000047",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000026",
      "ip": "192.0.2.36",
      "threshold": "5",
      "requestUri": "/oauth2/v1/authorize",
      "threatSuspected": "false",
      "orgId": "00o00000000000000286",
      "url": "/oauth2/v1/authorize?client_id=2uw00000000000000293&redirect_uri=00000000000000000000000000000000000000000000000002&scope=xki00000000000000294&response_type=code&state=00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002"
    }
  },
  "displayMessage": "Too many requests in flight for client",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

system.client.rate_limit.notification

#

Description

Notify when client rate limits are exceeded. This can be used to notify whenever a client is exceeding its rate limit without enforcing any violation. When fired, this event contains information about the request such as client, device and ip details.

References #

system.client.rate_limit.violation

#

Description

Client rate limit violation. This can be used to track if a client is exceeding its rate limit. When fired, this event contains information about the request such as client, device and ip details.

Example System Log Event #

{
  "published": 1784282811881,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000088",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36",
      "os": "Windows 10",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.30",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000292",
      "type": "PublicClientApp",
      "alternateId": null,
      "displayName": "DW Harness 101",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.30",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com",
          "ipServiceCategories": [
            {
              "type": "Proxy",
              "isAnonymous": false
            }
          ]
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "system.client.rate_limit.violation",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000048",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "clientId": "0oa00000000000000292",
      "ip": "192.0.2.30",
      "threshold": "60",
      "requestUri": "/oauth2/v1/authorize",
      "orgId": "00o00000000000000286",
      "url": "/oauth2/v1/authorize?client_id=c2c00000000000000295&redirect_uri=00000000000000000000000000000000000000000000000002&scope=ceo00000000000000296&response_type=code&state=000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002",
      "deviceTokenHash": "0000000000000000000000000000000000000000014=",
      "clientType": "OAUTH2",
      "requestId": "00000000000000000000000000000048",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000027",
      "timeSpan": "1",
      "threatSuspected": "false",
      "timeUnit": "MINUTES"
    }
  },
  "displayMessage": "Client rate limit violation",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000003",
    "externalSessionId": "0000003"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

system.csv.import_user

#

Description

Import of user from CSV is skipped. Informs when import of a user from CSV has been skipped due to reasons such as missing required attributes or unknown unique identifier. This event is logged when import of a user is skipped during CSV directory import workflow for on-premises systems using Okta provisioning agent.

References #

system.custom_email_server.lifecycle.activate

#

Description

Enable a custom email server. Audit the enablement of a custom email server.

References #

system.custom_email_server.lifecycle.create

#

Description

Create a custom email server. Audit the creation of a custom email server.

References #

system.custom_email_server.lifecycle.deactivate

#

Description

Disable a custom email server. Audit the disablement of a custom email server.

References #

system.custom_email_server.lifecycle.delete

#

Description

Delete a custom email server. Audit the deletion of a custom email server.

References #

system.custom_email_server.lifecycle.update

#

Description

Update a custom email server. Audit an update to the configuration of a custom email server.

References #

system.custom_error.delete

#

Description

Custom error page is deleted. Can be used to identify when an admin has deleted the custom error page. Event fired when the custom error page is deleted.

References #

system.custom_error.update

#

Description

Custom error page is updated. Can be used to identify when an admin has customized the error page. Event fired when the error page is successfully updated.

References #

system.custom_signin.delete

#

Description

Custom sign-in page is deleted. Can be used to identify when an admin has deleted the custom sign-in page. Event fired when custom sign-in page is deleted.

References #

system.custom_signin.update

#

Description

Custom sign-in page is updated. Can be used to identify when an admin has customized the sign-in page. Event fired when custom sign-in page is updated.

References #

system.custom_signout.update

#

Description

Custom sign-out page is updated. Admin has updated the custom sign-out page. Event fired when custom sign-out page is updated.

References #

system.custom_url_domain.cert_renew

#

Description

Okta managed certificates for custom domain are renewed. Can be used to identify when okta managed certificate renewal batch job has renewed certificates for custom domain. When fired, the event contains information about the domain name and certificate source type.

References #

system.custom_url_domain.cert_upload

#

Description

Custom domain certificates are uploaded by an admin or generated by Okta. Can be used to identify when custom domain certificates are uploaded by an admin or generated by Okta. When fired, the event contains information about the domain name and certificate source type.

References #

system.custom_url_domain.delete

#

Description

Custom domain is deleted. Can be used to identify when an admin has deleted their custom domain. When fired, the event contains information about the domain name that was deleted.

References #

system.custom_url_domain.initiate

#

Description

Custom domain setup is initiated. Admin has initiated custom domain setup by inputting their custom domain for DNS verification. When fired, the event contains information about the domain name, certificate source type and domain validation status.

References #

system.custom_url_domain.update

#

Description

Custom domain brand association is updated. Admin has updated the custom domain association with the brand. When fired, the event contains the domain name, certificate source type, domain validation status and information about the brand it is associated with.

References #

system.custom_url_domain.verify

#

Description

Verify custom domain ownership. Identifies whether an admin has succeeded or failed to verify the ownership of the domain name. When fired, the event contains information about the domain name, certificate source type and domain validation status.

References #

system.directory.debugger.extend

#

Description

Extend Directory Debugger access for Okta support. This can be used to audit the Directory Debugger access extension. When fired, this event contains information about Directory Debugger access extension.

References #

system.directory.debugger.grant

#

Description

Grant Directory Debugger access for Okta support. This can be used to audit the Directory Debugger access grants to Okta support. When fired, this event contains information about Directory Debugger access grant.

References #

system.directory.debugger.query_executed

#

Description

A read-only query executed against AD/LDAP instance by Okta support using the Directory Debugger tool. This can be used to audit the queries executed by Okta support using Directory Debugger. When fired, this event contains information about Directory Debugger query.

References #

system.directory.debugger.revoke

#

Description

Revoke Directory Debugger access for Okta support. This can be used to audit the Directory Debugger access revoke. When fired, this event contains information about Directory Debugger access revoke.

References #

system.dr.failback

#

Description

The Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. Triggered when the Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. This event is fired when the Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. If failback is successful, the outcome for this event will be SUCCESS. If failback is not successful, the outcome for this event will be FAILURE.

References #

system.dr.failover

#

Description

The Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. Triggered when the Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. This event is fired when the Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. If failover is successful, the outcome for this event will be SUCCESS. If failover is not successful, the outcome for this event will be FAILURE.

References #

system.email.account_unlock.sent_message

#

Description

Send self-service account unlock email.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.email.bounce.removal

#

Description

Attempted removal of one or more emails from bounce list. Identify email addresses which were submitted to Okta for removal from the email bounce list. This event does not guarantee that an email was removed from the bounce list, it only indicates that Okta contacted the email provider to attempt to remove if from the bounce list. The debugData object contains a reference to the email provider contacted by Okta which maintains the bounce list. The target object contains a list of email addresses which were submitted. A single target contains a maximum of 50 email addresses. Multiple events may be fired in response to a removal request.

References #

system.email.challenge_factor_redeemed

#

Description

User completed an email factor challenge. This can be used to identify when a credential sent in an email to a user has been redeemed (the link was clicked or the code was entered). When fired, this event contains information about the result. Success if successful or error reasons should be present for failure cases (e.g. incorrect code, timeout, expired, etc.). The event also contains a debugData with the action (the link was clicked or the code was entered).

Example System Log Event #

{
  "published": 1785244702483,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000089",
  "actor": {
    "id": "00u00000000000000297",
    "type": "User",
    "alternateId": "user65@dw-harness.example",
    "displayName": "DW Harness 102",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Windows 11",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "events": null,
  "target": [
    {
      "id": "00u00000000000000297",
      "type": "User",
      "alternateId": "user65@dw-harness.example",
      "displayName": "DW Harness 102",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.email.challenge_factor_redeemed",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000049",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "sameBrowser": "true",
      "behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "origin": "https://app.example.com",
      "requestUri": "/idp/idx/introspect",
      "url": "/idp/idx/introspect?",
      "flowContinuation": "new tab",
      "authnRequestId": "00000000000000000000000000000050",
      "requestId": "00000000000000000000000000000049",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000028",
      "action": "link clicked",
      "risk": "{level=LOW}",
      "threatSuspected": "false",
      "verification": "link clicked"
    }
  },
  "displayMessage": "Credential in email has been redeemed",
  "gatewayContext": null,
  "legacyEventType": "system.email.challenge_factor_redeemed",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "LOW"
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "NEGATIVE"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "NEGATIVE"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "NEGATIVE"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "NEGATIVE"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "NEGATIVE"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "NEGATIVE"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000298",
    "externalSessionId": "idx00000000000000298"
  }
}

References #

system.email.delivery

#

Description

An email's delivery status was updated. Used to notify admins of a bounced or dropped email. For certain bounce events, the context information may be lost by the email provider(s) due to email server communication delays. Such delayed bounce events will not appear in syslog. As of the 2022.08.0 release, this is also used to identify other email events e.g. delivered, deferred. See the event debugData for help identifying a remediation, such as updating an incorrect email address.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "SystemPrincipal",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000077",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Email delivery",
  "eventType": "system.email.delivery",
  "outcome": {
    "result": "DEFERRED",
    "reason": "deferred"
  },
  "published": "2026-07-02T18:36:06.442Z",
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "appContextName": "None",
      "emailProvider": "sendgrid",
      "category": "email.welcome",
      "userId": "",
      "emailRequestId": "00000000000000000000000000000004"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "JOB",
    "id": "00000000000000000000",
    "detail": {}
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": []
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "email",
      "alternateId": null,
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

system.email.mfa_enroll_notification.sent_message

#

Description

MFA enrollment notification email sent. Used to notify admins MFA enrollment notification email has been sent.

Example System Log Event #

{
  "published": 1781380212664,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000090",
  "actor": {
    "id": "00u00000000000000299",
    "type": "User",
    "alternateId": "user66@dw-harness.example",
    "displayName": "DW Harness 103",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "app.example.com.mobile/9.63.0 OktaDeviceSDK/0.0.1 macOS/26.3.2 Apple/Mac17,9 00000000-0000-0000-0000-000000000091",
      "os": "Mac OS X",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.31",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000299",
      "type": "User",
      "alternateId": "user66@dw-harness.example",
      "displayName": "DW Harness 103",
      "detailEntry": {
        "realmId": "guo00000000000000044"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.31",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.email.mfa_enroll_notification.sent_message",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000051",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000051",
      "requestUri": "/idp/authenticators",
      "url": "/idp/authenticators?"
    }
  },
  "displayMessage": "Send Example App 61 MFA enrollment notification email",
  "gatewayContext": null,
  "legacyEventType": "core.user.email.message_sent.mfa_enroll_notification",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000300",
    "externalSessionId": "trs00000000000000300"
  }
}

References #

system.email.mfa_reset_notification.sent_message

#

Description

MFA reset notification email sent. Used to notify admins MFA reset notification email has been sent.

Example System Log Event #

{
  "published": 1780408053181,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000092",
  "actor": {
    "id": "00u00000000000000164",
    "type": "User",
    "alternateId": "user03@dw-harness.example",
    "displayName": "DW Harness 04",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.5",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00u00000000000000301",
      "type": "User",
      "alternateId": "user67@dw-harness.example",
      "displayName": "DW Harness 104",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.5",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.email.mfa_reset_notification.sent_message",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000052",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000052",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000029",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000000000002",
      "url": "00000000000000000000000000000000000000000000000000000000000000000000000000000002?"
    }
  },
  "displayMessage": "Send Example App 61 MFA reset notification email",
  "gatewayContext": null,
  "legacyEventType": "core.user.email.message_sent.mfa_reset_notification",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000302",
    "externalSessionId": "10200000000000000302"
  }
}

References #

system.email.new_device_notification.sent_message

#

Description

New device signin notification email sent.

Example System Log Event #

{
  "published": 1780189574865,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000093",
  "actor": {
    "id": "00u00000000000000303",
    "type": "User",
    "alternateId": "user68@dw-harness.example",
    "displayName": "DW Harness 105",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
      "os": "Mac OS X",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.35",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "events": null,
  "target": [
    {
      "id": "00u00000000000000303",
      "type": "User",
      "alternateId": "user68@dw-harness.example",
      "displayName": "DW Harness 105",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.35",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.email.new_device_notification.sent_message",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000053",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000054",
      "deviceFingerprint": "00000000000000000000000000000055",
      "behaviors": "{New Geo-Location=UNKNOWN, New Device=UNKNOWN, New ASN=UNKNOWN, New IP=UNKNOWN, New State=UNKNOWN, New Country=UNKNOWN, Velocity=UNKNOWN, New City=UNKNOWN}",
      "requestId": "00000000000000000000000000000053",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000030",
      "risk": "{reasons=Anomalous Location, Anomalous Device, level=HIGH}",
      "requestUri": "/idp/idx/challenge/answer",
      "threatSuspected": "false",
      "url": "/idp/idx/challenge/answer?"
    }
  },
  "displayMessage": "Send Example App 61 new device notification email",
  "gatewayContext": null,
  "legacyEventType": "core.user.email.message_sent.new_device_notification",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "HIGH",
      "reasons": [
        "Anomalous Location",
        "Anomalous Device"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "UNKNOWN"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "UNKNOWN"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "UNKNOWN"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "UNKNOWN"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "UNKNOWN"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "UNKNOWN"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "UNKNOWN"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "UNKNOWN"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000304",
    "externalSessionId": "idx00000000000000304"
  }
}

References #

system.email.password_reset.sent_message

#

Description

Send self-service password reset email.

Example System Log Event #

{
  "published": 1785244692098,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000094",
  "actor": {
    "id": "spr00000000000000171",
    "type": "SystemPrincipal",
    "alternateId": "user41@dw-harness.example",
    "displayName": "Okta System",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
      "os": "Windows 11",
      "browser": "CHROME"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.4",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": {
    "id": null,
    "name": null,
    "os_platform": null,
    "os_version": null,
    "managed": null,
    "registered": null,
    "device_integrator": {
      "DEVICE_IDP": {}
    },
    "disk_encryption_type": null,
    "screen_lock_type": null,
    "jailbreak": null,
    "secure_hardware_present": null
  },
  "events": null,
  "target": [
    {
      "id": "00u00000000000000297",
      "type": "User",
      "alternateId": "user65@dw-harness.example",
      "displayName": "DW Harness 102",
      "detailEntry": {
        "emailAddress": "user65@dw-harness.example",
        "realmId": "guo00000000000000044"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.4",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.email.password_reset.sent_message",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000056",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000050",
      "deviceFingerprint": "00000000000000000000000000000057",
      "behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "requestId": "00000000000000000000000000000056",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000028",
      "origin": "https://app.example.com",
      "risk": "{level=LOW}",
      "requestUri": "/idp/idx/challenge",
      "threatSuspected": "false",
      "url": "/idp/idx/challenge?"
    }
  },
  "displayMessage": "Send self-service password reset email",
  "gatewayContext": null,
  "legacyEventType": "core.user.email.message_sent.self_service.password_reset",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "LOW"
    },
    "userBehaviors": [
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000052",
        "result": "NEGATIVE"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000053",
        "result": "NEGATIVE"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000054",
        "result": "NEGATIVE"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000055",
        "result": "NEGATIVE"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000056",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000057",
        "result": "NEGATIVE"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000058",
        "result": "NEGATIVE"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000059",
        "result": "NEGATIVE"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "idx00000000000000298",
    "externalSessionId": "idx00000000000000298"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.email.send_factor_verify_message

#

Description

An email was sent to a user for verification. Used to notify admins that an email was sent to a user for verification. When fired, this event contains information about the token lifetime in the debugData.

References #

system.email.template.create

#

Description

This event is fired when a custom email template is created. Developers and Org Admins can use this to identify when a default email template has been overridden with a new template. The event details can be used to identify the template type and template engine. Usually this event will precede "system.email.template.update" or "system.email.template.delete" events.

References #

system.email.template.delete

#

Description

This event is fired when a custom email template is deleted. Developers and Org Admins can use this to identify when a custom email template has been deleted to fall back to default template. The event details can be used to identify the template type and template engine. Usually this event will follow "system.email.template.create" or "system.email.template.update" events.

References #

system.email.template.settings_changed

#

Description

This event is fired when the settings for an email template is changed. Developers and Org Admins can use this to identify when an email template setting has been changed. When fired, this event contains information about the email template and settings that were changed.

References #

system.email.template.update

#

Description

This event is fired when a custom email template has been updated. Developers and Org Admins can use this to identify when a custom email template has been updated. The event details can be used to identify the template type and template engine. Usually this event will follow "system.email.template.create" and precede "system.email.template.delete" events.

References #

system.email_domain.create

#

Description

Email domain is created. Admin has initiated email domain setup by inputting their domain details for DNS verification. When fired, the event contains information about the domain name, display name, user name, brand id and validation status.

References #

system.email_domain.delete

#

Description

Email domain is deleted. Can be used to identify when an admin has deleted their email domain. When fired, the event contains information about the email domain that was deleted.

References #

system.email_domain.update

#

Description

Email domain is updated. Admin has updated the email domain. When fired, the event contains information about the email domain that was updated.

References #

system.email_domain.verify

#

Description

Verify email domain. Identifies whether an admin has succeeded or failed to verify the email domain. When fired, the event contains information about the email domain that is being verified.

References #

system.feature.disable

#

Description

Fired when self service features are requested to be disabled by admins. Use to determine who enabled the features and any limitations the features have. When fired, this event contains information about the requested features, their names and lifecycle state, the admin who made the change, and any possible limitations associated with the features. Related events include 'system.feature.enable'.

References #

system.feature.ea_auto_enroll

#

Description

Fired when an org has subscribed to or unsubscribed from EA Feature Auto Enroll. This can be used to understand the status of EA Feature Auto Enroll subscription and identify who has made changes to the subscription. When fired, this event contains information about the status of EA Feature Auto enroll subscription, as well as the admin who made any subscription changes.

References #

system.feature.enable

#

Description

Fired when self service features are requested to be enabled by admins. Use to determine who enabled the features and any limitations the features have. When fired, this event contains information about the requested features, their names and lifecycle state, the admin who made the change, and any possible limitations associated with the features. Related events include 'system.feature.disable'.

References #

system.hook.key.created

#

Description

Create a new hook key. This event can be used to identify when an admin created a new hook key. When triggered, this events contains information about the created hook key.

References #

system.hook.key.deleted

#

Description

Delete a hook key. This event can be used to identify when an admin deleted a hook key. When triggered, this events contains information about the deleted hook key.

References #

system.hook.key.updated

#

Description

Update a hook key. This event can be used to identify when an admin updated a hook key. When triggered, this events contains information about the updated hook key.

References #

system.identity_sources.bulk_delete

#

Description

Upload bulk delete data. Loads bulk data into an Identity Source Session for deactivation in Okta for an identity source. This event can be used to track the deactivations of user profiles in Okta from the custom identity source.

References #

system.identity_sources.bulk_group_delete

#

Description

Upload bulk groups delete data. Loads bulk groups data into an Identity Source Session for deactivation in Okta for an identity source. This event can be used to track the deactivations of groups profiles in Okta from the custom identity source.

References #

system.identity_sources.bulk_group_membership_delete

#

Description

Upload bulk group membership delete data. Loads bulk group membership data into an Identity Source Session to delete group membership in Okta for an identity source. This event can be used to track the deletion of group membership in Okta from the custom identity source.

References #

system.identity_sources.bulk_group_membership_upsert

#

Description

Upload bulk group membership upsert data. Loads bulk group membership data into an Identity Source Session for adding group membership in Okta for an identity source. This event can be used to track the addition of group membership in Okta from the custom identity source.

References #

system.identity_sources.bulk_group_upsert

#

Description

Upload bulk groups upsert data. Loads bulk groups data into an Identity Source Session for inserting or updating groups profiles in Okta for an identity source. This event can be used to track the insertions and updates of group profiles in Okta from the custom identity source.

References #

system.identity_sources.bulk_upsert

#

Description

Upload bulk upsert data. Loads bulk data into an Identity Source Session for inserting or updating user profiles in Okta for an identity source. This event can be used to track the insertions and updates of Okta user profiles from the custom identity source.

References #

system.identity_sources.group.create

#

Description

Create an identity source group. Creates a new group in Okta from an identity source. This event tracks the creation of a group in Okta sourced from a custom identity source.

References #

system.identity_sources.group.delete

#

Description

Delete an identity source group. Deletes a group in Okta from an identity source. This event tracks the deletion of a group in Okta sourced from a custom identity source.

References #

system.identity_sources.group.update

#

Description

Update an identity source group. Updates a group in Okta from an identity source. This event tracks the update of a group profile in Okta sourced from a custom identity source. Payload must include changeDetails.

References #

system.identity_sources.group.user.assign

#

Description

Assign a user to an identity source group. Assigns a user to an identity source group in Okta. This event tracks the assignment of a user to a group in Okta sourced from a custom identity source.

References #

system.identity_sources.group.user.revoke

#

Description

Revoke a user from an identity source group. Revokes a user from an identity source group in Okta. This event tracks the removal of a user from a group in Okta sourced from a custom identity source.

References #

system.identity_sources.user.create

#

Description

Create an identity source user. Creates a new user in Okta from an identity source. This event tracks the creation of a user in Okta sourced from a custom identity source.

References #

system.identity_sources.user.delete

#

Description

Delete an identity source user. Deletes a user in Okta from an identity source. This event tracks the deletion of a user in Okta sourced from a custom identity source.

References #

system.identity_sources.user.update

#

Description

Update an identity source user. Updates a user in Okta from an identity source. This event tracks the update of a user profile in Okta sourced from a custom identity source. Payload must include changeDetails.

References #

system.idp.key.create

#

Description

Identity provider key credential created. This can be used to audit that a new identity provider key credential has been created. When fired, this event indicates a new X.509 certificate credential is added to the IdP key store.

References #

system.idp.key.delete

#

Description

Identity provider key credential deleted. This can be used to audit that an identity provider key credential has been deleted. When fired, this event indicates a X.509 certificate credential by kid is deleted if it isn't currently being used by an active or inactive IdP.

References #

system.idp.key.update

#

Description

Identity provider key credential updated. This can be used to audit that an identity provider key credential has been updated. When fired, this event indicates a X.509 certificate credential is updated in the IdP key store.

References #

system.idp.lifecycle.activate

#

Description

Identity provider activated. This can be used to audit that an identity provider has been activated. When fired, this event indicates an Identity provider was activated. This event also indicates the type of the identity provider that was activated.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000069",
    "externalSessionId": "trs00000000000000069"
  },
  "displayMessage": "Activate an Identity Provider",
  "eventType": "system.idp.lifecycle.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:24:02.106Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "protocol": "OIDC",
      "requestId": "00000000000000000000000000000077",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/idps/0oa00000000000000067/lifecycle/activate",
      "url": "/api/v1/idps/0oa00000000000000067/lifecycle/activate?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000077",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000089",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000067",
      "type": "IdentityProvider",
      "alternateId": "oidc_idp",
      "displayName": "DW Harness 29",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Panther #

References #

system.idp.lifecycle.create

#

Description

Identity provider created. This can be used to audit that a new identity provider has been created. When fired, this event indicates an Identity provider was successfully created. This event also indicates the type of the identity provider that was created.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000040",
    "externalSessionId": "0000000000000000000000040"
  },
  "displayMessage": "Create an Identity Provider",
  "eventType": "system.idp.lifecycle.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:24:01.398Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "protocol": "OIDC",
      "requestId": "00000000000000000000000000000074",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/idps",
      "url": "/api/v1/idps?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000074",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000086",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000067",
      "type": "IdentityProvider",
      "alternateId": "oidc_idp",
      "displayName": "DW Harness 29",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

Panther #

References #

system.idp.lifecycle.deactivate

#

Description

Identity provider deactivated. This can be used to audit that an identity provider has been deactivated. When fired, this event indicates an Identity provider has been deactivated. This event also indicates the type of the identity provider that was deactivated.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000068",
    "externalSessionId": "trs00000000000000068"
  },
  "displayMessage": "Deactivate an Identity Provider",
  "eventType": "system.idp.lifecycle.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:24:01.800Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "protocol": "OIDC",
      "requestId": "00000000000000000000000000000076",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/idps/0oa00000000000000067/lifecycle/deactivate",
      "url": "/api/v1/idps/0oa00000000000000067/lifecycle/deactivate?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000076",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000088",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000067",
      "type": "IdentityProvider",
      "alternateId": "oidc_idp",
      "displayName": "DW Harness 29",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Panther #

References #

system.idp.lifecycle.delete

#

Description

Identity provider deleted. This can be used to audit that an identity provider has been deleted. When fired, this event indicates an Identity provider was deleted. This event also indicates the type of the identity provider that was deleted.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000070",
    "externalSessionId": "trs00000000000000070"
  },
  "displayMessage": "Delete an Identity Provider",
  "eventType": "system.idp.lifecycle.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-25T23:24:02.758Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "protocol": "OIDC",
      "requestId": "00000000000000000000000000000078",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/idps/0oa00000000000000067",
      "url": "/api/v1/idps/0oa00000000000000067?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000078",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000090",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000067",
      "type": "IdentityProvider",
      "alternateId": "oidc_idp",
      "displayName": "DW Harness 29",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

Panther #

References #

system.idp.lifecycle.read_client_secret

#

Description

Identity provider(s) with a client secret is read. This can be used to audit that identity provider(s) with a client secret has been read. When fired, this event indicates one or more Identity providers with a client secret was read.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000058",
    "externalSessionId": "trs00000000000000058"
  },
  "displayMessage": "Read an Identity Provider",
  "eventType": "system.idp.lifecycle.read_client_secret",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-24T03:47:48.717Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "idpIdsWithSecrets": "[0oa00000000000000057]",
      "protocol": "OIDC",
      "requestId": "00000000000000000000000000000068",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/idps/0oa00000000000000057",
      "url": "/api/v1/idps/0oa00000000000000057?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000068",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000079",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000057",
      "type": "IdentityProvider",
      "alternateId": "oidc_idp",
      "displayName": "DW Harness 21",
      "detailEntry": null
    }
  ]
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

system.idp.lifecycle.update

#

Description

Identity provider updated. This can be used to audit that an identity provider configuration has been updated. When fired, this event indicates an Identity provider configuration was updated. This event also indicates the type of the identity provider that was updated.

Example System Log Event #

{
  "actor": {
    "alternateId": "user03@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 22",
    "id": "000000000000000084",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000085",
    "interface": null,
    "issuer": null,
    "rootSessionId": "0000000000000000000000086"
  },
  "client": {
    "device": "Unknown",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "203.0.113.144",
    "userAgent": {
      "browser": "UNKNOWN",
      "os": "Unknown",
      "rawUserAgent": "pekko-http/1.2.0"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "dtHash": "000000000000000000000000000000000000000000000000000000000000087",
      "protocol": "SAML 2.0",
      "requestId": "000000000000000000000000088",
      "requestUri": "/api/v1/idps/1i600000000000000010",
      "url": "/api/v1/idps/1i600000000000000010?"
    }
  },
  "device": null,
  "displayMessage": "Update an Identity Provider",
  "eventType": "system.idp.lifecycle.update",
  "legacyEventType": null,
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2025-08-19T19: 49: 51.342Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": null,
        "ip": "198.51.100.12",
        "source": null,
        "version": "V4"
      },
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "203.0.113.144",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "INFO",
  "target": [
    {
      "alternateId": "user14@dw-harness.example",
      "changeDetails": {
        "from": {
          "policySubject": {
            "filter": "^$",
            "matchType": "USERNAME",
            "userNameTemplate": {
              "template": "idpuser.email"
            }
          }
        },
        "to": {
          "policySubject": {
            "filter": "^.+@(?i)(?:example\\.com)$",
            "matchType": "USERNAME",
            "userNameTemplate": {
              "template": "idpuser.email"
            }
          }
        }
      },
      "detailEntry": null,
      "displayName": "DW Harness 23",
      "id": "00000000000000000000089",
      "type": "IdentityProvider"
    }
  ],
  "transaction": {
    "detail": {
      "requestApiTokenId": "00000000000000000090",
      "rootApiTokenId": "00000000000000000090"
    },
    "id": "000000000000000000000000088",
    "type": "WEB"
  },
  "uuid": "000000000000000000000000000000000091",
  "version": "0"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

system.import.clear.unconfirmed.users.summary

#

Description

Clear Unconfirmed Imported Users. Can be used for clearing unconfirmed imported users from last import result. Note that a single event is fired for clearing unconfirmed imported users instead of fire delete event on each user.

References #

system.import.complete

#

Description

Import process complete.

Example System Log Event #

{
  "published": 1781014987808,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000095",
  "actor": {
    "id": "00u00000000000000246",
    "type": "User",
    "alternateId": "user56@dw-harness.example",
    "displayName": "DW Harness 79",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij000000000000000305",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 59",
      "totalTime": "0 seconds"
    }
  },
  "displayMessage": "Import process complete",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.complete",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000248",
    "externalSessionId": "trs00000000000000306"
  }
}

References #

system.import.complete_batch

#

Description

Batch import process complete.

Example System Log Event #

{
  "published": 1780928948593,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000096",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.complete_batch",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 59",
      "totalTime": "1 minute and 15 seconds"
    }
  },
  "displayMessage": "Batch import process complete",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.batch.complete",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.custom_object.complete

#

Description

Import of custom objects completed.

Example System Log Event #

{
  "published": 1781014987799,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000097",
  "actor": {
    "id": "00u00000000000000246",
    "type": "User",
    "alternateId": "user56@dw-harness.example",
    "displayName": "DW Harness 79",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.custom_object.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij000000000000000305",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "deletedObjects": "0",
      "addedObjects": "0",
      "appname": "Example App 59",
      "totalObjects": "0",
      "updatedObjects": "0",
      "unchangedObjects": "0"
    }
  },
  "displayMessage": "Import of custom objects completed",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.summary.custom_object",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000248",
    "externalSessionId": "trs00000000000000306"
  }
}

References #

system.import.custom_object.create

#

Description

Create custom object triggered by import process.

References #

system.import.custom_object.delete

#

Description

Delete custom object triggered by import process.

References #

system.import.custom_object.update

#

Description

Update custom object triggered by import process.

References #

system.import.download.complete

#

Description

Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record.

Example System Log Event #

{
  "published": 1780156929845,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000098",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.download.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gij00000000000000310",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "gij00000000000000310",
      "appname": "Example App 84",
      "detailedmessage": "Download object phase completed."
    }
  },
  "displayMessage": "Download object phase completed.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000183",
    "externalSessionId": "trs00000000000000311"
  }
}

References #

system.import.download.start

#

Description

Fired at the start of the download objects phase, when the objects (users, groups, devices) to be imported are being downloaded from the system of record. This can be used to determine when an import has started, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the download objects phase, when the objects (users, groups, devices) to be imported are being downloaded from the system of record.

Example System Log Event #

{
  "published": 1780156929170,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000099",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.download.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gij00000000000000310",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "gij00000000000000310",
      "appname": "Example App 84",
      "detailedmessage": "Download object phase started."
    }
  },
  "displayMessage": "Download object phase started.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000183",
    "externalSessionId": "trs00000000000000311"
  }
}

References #

system.import.entitlement

#

Description

Emitted during the entitlement discovery process to identify entitlement schemas, excluding assignments. Tracks entitlement discovery status. In case of a NullPointerException (NPE), the outcome.result will be 'SKIPPED'. Use this event to track the status of entitlements during discovery.

References #

system.import.entitlement.mismatch

#

Description

Skipping of entitlement during import of an user. This event will be emitted during import whenever a user has some entitlement associated with it that are not present in Okta. This event can be use to track the entitlement of user which were skipped during import.

References #

system.import.group.complete

#

Description

Import of groups completed.

Example System Log Event #

{
  "published": 1781014987802,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000100",
  "actor": {
    "id": "00u00000000000000246",
    "type": "User",
    "alternateId": "user56@dw-harness.example",
    "displayName": "DW Harness 79",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.group.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij000000000000000305",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "deletedObjects": "0",
      "addedObjects": "0",
      "appname": "Example App 59",
      "totalObjects": "0",
      "updatedObjects": "0",
      "unchangedObjects": "0"
    }
  },
  "displayMessage": "Import of groups completed",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.summary.group",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000248",
    "externalSessionId": "trs00000000000000306"
  }
}

References #

system.import.group.create

#

Description

Create group triggered by import process.

References #

system.import.group.delete

#

Description

Remove group triggered by import process.

References #

system.import.group.start

#

Description

Start importing groups from refreshing AppGroups.

Example System Log Event #

{
  "published": 1780156929165,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000102",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.group.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gij00000000000000310",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 84"
    }
  },
  "displayMessage": "Start importing groups from refreshing AppGroups",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.import_groups",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000183",
    "externalSessionId": "trs00000000000000311"
  }
}

References #

system.import.group.update

#

Description

Update group triggered from import process.

References #

system.import.group_membership.complete

#

Description

Import of application group members completed.

Example System Log Event #

{
  "published": 1781014987805,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000101",
  "actor": {
    "id": "00u00000000000000246",
    "type": "User",
    "alternateId": "user56@dw-harness.example",
    "displayName": "DW Harness 79",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.group_membership.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij000000000000000305",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "deletedObjects": "0",
      "addedObjects": "0",
      "appname": "Example App 59",
      "totalObjects": "0",
      "updatedObjects": "0",
      "unchangedObjects": "0"
    }
  },
  "displayMessage": "Import of application group members completed",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.summary.group_membership",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000248",
    "externalSessionId": "trs00000000000000306"
  }
}

References #

system.import.implicit_deletion.complete

#

Description

Fired upon completion of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects.

Example System Log Event #

{
  "published": 1780928918178,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000103",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.implicit_deletion.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "Deletion processing phase completed."
    }
  },
  "displayMessage": "Deletion processing phase completed.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.implicit_deletion.start

#

Description

Fired at the start of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects.

Example System Log Event #

{
  "published": 1780928913927,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000104",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.implicit_deletion.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "Deletion processing phase started."
    }
  },
  "displayMessage": "Deletion processing phase started.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.import_profile

#

Description

Import user profile triggered by import process.

References #

system.import.import_provisioning_info

#

Description

Import provisioning info triggered by import process.

Example System Log Event #

{
  "published": 1781014987343,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000105",
  "actor": {
    "id": "00u00000000000000246",
    "type": "User",
    "alternateId": "user56@dw-harness.example",
    "displayName": "DW Harness 79",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.import_provisioning_info",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij000000000000000305",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "appname": "Example App 59"
    }
  },
  "displayMessage": "Import provisioning info triggered by import process",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.provisioning_data",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000248",
    "externalSessionId": "trs00000000000000306"
  }
}

References #

system.import.membership_processing.complete

#

Description

Fired upon completion of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from.

Example System Log Event #

{
  "published": 1780928918496,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000106",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.membership_processing.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "Membership processing phase completed."
    }
  },
  "displayMessage": "Membership processing phase completed.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.membership_processing.start

#

Description

Fired at the start of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from.

Example System Log Event #

{
  "published": 1780928918182,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000107",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.membership_processing.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "Membership processing phase started."
    }
  },
  "displayMessage": "Membership processing phase started.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.object_creation.complete

#

Description

Fired upon completion of the object creation phase, when the first batch of objects is created/updated. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the object creation phase, when the first batch of objects is created/updated.

Example System Log Event #

{
  "published": 1780928913922,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000108",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.object_creation.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "Object creation phase completed."
    }
  },
  "displayMessage": "Object creation phase completed.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.object_creation.start

#

Description

Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record.

Example System Log Event #

{
  "published": 1780156929847,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000109",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.object_creation.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gij00000000000000310",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "gij00000000000000310",
      "appname": "Example App 84",
      "detailedmessage": "Object creation phase started."
    }
  },
  "displayMessage": "Object creation phase started.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000183",
    "externalSessionId": "trs00000000000000311"
  }
}

References #

system.import.roadblock

#

Description

Import roadblock triggered due to exceeded threshold.

References #

system.import.roadblock.reschedule_and_resume

#

Description

The affected import from AppInstance has been rescheduled. All other imports will resume.

References #

system.import.roadblock.resume

#

Description

The affected import from AppInstance has been canceled. All other imports will resume.

References #

system.import.roadblock.updated

#

Description

Fired when an import roadblock (aka, Import Safeguard) has been updated. This event can be used to identify when an admin updated the Max Import Unassignment roadblock setting, and what the setting was updated to. This event includes details on what the roadblock was updated to and who made the change.

References #

system.import.schedule

#

Description

Import process was scheduled. This event can be used to track when import jobs were triggered, which helps with audit trails. This event may also be useful when troubleshooting a failed import, as it indicates the time at which the process was first triggered and the user or application that invoked the import. Import is a multi-stage process which may import users, groups, and group memberships. Each stage has corresponding events in the system log. For example 'system.import.user.start' indicates beginning of user import process.

Example System Log Event #

{
  "published": 1780928872549,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000110",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.20",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.20",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.schedule",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000058",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000058",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000004",
      "url": "00000000000000000000000000000000000000000000000000004?"
    }
  },
  "displayMessage": "Import process was scheduled.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "10200000000000000308"
  }
}

References #

system.import.session.cancelled

#

Description

Import session for identity source canceled. This event appears when an import session is canceled and not available for further activity. Only sessions that are in CREATED or IN_PROGRESS status can be canceled. Previously uploaded entities are deleted from a canceled identity import session.

References #

system.import.session.created

#

Description

Create new import session for identity source. This event appears when a new import session is created for a given identity source to bulk upload entities. This event includes information on when the session was created.

References #

system.import.session.expired

#

Description

Import session for identity source expired. This event appears when a session in CREATED or IN_PROGRESS status is marked as EXPIRED after 24 hours of inactivity. Expired sessions can no longer be used for import operations.

References #

system.import.session.triggered

#

Description

Triggered import session for identity source. This event appears when import session was triggered. It's used to make changes in Okta to insert, update, or delete the entities that are submitted by the identity source.

References #

system.import.start

#

Description

import started.

Example System Log Event #

{
  "published": 1782502956369,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000111",
  "actor": {
    "id": "00u00000000000000117",
    "type": "User",
    "alternateId": "user29@dw-harness.example",
    "displayName": "DW Harness 44",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "prj00000000000000119",
    "detail": {
      "rootApiTokenId": "00t00000000000000120"
    }
  },
  "debugContext": {
    "debugData": {
      "jobId": "prj00000000000000119",
      "importType": "Incremental",
      "appname": "Example App 59",
      "importLastToken": "2026-06-08T07:27:53.237Z",
      "importTrigger": "Manual action"
    }
  },
  "displayMessage": "import started",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.started",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000121",
    "externalSessionId": "trs00000000000000122"
  }
}

References #

system.import.user.complete

#

Description

Import of user completed.

Example System Log Event #

{
  "published": 1780156929921,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000112",
  "actor": {
    "id": "00u00000000000000179",
    "type": "User",
    "alternateId": "user44@dw-harness.example",
    "displayName": "DW Harness 59",
    "detailEntry": null
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000165",
      "type": "AppInstance",
      "alternateId": "user40@dw-harness.example",
      "displayName": "DW Harness 47",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "gij00000000000000310",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "deletedObjects": "0",
      "addedObjects": "0",
      "appname": "Example App 84",
      "totalObjects": "0",
      "updatedObjects": "0",
      "unchangedObjects": "0"
    }
  },
  "displayMessage": "Import of Example App 61 completed",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.summary.user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000183",
    "externalSessionId": "trs00000000000000311"
  }
}

References #

system.import.user.create

#

Description

Create user triggered by import process.

Example System Log Event #

{
  "published": 1780928898079,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000113",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000312",
      "type": "AppUser",
      "alternateId": "user69@dw-harness.example",
      "displayName": "DW Harness 106",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user.create",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Create Example App 61 triggered by import process",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.details.add_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.user.delete

#

Description

Delete user triggered by import process.

Example System Log Event #

{
  "published": 1780928917042,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000114",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000313",
      "type": "AppUser",
      "alternateId": "user70@dw-harness.example",
      "displayName": "DW Harness 107",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user.delete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Delete Example App 61 triggered by import process",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.details.delete_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.user.match

#

Description

Assign user triggered by import process with callback. This event can be used to alter the matching result for a given imported user. This event is fired when the matching result is altered by the synchronous callback.

References #

system.import.user.start

#

Description

Start importing users triggered import process.

References #

system.import.user.suspend

#

Description

Suspend user triggered by import process.

References #

system.import.user.unsuspend

#

Description

Unsuspend user triggered by import process.

References #

system.import.user.unsuspend_after_confirm

#

system.import.user.update

#

Description

Update user triggered by import process.

Example System Log Event #

{
  "published": 1780928893392,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000118",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0ua00000000000000315",
      "type": "AppUser",
      "alternateId": "user71@dw-harness.example",
      "displayName": "DW Harness 108",
      "detailEntry": null
    },
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {}
  },
  "displayMessage": "Update Example App 61 triggered by import process",
  "gatewayContext": null,
  "legacyEventType": "app.generic.import.details.update_user",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.user.update_user_lifecycle_from_master

#

Description

Update user status triggered by import process.

References #

system.import.user_csv.complete

#

Description

Bulk Import users from CSV is completed. Informs when bulk user import from CSV has been completed. This event is logged when bulk user import from CSV has completed with the outcome as success or failure. When fired, this event also contains debug context about the number of users added/updated/unchanged or with errors.

References #

system.import.user_csv.start

#

Description

Bulk Import of users from CSV is started. Informs when bulk import of users from CSV has been attempted to be uploaded. This event is logged when bulk user import from CSV has started and is a precursor to user.lifecycle.create; user.lifecycle.activate events.

References #

system.import.user_match.confirm

#

Description

Import user matching assignment confirmed. This event can be used to track when the confirmation of user matching assignments was triggered on the Import page, which helps with audit trails. This event may also be useful when troubleshooting incorrect user matches. After users are imported from the app, they're matched and assigned with existing Okta users on the basis of Name, Username, and Email. The assignment confirmation is a manual step, needing admin intervention.

Example System Log Event #

{
  "published": 1782501745846,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000115",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user_match.confirm",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000059",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000059",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000004",
      "url": "00000000000000000000000000000000000000000000000000000000000004?"
    }
  },
  "displayMessage": "Import Example App 61 matching assignment confirmed.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000314",
    "externalSessionId": "10200000000000000314"
  }
}

References #

system.import.user_match.unignore

#

Description

Assignment was unignored. This event indicates that a user match, which was previously marked to be ignored during imports, has been reactivated for consideration. It's important for tracking changes in user matching policies and decisions during the import process. This event can be of critical importance for auditing purposes, especially when investigating why certain user accounts were matched or updated after being ignored in previous imports. It helps maintain the accuracy and integrity of user data by ensuring that valid matches are not permanently overlooked.

References #

system.import.user_match.update

#

Description

Assignment was modified. This event can be used to track when an assignment was modified. This may also be useful when troubleshooting incorrect user assignments. After users are imported from the app, they're matched and assigned with existing Okta users on the basis of Name, Username, and Email. Assignments can be modified by the admin through a manual intervention.

References #

system.import.user_matching.complete

#

Description

Fired upon completion of the user matching phase, when Okta attempts to match imported users to existing Okta users. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the user matching phase, when Okta attempts to match imported users to existing Okta users.

Example System Log Event #

{
  "published": 1780928951337,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000116",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user_matching.complete",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "User matching phase completed."
    }
  },
  "displayMessage": "User matching phase completed.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.import.user_matching.start

#

Description

Fired at the start of the user matching phase, when Okta attempts to match imported users to existing Okta users. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the user matching phase, when Okta attempts to match imported users to existing Okta users.

Example System Log Event #

{
  "published": 1780928918504,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000117",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": null,
    "zone": null,
    "device": null,
    "id": null,
    "ipAddress": null,
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000154",
      "type": "AppInstance",
      "alternateId": "user38@dw-harness.example",
      "displayName": "DW Harness 55",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": []
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.import.user_matching.start",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "JOB",
    "id": "ij100000000000000307",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "jobId": "ij100000000000000307",
      "appname": "Example App 59",
      "detailedmessage": "User matching phase started."
    }
  },
  "displayMessage": "User matching phase started.",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000308",
    "externalSessionId": "trs00000000000000309"
  }
}

References #

system.iwa.create

#

Description

Create IWA agent.

References #

system.iwa.go_offline

#

Description

IWA going offline.

References #

system.iwa.go_online

#

Description

IWA going online.

References #

system.iwa.promote_primary

#

Description

Promote IWA agent to primary.

References #

system.iwa.remove

#

Description

Remove IWA agent.

References #

system.iwa.update

#

Description

Update IWA agent.

References #

system.iwa.use_default

#

Description

No primary IWA app found. Using default login.

References #

system.iwa_agentless.auth

#

Description

Agentless IWA authentication.

References #

system.iwa_agentless.auth_after_redirect

#

Description

Fired after redirection from Agentless DSSO failure. This can be used to track the start of a subsequent authentication request after Agentless DSSO fails. This can also be used for end-to-end tracking of an ADSSO failure to the subsequent authentication it is redirected to by searching for the common stateTokenHash. When fired, this event contains the stateTokenHash which will be common before and after the redirection occurs.

References #

system.iwa_agentless.redirect

#

Description

Fired when an Agentless DSSO authentication request is redirected to an onprem IWA authentication or the default login page. This can be used to identify when an agentless authentication request resulted in a redirect to an onprem IWA or default login page. This can also be used to identify the potential cause of the redirect. When fired, this event identifies the cause of the redirection. When a custom error page is defined, a redirect event is not always generated when a redirection occurs.

References #

system.iwa_agentless.update

#

Description

Update to agentless IWA.

References #

system.iwa_agentless.user.not_found

#

Description

Fired when a user could not be found during Agentless DSSO authentication, resulting in an authentication failure. This can be used to identify when an agentless authentication request resulted in a failure. The failure could be due to the user not being found in Okta, Okta not being able to connect to AD, or the user not being found in AD. This can also be used to identify the potential cause of the failure. When fired, this event contains information about the potential cause of the failure.

References #

system.iwa_agentless_kerberos.update

#

Description

Fires when a Kerberos realm settings is updated by an admin. This event fires when the update is successful or fails. This can be used to audit Kerberos realm setting, and troubleshoot why Kerberos authentication failed. When fired, this event indicates whether Kerberos realm setting update has been successful or failed. This event also indicates the initiator of the event and the current setting for Kerberos Realm. Related events: none, all debugging context is included in this event.

References #

system.ldapi.admin_limit_exceeded

#

Description

This event indicates that an administrative limit was exceeded when processing an LDAP interface operation. It can be used to audit and debug failures caused by exceeding an administrative limit. This event may occur periodically when an LDAP operation results in a large number of corresponding actions in the Okta directory. These errors are often temporary and will subside when Okta has processed the actions. Contact Okta support if you see such errors consistently over the course of a day or more.

References #

system.ldapi.bind

#

Description

Fired when a user performs a BIND to LDAP Interface. Can be used to identify when a user attempted to perform an LDAP authentication for audit or debugging purposes. The firing of this event is subject to LDAPi event filtering rules and is only logged when a failure is returned for the given LDAP operation.

References #

system.ldapi.search

#

Description

Fired when a user performs a SEARCH to LDAP Interface. Can be used to identify when a user attempted to perform a search on LDAP Interface for audit or debugging purposes. The firing of this event is subject to LDAPi event filtering rules and is only logged when a failure is returned for the given LDAP operation.

References #

system.ldapi.unbind

#

Description

Fired when a user performs an UNBIND to LDAP Interface. Can be used to identify when a user attempted to end an LDAP Interface session for audit or debugging purposes. The firing of this event is subject to LDAPi event filtering rules and is only logged when a failure is returned for the given LDAP operation.

References #

system.log_stream.lifecycle.activate

#

Description

Log stream activated. This event can be used to track and audit when a user activates a log stream. When fired, this event indicates that a user activated a log stream configuration.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000092",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Activate a Log Stream",
  "eventType": "system.log_stream.lifecycle.activate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:55:05.656Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/logStreams/0oa00000000000000020/lifecycle/activate",
      "url": "/api/v1/logStreams/0oa00000000000000020/lifecycle/activate?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "LogStream",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

system.log_stream.lifecycle.create

#

Description

Log stream created. This event can be used to track and audit when a user creates a log stream. When fired, this event indicates that a user created a log stream configuration.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000093",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Create a Log Stream",
  "eventType": "system.log_stream.lifecycle.create",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:55:05.398Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/logStreams",
      "url": "/api/v1/logStreams?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "LogStream",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

system.log_stream.lifecycle.deactivate

#

Description

Log stream deactivated. This event can be used to track and audit when a user or Okta deactivates a log stream. When fired, this event indicates that a user or Okta deactivated a log stream configuration.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000094",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Deactivate a Log Stream",
  "eventType": "system.log_stream.lifecycle.deactivate",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:55:05.519Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/logStreams/0oa00000000000000020/lifecycle/deactivate",
      "url": "/api/v1/logStreams/0oa00000000000000020/lifecycle/deactivate?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "LogStream",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

system.log_stream.lifecycle.delete

#

Description

Log stream deleted. This event can be used to track and audit when a user deletes a log stream. When fired, this event indicates that a user deleted a log stream configuration.

Example System Log Event #

{
  "actor": {
    "id": "00000000000000000000",
    "type": "User",
    "alternateId": "user@dw-harness.example",
    "displayName": "DW Harness",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "203.0.113.10",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000095",
    "externalSessionId": "00000000000000000000"
  },
  "displayMessage": "Delete a Log Stream",
  "eventType": "system.log_stream.lifecycle.delete",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-02T18:55:06.335Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
      "requestUri": "/api/v1/logStreams/0oa00000000000000020",
      "url": "/api/v1/logStreams/0oa00000000000000020?"
    }
  },
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000",
    "detail": {
      "rootApiTokenId": "00T00000000000000005",
      "requestApiTokenId": "00T00000000000000005"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000000",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "203.0.113.10",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "00000000000000000000",
      "type": "LogStream",
      "alternateId": "user@dw-harness.example",
      "displayName": "DW Harness",
      "detailEntry": null
    }
  ]
}

References #

system.log_stream.lifecycle.update

#

Description

Log stream updated. This event can be used to track and audit when a user updates a log stream. When fired, this event indicates that a user updated a log stream configuration.

Example System Log Event #

{
  "actor": {
    "id": "00u00000000000000002",
    "type": "User",
    "alternateId": "user02@dw-harness.example",
    "displayName": "DW Harness 02",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "python-requests/2.34.2",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "198.51.100.2",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "0000000000000000000000036",
    "externalSessionId": "0000000000000000000000036"
  },
  "displayMessage": "Update a Log Stream",
  "eventType": "system.log_stream.lifecycle.update",
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "published": "2026-07-24T03:47:51.776Z",
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    }
  },
  "severity": "INFO",
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000075",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "requestUri": "/api/v1/logStreams/0oa00000000000000062",
      "url": "/api/v1/logStreams/0oa00000000000000062?"
    }
  },
  "gatewayContext": null,
  "legacyEventType": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000075",
    "detail": {
      "rootApiTokenId": "00T00000000000000004",
      "requestApiTokenId": "00T00000000000000004"
    }
  },
  "uuid": "00000000-0000-0000-0000-000000000086",
  "version": "0",
  "request": {
    "ipChain": [
      {
        "ip": "198.51.100.2",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "target": [
    {
      "id": "0oa00000000000000062",
      "type": "LogStream",
      "alternateId": "user12@dw-harness.example",
      "displayName": "DW Harness 22",
      "detailEntry": null
    }
  ]
}

References #

system.mfa.factor.activate

#

Description

Activate a new authentication factor. Can be used to identify when an admin has enabled a new factor for authentication. When fired the event will contain details of which factor is enabled.

Example System Log Event #

{
  "published": 1784656596937,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000119",
  "actor": {
    "id": "00u00000000000000026",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000027"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00o00000000000000316",
      "type": "MFA Factor",
      "alternateId": null,
      "displayName": null,
      "detailEntry": {
        "factorType": "FIDO_WEBAUTHN"
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.mfa.factor.activate",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000040",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000040",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
      "origin": "https://app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "00000000000000000000000000000000000000000000000000000000000003",
      "url": "00000000000000000000000000000000000000000000000000000000000003?"
    }
  },
  "displayMessage": "MFA factor enabled",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New Device",
        "id": "bhv00000000000000031",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000032",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New ASN",
        "id": "bhv00000000000000033",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000034",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000035",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000036",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000037",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000038",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000281",
    "externalSessionId": "10200000000000000281"
  }
}

References #

system.mfa.factor.deactivate

#

Description

Deactivate MFA factor. Can be used to identify when an admin has disabled a factor for MFA. When fired the event will contain details of which factor is disabled.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
eventType (panther rule field)inuser.account.reset_password1 rulepanther
eventType (panther rule field)inuser.mfa.factor.update1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • New Device/Location sign-in along with critical operation source medium: This query identifies users seen login from a new geo location/country and a new device, then correlates that sign-in with successful risky operations such as policy changes, MFA changes, API token actions etc. This can be an indication of an attacker gaining access to a user's credentials and then performing critical operations, which typically requires admin privileges. By detecting such patterns, organizations can quickly respond to potential security incidents and mitigate risks associated with unauthorized access and privilege escalation.T1078, T1098, T1556↳ also matches system.api_token.create, system.api_token.revoke

Panther #

References #

system.oauth2.token.request_outside_allowed_range

#

Description

Request with valid bearer tokens made from outside the allowed network zone. Use to detect when a bearer token comes from an IP address that's outside of the specified allowed zone. Fired when a bearer token comes from an IP address that's outside of the specified allowed zone of the client.

References #

system.operation.concurrency_limit.violation

#

Description

Operation concurrency limit violation. This can be used to track if there are too many concurrent operations of the given type. The operation type information is available in debugData. When fired, this event contains information about the operation such as its actor, type, scope and threshold details. OperationRateLimitType in debugData will indicate the category to which the concurrency limit is being applied (e.g. web_request), OperationRateLimitSubtype defines specific subtypes (e.g. ssws_token) and OperationRateLimitScope will indicate the scope of the rate limit (e.g. token).

Example System Log Event #

{
  "published": 1785203175533,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000120",
  "actor": {
    "id": "0oa00000000000000317",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 109",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "unknown",
      "os": "unknown",
      "browser": "unknown"
    },
    "zone": "null",
    "device": "unknown",
    "id": null,
    "ipAddress": "192.0.2.32",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0oa00000000000000317",
      "type": "PublicClientAppEntity",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 109",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.32",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "system.operation.concurrency_limit.violation",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000060",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000019",
      "requestApiTokenId": "0000000000000000000000000000000000000000000019",
      "requestApiTokenClientId": "0oa00000000000000317"
    }
  },
  "debugContext": {
    "debugData": {
      "operationRateLimitSubtype": "oauth_client",
      "operationRateLimitScopeType": "application",
      "requestId": "00000000000000000000000000000060",
      "operationRateLimitThreshold": "37",
      "requestUri": "0000000000000000000000000000000000000000000020",
      "operationRateLimitType": "web_request",
      "url": "0000000000000000000000000000000000000000000020?limit=500"
    }
  },
  "displayMessage": "This application has made too many concurrent requests",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000318",
    "externalSessionId": "trs00000000000000318"
  }
}

References #

system.operation.rate_limit.violation

#

Description

Operation rate limit violation. This can be used to track if an operation is exceeding its rate limit. When fired, this event contains information about the operation such as actor, type, scope and threshold details. OperationRateLimitType in debugData will indicate the category to which the rate limit is being applied (e.g. authenticator_otp_verification), OperationRateLimitSubtype defines specific subtypes (e.g. Email Factor for authenticator_otp_verification) and OperationRateLimitScope will indicate the scope of the rate limit (e.g. user or org level). Formerly, this event was used to indicate blocked SMS/Call transactions, please see system.sms.send*/system.voice.send* for blocked transactions.

Example System Log Event #

{
  "published": 1785225661392,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000121",
  "actor": {
    "id": "00u00000000000000139",
    "type": "User",
    "alternateId": "user33@dw-harness.example",
    "displayName": "DW Harness 51",
    "detailEntry": {
      "realmId": "guo00000000000000044"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Go-http-client/2.0",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "192.0.2.34",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00000000-0000-0000-0000-000000000122",
      "type": "Bucket UUID",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    },
    {
      "id": "00t00000000000000319",
      "type": "Token",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 110",
      "detailEntry": null
    }
  ],
  "outcome": null,
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.34",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "system.operation.rate_limit.violation",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000061",
    "detail": {
      "rootApiTokenId": "00t00000000000000319",
      "requestApiTokenId": "00t00000000000000319"
    }
  },
  "debugContext": {
    "debugData": {
      "operationRateLimitSubtype": "ssws_token",
      "operationRateLimitTimeUnit": "MINUTES",
      "operationRateLimitScopeType": "token",
      "operationRateLimitSecondsToReset": "57",
      "requestId": "00000000000000000000000000000061",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000031",
      "operationRateLimitThreshold": "50",
      "operationRateLimitTimeSpan": "1",
      "requestUri": "fr100000000000000320",
      "operationRateLimitType": "web_request",
      "url": "fr100000000000000320?limit=200"
    }
  },
  "displayMessage": "This API token has made too many requests",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000321",
    "externalSessionId": "trs00000000000000321"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

system.operation.rate_limit.warning

#

Description

Operation rate limit warning. This can be used to track if an operation is approaching its rate limit. When fired, this event contains information about the operation such as actor, type, scope and threshold details. OperationRateLimitType in debugData will indicate the category to which the rate limit is being applied (e.g. authenticator_otp_verification), OperationRateLimitSubtype defines specific subtypes (e.g. Email, SMS or Voice call for authenticator_otp_verification type) and OperationRateLimitScope will indicate the scope of the rate limit (e.g. user or org level).

References #

system.org.captcha.activate

#

Description

Enable org-wide captcha support. Indicates when org-wide captcha support is enabled, for which pages and using which captcha instance. This event is fired when org admin enables org-wide captcha for any supported pages.

References #

system.org.captcha.deactivate

#

Description

Disable org-wide captcha support. Indicates when org-wide captcha support is disabled. This event is fired when org admin disables org-wide captcha support for all pages.

References #

system.org.lifecycle.create

#

system.org.rate_limit.burst

#

Description

Fired when burst rate limit capacity is activated. This can be used to identify when an API in the Org exceeds standard rate limits and the frequency with which the activities occur. This event is fired after a corresponding warning event. If usage continues on this API the risk is hitting a rate limit violation which will fire a corresponding violation event. The event contains a burst rate limit threshold which informs how much capacity is remaining before a violation occurs.

Example System Log Event #

{
  "published": 1783545338762,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000123",
  "actor": {
    "id": "0oa00000000000000123",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 46",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "local-v2-sdk/0.0.0 golang/go1.26.2 linux/arm64 okta-terraform/6.12.0",
      "os": "Linux",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.25",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0000000000000000002",
      "type": "URL Pattern",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    },
    {
      "id": "00000000-0000-0000-0000-000000000124",
      "type": "Bucket Uuid",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.25",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.org.rate_limit.burst",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000062",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000021",
      "requestApiTokenId": "0000000000000000000000000000000000000000000021",
      "requestApiTokenClientId": "0oa00000000000000123"
    }
  },
  "debugContext": {
    "debugData": {
      "burstRateLimitUrlPattern": "/api/v1/groups/{id}",
      "requestId": "00000000000000000000000000000062",
      "burstRateLimitBucketUuid": "00000000-0000-0000-0000-000000000124",
      "burstRateLimitExpirationDate": "",
      "burstThreshold": "5000",
      "baseThreshold": "1000",
      "timeSpan": "1",
      "requestUri": "je900000000000000322",
      "userId": "",
      "url": "je900000000000000322?",
      "timeUnit": "MINUTES"
    }
  },
  "displayMessage": "Burst rate limit activated",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000323",
    "externalSessionId": "trs00000000000000323"
  }
}

References #

system.org.rate_limit.expiration.warning

#

Description

Rate limit approaching expiration date.

References #

system.org.rate_limit.violation

#

Description

Rate limit violation.

Example System Log Event #

{
  "published": 1781435035381,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000125",
  "actor": {
    "id": "0oa00000000000000112",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 42",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "okta-sdk-python/2.9.13 python/3.12.13 Linux/5.10.253-286.1015.amzn2.x86_64",
      "os": "Linux",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.16",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "0000000000004",
      "type": "URL Pattern",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    },
    {
      "id": "00000000-0000-0000-0000-000000000126",
      "type": "Bucket Uuid",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.16",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "system.org.rate_limit.violation",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000063",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000022",
      "requestApiTokenId": "0000000000000000000000000000000000000000000022",
      "requestApiTokenClientId": "0oa00000000000000112"
    }
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000063",
      "rateLimitBucketUuid": "00000000-0000-0000-0000-000000000126",
      "rateLimitSecondsToReset": "17",
      "threshold": "600",
      "timeSpan": "1",
      "rateLimitScopeType": "ORG",
      "requestUri": "00000000000000000000000000000000000000012",
      "url": "00000000000000000000000000000000000000012?",
      "timeUnit": "MINUTES"
    }
  },
  "displayMessage": "Rate limit violation",
  "gatewayContext": null,
  "legacyEventType": "core.framework.ratelimit.exceeded",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000324",
    "externalSessionId": "trs00000000000000324"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

system.org.rate_limit.warning

#

Description

Rate limit warning.

Example System Log Event #

{
  "published": 1780264594853,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000127",
  "actor": {
    "id": "0oa00000000000000325",
    "type": "PublicClientAppEntity",
    "alternateId": "user06@dw-harness.example",
    "displayName": "DW Harness 111",
    "detailEntry": null
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "graphrest-python",
      "os": "Unknown",
      "browser": "UNKNOWN"
    },
    "zone": "null",
    "device": "Unknown",
    "id": null,
    "ipAddress": "192.0.2.33",
    "geographicalContext": null
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "000000000002",
      "type": "URL Pattern",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    },
    {
      "id": "00000000-0000-0000-0000-000000000122",
      "type": "Bucket Uuid",
      "alternateId": null,
      "displayName": null,
      "detailEntry": null
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.33",
        "geographicalContext": null,
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "WARN",
  "eventType": "system.org.rate_limit.warning",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000064",
    "detail": {
      "rootApiTokenId": "0000000000000000000000000000000000000000000023",
      "requestApiTokenId": "0000000000000000000000000000000000000000000023",
      "requestApiTokenClientId": "0oa00000000000000325"
    }
  },
  "debugContext": {
    "debugData": {
      "requestId": "00000000000000000000000000000064",
      "warningPercent": "90",
      "rateLimitBucketUuid": "00000000-0000-0000-0000-000000000122",
      "rateLimitSecondsToReset": "33",
      "threshold": "100",
      "timeSpan": "1",
      "rateLimitScopeType": "ORG",
      "requestUri": "iq300000000000000326",
      "url": "iq300000000000000326?limit=500",
      "timeUnit": "MINUTES"
    }
  },
  "displayMessage": "Rate limit warning",
  "gatewayContext": null,
  "legacyEventType": "core.framework.ratelimit.warning",
  "resourceDetails": null,
  "securityContext": {
    "asNumber": null,
    "asOrg": null,
    "isp": null,
    "domain": null,
    "isProxy": null
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "trs00000000000000327",
    "externalSessionId": "trs00000000000000327"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.org.task.remove

#

Description

Tasks removed.

References #

system.push.send_factor_verify_push

#

Description

Fired when a Push notification is sent to a device. Used to notify admins when a push was sent to a user for verification. Note that this event is fired whenever a Push is sent.

Example System Log Event #

{
  "actor": {
    "alternateId": "user15@dw-harness.example",
    "detailEntry": null,
    "displayName": "DW Harness 24",
    "id": "0000000000000000096",
    "type": "User"
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "authenticationStep": 0,
    "credentialProvider": null,
    "credentialType": null,
    "externalSessionId": "0000000000000000000000097",
    "interface": null,
    "issuer": null,
    "rootSessionId": "0000000000000000000000097"
  },
  "client": {
    "device": "Computer",
    "geographicalContext": {
      "city": "Anytown",
      "country": "Placeholderland",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      },
      "postalCode": "00000",
      "state": "Anystate"
    },
    "id": null,
    "ipAddress": "198.51.100.13",
    "userAgent": {
      "browser": "CHROME",
      "os": "Windows 10",
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
    },
    "zone": "null"
  },
  "debugContext": {
    "debugData": {
      "authnRequestId": "00000000000000000000000000000005",
      "behaviors": "{New Geo-Location=POSITIVE, New Device=POSITIVE, New IP=POSITIVE, New State=POSITIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
      "deviceCategory": "SmartPhone_IPhone",
      "devicePlatform": "IOS",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000098",
      "requestId": "00000000000000000000000000000099",
      "requestUri": "/idp/idx/challenge",
      "risk": "{reasons=Anomalous Device, level=MEDIUM}",
      "threatSuspected": "false",
      "url": "/idp/idx/challenge?"
    }
  },
  "device": null,
  "displayMessage": "A push was sent to a user for verification",
  "eventType": "system.push.send_factor_verify_push",
  "legacyEventType": null,
  "outcome": {
    "reason": null,
    "result": "SUCCESS"
  },
  "published": "2024-11-18T22:34:55.603Z",
  "request": {
    "ipChain": [
      {
        "geographicalContext": {
          "city": "Anytown",
          "country": "Placeholderland",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          },
          "postalCode": "00000",
          "state": "Anystate"
        },
        "ip": "198.51.100.13",
        "source": null,
        "version": "V4"
      }
    ]
  },
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "domain": "example.com",
    "isProxy": false,
    "isp": "example-isp"
  },
  "severity": "INFO",
  "target": [
    {
      "alternateId": "user15@dw-harness.example",
      "detailEntry": null,
      "displayName": "DW Harness 24",
      "id": "0000000000000000096",
      "type": "User"
    }
  ],
  "transaction": {
    "detail": {},
    "id": "00000000000000000000000000000099",
    "type": "WEB"
  },
  "uuid": "00000000-0000-0000-0000-000000000015",
  "version": "0"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
debugContext.debugData.factor (splunk rule field)eqokta_verify_push2 rulessplunk
eventType (splunk rule field)eqsystem.push.send_factor_verify_push2 rulessplunk
eventType (splunk rule field)equser.authentication.auth_via_mfa1 rulesplunk
okta::eventType (kusto rule field)equser.authentication.auth_via_mfa1 rulekusto
okta::eventType (kusto rule field)equser.mfa.okta_verify.deny_push1 rulekusto
ratio (splunk rule field)lt0.51 rulesplunk
security_result.detection_fields["factor"] (Chronicle)eqOKTA_VERIFY_PUSH1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

  • Okta MFA Exhaustion Hunt source: The following analytic detects patterns of successful and failed Okta MFA push attempts to identify potential MFA exhaustion attacks. It leverages Okta event logs, specifically focusing on push verification events, and uses statistical…T1110
  • Okta Mismatch Between Source and Response for Verify Push Request source: The following analytic identifies discrepancies between the source and response events for Okta Verify Push requests, indicating potential suspicious behavior. It leverages Okta System Log events, specifically…T1621

Kusto #

YARA-L #

References #

system.rate_limit.configuration.update

#

Description

Rate limit configuration update. This can be used to trace the change that an org admin updates rate limit configuration. This event is triggered when an admin updates rate limit related settings in the admin portal, including but not limited to:1. update client rate limit enforcement mode2. enable or disable rate limit notification3. update the warning threshold of rate limit notification4. update rate limit percentage of API token.

References #

system.self_service.configuration.update

#

Description

Self-service for apps configuration updated. Identify changes to self-service application request settings which may allow a user to request to add an application to their end user dashboard. Self-service application requests are different than Okta Identity Governance (OIG) Access requests. See events beginning with access.request for events relevant to OIG Access requests.

Example System Log Event #

{
  "published": 1782836082885,
  "id": null,
  "etag": null,
  "kind": null,
  "uuid": "00000000-0000-0000-0000-000000000128",
  "actor": {
    "id": "00u00000000000000153",
    "type": "User",
    "alternateId": "user08@dw-harness.example",
    "displayName": "DW Harness 10",
    "detailEntry": {
      "realmId": "guo00000000000000062"
    }
  },
  "client": {
    "userAgent": {
      "rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
      "os": "Windows 10",
      "browser": "FIREFOX"
    },
    "zone": "null",
    "device": "Computer",
    "id": null,
    "ipAddress": "192.0.2.22",
    "geographicalContext": {
      "city": "Anytown",
      "state": "Anystate",
      "country": "Placeholderland",
      "postalCode": "00000",
      "geolocation": {
        "lat": 0.0,
        "lon": 0.0
      }
    }
  },
  "device": null,
  "events": null,
  "target": [
    {
      "id": "00o00000000000000328",
      "type": "Org",
      "alternateId": "user06@dw-harness.example",
      "displayName": "DW Harness 112",
      "detailEntry": null,
      "changeDetails": {
        "from": {
          "selfServiceForPersonalApps": true
        },
        "to": {
          "selfServiceForPersonalApps": false
        }
      }
    }
  ],
  "outcome": {
    "result": "SUCCESS",
    "reason": null
  },
  "request": {
    "ipChain": [
      {
        "ip": "192.0.2.22",
        "geographicalContext": {
          "city": "Anytown",
          "state": "Anystate",
          "country": "Placeholderland",
          "postalCode": "00000",
          "geolocation": {
            "lat": 0.0,
            "lon": 0.0
          }
        },
        "version": "V4",
        "source": null,
        "ipDetails": {
          "asNumber": 0,
          "asOrg": "example-as-org",
          "isp": "example-isp",
          "domain": "example.com"
        }
      }
    ]
  },
  "version": "0",
  "severity": "INFO",
  "eventType": "system.self_service.configuration.update",
  "ipAddress": null,
  "networkInfo": null,
  "transaction": {
    "type": "WEB",
    "id": "00000000000000000000000000000065",
    "detail": {}
  },
  "debugContext": {
    "debugData": {
      "behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
      "requestId": "00000000000000000000000000000065",
      "dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
      "origin": "https://app.example.com App app.example.com",
      "risk": "{reasons=Anomalous Location, level=MEDIUM}",
      "requestUri": "000000000000000000000000000000000000000000003",
      "url": "000000000000000000000000000000000000000000003?"
    }
  },
  "displayMessage": "Self Service configuration updated",
  "gatewayContext": null,
  "legacyEventType": null,
  "resourceDetails": null,
  "securityContext": {
    "asNumber": 0,
    "asOrg": "example-as-org",
    "isp": "example-isp",
    "domain": "example.com",
    "isProxy": false,
    "ipDetails": {
      "asNumber": 0,
      "asOrg": "example-as-org",
      "isp": "example-isp",
      "domain": "example.com"
    },
    "risk": {
      "level": "MEDIUM",
      "reasons": [
        "Anomalous Location"
      ]
    },
    "userBehaviors": [
      {
        "name": "New ASN",
        "id": "bhv00000000000000155",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New IP",
        "id": "bhv00000000000000156",
        "result": "NEGATIVE"
      },
      {
        "name": "New State",
        "id": "bhv00000000000000157",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Country",
        "id": "bhv00000000000000158",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Geo-Location",
        "id": "bhv00000000000000159",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New Device",
        "id": "bhv00000000000000160",
        "result": "BAD_REQUEST"
      },
      {
        "name": "Velocity",
        "id": "bhv00000000000000161",
        "result": "BAD_REQUEST"
      },
      {
        "name": "New City",
        "id": "bhv00000000000000162",
        "result": "BAD_REQUEST"
      }
    ]
  },
  "authenticationContext": {
    "authenticationProvider": null,
    "credentialProvider": null,
    "credentialType": null,
    "issuer": null,
    "interface": null,
    "authenticationStep": 0,
    "rootSessionId": "10200000000000000329",
    "externalSessionId": "10200000000000000329"
  }
}

References #

system.sms.receive_status

#

Description

Fired when receiving a status update on SMS message from provider. This event can be used by Org Admins to identify users that are/aren't getting one-time passcodes delivered successfully via SMS, provider status can be obtained from status field in debug data. For any system.sms.send_* event, there should be exactly one of this event.

References #

system.sms.send_account_unlock_message

#

Description

Send self-service account unlock SMS message. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.sms.send_factor_verify_message

#

Description

Send second factor auth SMS. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

References #

system.sms.send_okta_push_verify_message

#

Description

Send activate Okta Verify Push for mobile SMS. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

References #

system.sms.send_password_reset_message

#

Description

Send self-service password reset SMS message. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.sms.send_phone_verification_message

#

Description

Send phone verification SMS message. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

References #

system.theme.update

#

Description

This event is fired when the theme resource is updated. Developer and org admins can use this event to identify when and how the theme resource was updated. Event details can be used to identify changes made to theme assets including updates to theme hex codes, logo, background image, and favicon. This event also tracks which combination of theme assets was applied to end users pages such as the sign-in page, error pages, and email templates.

References #

system.voice.receive_status

#

Description

Fired when receiving a status update on voice call from provider. This event can be used by Org Admins to identify users that are/aren't getting one-time passcodes delivered successfully via voice call, provider status can be obtained from status field in debug data. For any system.voice.send_* event, there should be exactly one of this event.

References #

system.voice.send_account_unlock_call

#

Description

Send self-service account unlock call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.voice.send_call

#

Description

Send phone call.

References #

system.voice.send_mfa_challenge_call

#

Description

Send second factor auth call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

References #

system.voice.send_password_reset_call

#

Description

Send self-service password reset call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

system.voice.send_phone_verification_call

#

Description

Send phone verification call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.

References #

system.well_known_uri.update

#

Description

The well-known URI was updated. Identify the previous and current versions of a well-known URI for a custom brand, such as a assetlinks.json. The brand id and specific well-known URI are available in the target resource.

References #

system.identity_sources.bulk_device_delete

#

Description

Upload bulk devices delete data. Loads bulk device data into an Identity Source Session for deletion in Okta for an identity source. This event can be used to track the deletion of device profiles in Okta from the custom identity source.

References #

system.identity_sources.bulk_device_upsert

#

Description

Upload bulk devices upsert data. Loads bulk device data into an Identity Source Session for inserting or updating device profiles in Okta for an identity source. This event can be used to track the insertions and updates of device profiles in Okta from the custom identity source.

References #