Okta System
| eventType | Description | Sample | Rule |
|---|---|---|---|
| system. | A monitored variable in an AD agent configuration file has changed. | N | Y |
| system. | Connect AD agent to Okta. | N | N |
| system. | Create AD agent. | N | N |
| system. | Deactivate AD agent. | N | N |
| system. | Delete AD agent. | N | N |
| system. | Verify AD agent compatibility for DirSync-based imports. | N | N |
| system. | Perform import OU by AD agent. | N | N |
| system. | Perform import user by AD agent. | N | N |
| system. | Perform directory invoke command by AD agent. | N | N |
| system. | Reactivate AD agent. | N | N |
| system. | Perform config read by AD agent. | N | N |
| system. | Perform dirsync read by AD agent. | N | N |
| system. | Perform LDAP read by AD agent. | N | N |
| system. | Perform schema read by AD agent. | N | N |
| system. | Directory agent performed topology import operation. | N | N |
| system. | Perform RealTimeSync by AD agent. | N | N |
| system. | Perform user password reset by AD agent. | N | N |
| system. | Start AD agent. | N | N |
| system. | Perform unlock user account by AD agent. | N | N |
| system. | Update AD agent configuration. | N | N |
| system. | User Auth and Update. | N | N |
| system. | Upgrade AD agent. | N | N |
| system. | Fired when an AD agent has fetched and uploaded IWA agent log file. | N | N |
| system. | Upload AD agent log. | N | N |
| system. | Perform LDAP write by AD agent. | N | N |
| system. | Fired when an individual agent auto-update succeeds or fails. | N | N |
| system. | Connect connector agent to Okta. | N | N |
| system. | Deactivate connector agent. | N | N |
| system. | Delete connector agent. | N | N |
| system. | Reactivate connector agent. | N | N |
| system. | Perform change user password by LDAP agent. | N | N |
| system. | A monitored variable in an LDAP agent configuration file has changed. | N | N |
| system. | Perform create user JIT by LDAP agent. | N | N |
| system. | Disconnect LDAP agent from Okta. | N | N |
| system. | Fired when LDAP Delegated Authentication is used to sign in and a user profile is updated using RealTimeSync action. | N | N |
| system. | Reconnect LDAP agent to Okta. | N | N |
| system. | LDAP agent performed a password reset. | N | N |
| system. | LDAP agent performed account unlock for User. | N | N |
| system. | Fired when LDAP Delegated Authentication is used to sign in and a user profile is updated. | N | N |
| system. | Perform update user password by LDAP agent. | N | N |
| system. | Agent was registered. | N | N |
| system. | Fired when the status of an agent pool auto-update is changed. | N | N |
| system. | Create API token. | Y | Y |
| system. | Enable API token. | N | N |
| system. | Request with API tokens made from outside the allowed network zone. | N | N |
| system. | Revoke API token. | Y | Y |
| system. | An API token has been updated. | Y | N |
| system. | Fired when an admin has enabled a BETA feature. | N | N |
| system. | This event is fired when the brand resource is created. | N | N |
| system. | This event is fired when a brand resource is deleted. | N | N |
| system. | This event is fired when the brand resource is updated. | N | N |
| system. | A captcha instance is created for Sign-in Widget. | N | N |
| system. | A captcha instance is deleted. | N | N |
| system. | A captcha instance is updated. | N | N |
| system. | Notify when too many requests in flight for client. | N | N |
| system. | Too many requests in flight for client. | Y | Y |
| system. | Notify when client rate limits are exceeded. | N | N |
| system. | Client rate limit violation. | Y | Y |
| system. | Import of user from CSV is skipped. | N | N |
| system. | Enable a custom email server. | N | N |
| system. | Create a custom email server. | N | N |
| system. | Disable a custom email server. | N | N |
| system. | Delete a custom email server. | N | N |
| system. | Update a custom email server. | N | N |
| system. | Custom error page is deleted. | N | N |
| system. | Custom error page is updated. | N | N |
| system. | Custom sign-in page is deleted. | N | N |
| system. | Custom sign-in page is updated. | N | N |
| system. | Custom sign-out page is updated. | N | N |
| system. | Okta managed certificates for custom domain are renewed. | N | N |
| system. | Custom domain certificates are uploaded by an admin or generated by Okta. | N | N |
| system. | Custom domain is deleted. | N | N |
| system. | Custom domain setup is initiated. | N | N |
| system. | Custom domain brand association is updated. | N | N |
| system. | Verify custom domain ownership. | N | N |
| system. | Extend Directory Debugger access for Okta support. | N | N |
| system. | Grant Directory Debugger access for Okta support. | N | N |
| system. | A read-only query executed against AD/LDAP instance by Okta support using the Directory Debugger tool. | N | N |
| system. | Revoke Directory Debugger access for Okta support. | N | N |
| system. | The Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. | N | N |
| system. | The Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. | N | N |
| system. | Send self-service account unlock email. | N | Y |
| system. | Attempted removal of one or more emails from bounce list. | N | N |
| system. | User completed an email factor challenge. | Y | N |
| system. | An email's delivery status was updated. | Y | N |
| system. | MFA enrollment notification email sent. | Y | N |
| system. | MFA reset notification email sent. | Y | N |
| system. | New device signin notification email sent. | Y | N |
| system. | Send self-service password reset email. | Y | Y |
| system. | An email was sent to a user for verification. | N | N |
| system. | This event is fired when a custom email template is created. | N | N |
| system. | This event is fired when a custom email template is deleted. | N | N |
| system. | This event is fired when the settings for an email template is changed. | N | N |
| system. | This event is fired when a custom email template has been updated. | N | N |
| system. | Email domain is created. | N | N |
| system. | Email domain is deleted. | N | N |
| system. | Email domain is updated. | N | N |
| system. | Verify email domain. | N | N |
| system. | Fired when self service features are requested to be disabled by admins. | N | N |
| system. | Fired when an org has subscribed to or unsubscribed from EA Feature Auto Enroll. | N | N |
| system. | Fired when self service features are requested to be enabled by admins. | N | N |
| system. | Create a new hook key. | N | N |
| system. | Delete a hook key. | N | N |
| system. | Update a hook key. | N | N |
| system. | Upload bulk delete data. | N | N |
| system. | Upload bulk groups delete data. | N | N |
| system. | Upload bulk group membership delete data. | N | N |
| system. | Upload bulk group membership upsert data. | N | N |
| system. | Upload bulk groups upsert data. | N | N |
| system. | Upload bulk upsert data. | N | N |
| system. | Create an identity source group. | N | N |
| system. | Delete an identity source group. | N | N |
| system. | Update an identity source group. | N | N |
| system. | Assign a user to an identity source group. | N | N |
| system. | Revoke a user from an identity source group. | N | N |
| system. | Create an identity source user. | N | N |
| system. | Delete an identity source user. | N | N |
| system. | Update an identity source user. | N | N |
| system. | Identity provider key credential created. | N | N |
| system. | Identity provider key credential deleted. | N | N |
| system. | Identity provider key credential updated. | N | N |
| system. | Identity provider activated. | Y | Y |
| system. | Identity provider created. | Y | Y |
| system. | Identity provider deactivated. | Y | Y |
| system. | Identity provider deleted. | Y | Y |
| system. | Identity provider(s) with a client secret is read. | Y | Y |
| system. | Identity provider updated. | Y | Y |
| system. | Clear Unconfirmed Imported Users. | N | N |
| system. | Import process complete. | Y | N |
| system. | Batch import process complete. | Y | N |
| system. | Import of custom objects completed. | Y | N |
| system. | Create custom object triggered by import process. | N | N |
| system. | Delete custom object triggered by import process. | N | N |
| system. | Update custom object triggered by import process. | N | N |
| system. | Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. | Y | N |
| system. | Fired at the start of the download objects phase, when the objects (users, groups, devices) to be imported are being downloaded from the system of record. | Y | N |
| system. | Emitted during the entitlement discovery process to identify entitlement schemas, excluding assignments. | N | N |
| system. | Skipping of entitlement during import of an user. | N | N |
| system. | Import of groups completed. | Y | N |
| system. | Create group triggered by import process. | N | N |
| system. | Remove group triggered by import process. | N | N |
| system. | Start importing groups from refreshing AppGroups. | Y | N |
| system. | Update group triggered from import process. | N | N |
| system. | Import of application group members completed. | Y | N |
| system. | Fired upon completion of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects. | Y | N |
| system. | Fired at the start of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects. | Y | N |
| system. | Import user profile triggered by import process. | N | N |
| system. | Import provisioning info triggered by import process. | Y | N |
| system. | Fired upon completion of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from. | Y | N |
| system. | Fired at the start of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from. | Y | N |
| system. | Fired upon completion of the object creation phase, when the first batch of objects is created/updated. | Y | N |
| system. | Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. | Y | N |
| system. | Import roadblock triggered due to exceeded threshold. | N | N |
| system. | The affected import from AppInstance has been rescheduled. | N | N |
| system. | The affected import from AppInstance has been canceled. | N | N |
| system. | Fired when an import roadblock (aka, Import Safeguard) has been updated. | N | N |
| system. | Import process was scheduled. | Y | N |
| system. | Import session for identity source canceled. | N | N |
| system. | Create new import session for identity source. | N | N |
| system. | Import session for identity source expired. | N | N |
| system. | Triggered import session for identity source. | N | N |
| system. | import started. | Y | N |
| system. | Import of user completed. | Y | N |
| system. | Create user triggered by import process. | Y | N |
| system. | Delete user triggered by import process. | Y | N |
| system. | Assign user triggered by import process with callback. | N | N |
| system. | Start importing users triggered import process. | N | N |
| system. | Suspend user triggered by import process. | N | N |
| system. | Unsuspend user triggered by import process. | N | N |
| system. | N | N | |
| system. | Update user triggered by import process. | Y | N |
| system. | Update user status triggered by import process. | N | N |
| system. | Bulk Import users from CSV is completed. | N | N |
| system. | Bulk Import of users from CSV is started. | N | N |
| system. | Import user matching assignment confirmed. | Y | N |
| system. | Assignment was unignored. | N | N |
| system. | Assignment was modified. | N | N |
| system. | Fired upon completion of the user matching phase, when Okta attempts to match imported users to existing Okta users. | Y | N |
| system. | Fired at the start of the user matching phase, when Okta attempts to match imported users to existing Okta users. | Y | N |
| system. | Create IWA agent. | N | N |
| system. | IWA going offline. | N | N |
| system. | IWA going online. | N | N |
| system. | Promote IWA agent to primary. | N | N |
| system. | Remove IWA agent. | N | N |
| system. | Update IWA agent. | N | N |
| system. | No primary IWA app found. | N | N |
| system. | Agentless IWA authentication. | N | N |
| system. | Fired after redirection from Agentless DSSO failure. | N | N |
| system. | Fired when an Agentless DSSO authentication request is redirected to an onprem IWA authentication or the default login page. | N | N |
| system. | Update to agentless IWA. | N | N |
| system. | Fired when a user could not be found during Agentless DSSO authentication, resulting in an authentication failure. | N | N |
| system. | Fires when a Kerberos realm settings is updated by an admin. | N | N |
| system. | This event indicates that an administrative limit was exceeded when processing an LDAP interface operation. | N | N |
| system. | Fired when a user performs a BIND to LDAP Interface. | N | N |
| system. | Fired when a user performs a SEARCH to LDAP Interface. | N | N |
| system. | Fired when a user performs an UNBIND to LDAP Interface. | N | N |
| system. | Log stream activated. | Y | N |
| system. | Log stream created. | Y | N |
| system. | Log stream deactivated. | Y | N |
| system. | Log stream deleted. | Y | N |
| system. | Log stream updated. | Y | N |
| system. | Activate a new authentication factor. | Y | N |
| system. | Deactivate MFA factor. | N | Y |
| system. | Request with valid bearer tokens made from outside the allowed network zone. | N | N |
| system. | Operation concurrency limit violation. | Y | N |
| system. | Operation rate limit violation. | Y | Y |
| system. | Operation rate limit warning. | N | N |
| system. | Enable org-wide captcha support. | N | N |
| system. | Disable org-wide captcha support. | N | N |
| system. | Org creation. | N | N |
| system. | Fired when burst rate limit capacity is activated. | Y | N |
| system. | Rate limit approaching expiration date. | N | N |
| system. | Rate limit violation. | Y | Y |
| system. | Rate limit warning. | Y | Y |
| system. | Tasks removed. | N | N |
| system. | Fired when a Push notification is sent to a device. | Y | Y |
| system. | Rate limit configuration update. | N | N |
| system. | Self-service for apps configuration updated. | Y | N |
| system. | Fired when receiving a status update on SMS message from provider. | N | N |
| system. | Send self-service account unlock SMS message. | N | Y |
| system. | Send second factor auth SMS. | N | N |
| system. | Send activate Okta Verify Push for mobile SMS. | N | N |
| system. | Send self-service password reset SMS message. | N | Y |
| system. | Send phone verification SMS message. | N | N |
| system. | This event is fired when the theme resource is updated. | N | N |
| system. | Fired when receiving a status update on voice call from provider. | N | N |
| system. | Send self-service account unlock call. | N | Y |
| system. | Send phone call. | N | N |
| system. | Send second factor auth call. | N | N |
| system. | Send self-service password reset call. | N | Y |
| system. | Send phone verification call. | N | N |
| system. | The well-known URI was updated. | N | N |
| system. | Upload bulk devices delete data. | N | N |
| system. | Upload bulk devices upsert data. | N | N |
system.agent.ad.config_change_detected
#Description
A monitored variable in an AD agent configuration file has changed. This can be used to audit that a customer's AD agent configuration file has changed. This event occurs when a monitored variable in an AD agent configuration file has changed.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
Okta.ADAgent.AuthenticationAnomaly.ZScore which detects the actual USE of stolen tokens through authentication pattern anomalies.T1098, T1528↳ also matches system.api_token.create
References #
system.agent.ad.dirsync.verify
#Description
Verify AD agent compatibility for DirSync-based imports. Use this event to audit which AD agents meet DirSync requirements, set up alerts when agents need remediation before DirSync-based imports can run, and troubleshoot import failures related to agent version or configuration gaps. outcome.result = SUCCESS indicates the agent meets all DirSync requirements. FAILURE indicates the agent requires intervention, such as a version upgrade (minimum 3.20.0) or service account permission changes.
References #
system.agent.ad.read_topology
#Description
Directory agent performed topology import operation.
References #
system.agent.ad.upload_iwa_log
#Description
Fired when an AD agent has fetched and uploaded IWA agent log file. This event fires when the log file upload is successful or fails. This can be used to audit that logs files are being fetched successfully, have been uploaded successfully, and troubleshoot why an IWA log upload has failed. When fired, this event indicates whether a log file upload has been successful or failed. This event also indicates whether the event was initiated by the Okta system or a user. Related events: none, all debugging context is included in this event.
References #
system.agent.auto_update
#Description
Fired when an individual agent auto-update succeeds or fails. Confirms a successful agent auto-update, or provides troubleshooting information when the agent auto-update is unsuccessful. Indicates when an agent auto-update is successful or unsuccessful.
References #
system.agent.ldap.change_user_password
#Description
Perform change user password by LDAP agent.
References #
system.agent.ldap.config_change_detected
#Description
A monitored variable in an LDAP agent configuration file has changed. This can be used to audit when a customer's LDAP agent configuration file has changed. This event occurs when a monitored variable in an LDAP agent configuration file has changed.
References #
system.agent.ldap.realtimesync
#Description
Fired when LDAP Delegated Authentication is used to sign in and a user profile is updated using RealTimeSync action. Can be used by admins to identify user profile changes resulting from corresponding changes in the LDAP directory. The previous name for this event was system.agent.ad.realtimesync.
References #
system.agent.ldap.unlock_user_account
#Description
LDAP agent performed account unlock for User.
References #
system.agent.ldap.update_user
#Description
Fired when LDAP Delegated Authentication is used to sign in and a user profile is updated. Can be used by admins to identify user profile changes resulting from corresponding changes in the LDAP directory. The previous name for this event was system.agent.ad.update_user.
References #
system.agent.ldap.update_user_password
#Description
Perform update user password by LDAP agent.
References #
system.agent.register
#Description
Agent was registered. This event indicates that an agent (such as Okta Provisioning Agent, Okta RSA SecurID Agent, and so on) has been successfully registered with the Okta org. This also provides a signal to all admins of the Okta org that a new agent was registered, which improves the overall security posture. This event can be used to track the deployment and integration of Okta agents across an org's infrastructure. This information can be useful for security audits, compliance reporting, and managing the overall Okta ecosystem.
References #
system.agent_pools.auto_update
#Description
Fired when the status of an agent pool auto-update is changed. Confirms an agent pool auto-update status change and provides troubleshooting information. Indicates when the status of an agent pool auto-update is changed.
References #
system.api_token.create
#Description
Create API token. This event occurs when a new unscoped API token is generated within the system. The unscoped API token grants authenticated access to the system's API for automated tasks or integration purposes. Event log details include the token ID, the user, or service it was created for, and the time of creation. This information helps maintain a secure API access framework by allowing administrators to track token issuance. Administrators can also enforce least privilege access and promptly identify any unauthorized token creation.
Example System Log Event #
{
"actor": {
"alternateId": "user11@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 18",
"id": "00u00000000000000017",
"type": "User"
},
"authenticationContext": {
"authenticationProvider": null,
"authenticationStep": 0,
"credentialProvider": null,
"credentialType": null,
"externalSessionId": "0000000000000000000000074",
"interface": null,
"issuer": null
},
"client": {
"device": "Computer",
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"id": null,
"ipAddress": "198.51.100.10",
"userAgent": {
"browser": "CHROME",
"os": "Mac OS 14.3.1 (Sonoma)",
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
},
"zone": "null"
},
"debugContext": {
"debugData": {
"concurrencyPercentage": "50",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000075",
"rateLimitPercentage": "50",
"requestId": "00000000000000000000000000000076",
"requestUri": "/api/internal/tokens",
"url": "/api/internal/tokens?expand=user"
}
},
"device": null,
"displayMessage": "Create API token",
"eventType": "system.api_token.create",
"legacyEventType": "api.token.create",
"outcome": {
"reason": null,
"result": "SUCCESS"
},
"published": "2024-03-06T20:08:34.848Z",
"request": {
"ipChain": [
{
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"ip": "198.51.100.10",
"source": null,
"version": "V4"
}
]
},
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"domain": "example.com",
"isProxy": false,
"isp": "example-isp"
},
"severity": "INFO",
"target": [
{
"alternateId": "user07@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 19",
"id": "00T00000000000000018",
"type": "Token"
}
],
"transaction": {
"detail": {},
"id": "00000000000000000000000000000076",
"type": "WEB"
},
"uuid": "00000000-0000-0000-0000-000000000010",
"version": "0"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType | eq | system.api_token.create | 2 rules | panther, sigma |
okta::eventType (kusto rule field) | in | system.api_token.create | 2 rules | kusto |
okta::eventType (kusto rule field) | in | policy.evaluate_sign_on | 1 rule | kusto |
All_Changes.action (splunk rule field) | eq | created | 1 rule | splunk |
outcome.result (panther rule field) | eq | SUCCESS | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1098, T1098.001, T1136Splunk #
system.api_token.create command is executed.…T1078, T1078.001Kusto #
T1078, T1078.004, T1098T1078, T1098, T1556↳ also matches system.api_token.revoke, system.mfa.factor.deactivate YARA-L #
T1078Panther #
T1528Okta.ADAgent.AuthenticationAnomaly.ZScore which detects the actual USE of stolen tokens through authentication pattern anomalies.T1098, T1528↳ also matches system.agent.ad.config_change_detected
References #
system.api_token.request_outside_allowed_range
#Description
Request with API tokens made from outside the allowed network zone. Use to detect when an API token comes from an IP address that's outside of the specified allowed zone. Fired when an API token comes from an IP address that's outside of the specified allowed zone of the token.
References #
system.api_token.revoke
#Description
Revoke API token.
Example System Log Event #
{
"published": 1780768813892,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000085",
"actor": {
"id": "0000003",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "00t00000000000000288",
"type": "Token",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 99",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.api_token.revoke",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "00000000000000000000000000000045",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Revoke API token",
"gatewayContext": null,
"legacyEventType": "api.token.revoke",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType | eq | system.api_token.revoke | 2 rules | panther, sigma |
outcome.result (panther rule field) | eq | SUCCESS | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
T1531Kusto #
T1078, T1098, T1556↳ also matches system.api_token.create, system.mfa.factor.deactivate Panther #
References #
system.api_token.update
#Description
An API token has been updated. This event can be used to identify a change to an existing API token, such as a change to the applicable rate limits for the token. Details of the change can be found in the debugData. This event does not change whether the token is valid for use, for actions that impact validity see system.api_token.enable and system.api_token.revoke.
Example System Log Event #
{
"published": 1784123665870,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000086",
"actor": {
"id": "00u00000000000000026",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000027"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00t00000000000000289",
"type": "Token",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 100",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.api_token.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000046",
"detail": {}
},
"debugContext": {
"debugData": {
"concurrencyPercentage": "50",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"includedNetworkZones": "[nzo00000000000000290]",
"requestId": "00000000000000000000000000000046",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"origin": "https://app.example.com",
"rateLimitPercentage": "50",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"networkConnection": "ZONE",
"requestUri": "0000000000000000000000000000000000000000000000000000000002",
"url": "0000000000000000000000000000000000000000000000000000000002?expand=Example App 61"
}
},
"displayMessage": "Update API token",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Device",
"id": "bhv00000000000000031",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000032",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000033",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000034",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000035",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000036",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000037",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000038",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000291",
"externalSessionId": "10200000000000000291"
}
}
References #
system.beta.feature.enable
#Description
Fired when an admin has enabled a BETA feature. This can be used to understand the status of the BETA Feature and identify who has enabled it for an org. When fired, this event contains information about the enabled BETA Feature, as well as the admin who enabled it.
References #
system.brand.create
#Description
This event is fired when the brand resource is created. Developer and org admins can use this event to identify when the brand resource was created. The event contains information about the created brand.
References #
system.brand.update
#Description
This event is fired when the brand resource is updated. Developer and org admins can use this event to identify when the brand resource was updated. The event contains information regarding specific updates made to brand like "customPrivacyPolicyUrl".
References #
system.captcha.create
#Description
A captcha instance is created for Sign-in Widget. Indicates when a captcha instance was created. This event is fired when org admin creates a captcha instance.
References #
system.captcha.delete
#Description
A captcha instance is deleted. Indicates when a captcha instance was deleted. This event is fired when org admin deletes a captcha instance.
References #
system.captcha.update
#Description
A captcha instance is updated. Indicates when a captcha instance was updated. This event is fired when org admin updates a captcha instance.
References #
system.client.concurrency_rate_limit.notification
#Description
Notify when too many requests in flight for client. This can be used to notify whenever there are too many concurrent requests from a client without enforcing any violation. When fired, this event contains information about the request such as client, device and ip details.
References #
system.client.concurrency_rate_limit.violation
#Description
Too many requests in flight for client. This can be used to track if there are too many concurrent requests from a client. When fired, this event contains information about the request such as client, device and ip details.
Example System Log Event #
{
"published": 1780867129756,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000087",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "fasthttp",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "192.0.2.36",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000292",
"type": "PublicClientApp",
"alternateId": null,
"displayName": "DW Harness 101",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.36",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "system.client.concurrency_rate_limit.violation",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000047",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000292",
"clientType": "OAUTH2",
"requestId": "00000000000000000000000000000047",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000026",
"ip": "192.0.2.36",
"threshold": "5",
"requestUri": "/oauth2/v1/authorize",
"threatSuspected": "false",
"orgId": "00o00000000000000286",
"url": "/oauth2/v1/authorize?client_id=2uw00000000000000293&redirect_uri=00000000000000000000000000000000000000000000000002&scope=xki00000000000000294&response_type=code&state=00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002"
}
},
"displayMessage": "Too many requests in flight for client",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1110, T1498↳ also matches system.client.rate_limit.violation, system.operation.rate_limit.violation, system.org.rate_limit.violation
References #
system.client.rate_limit.notification
#Description
Notify when client rate limits are exceeded. This can be used to notify whenever a client is exceeding its rate limit without enforcing any violation. When fired, this event contains information about the request such as client, device and ip details.
References #
system.client.rate_limit.violation
#Description
Client rate limit violation. This can be used to track if a client is exceeding its rate limit. When fired, this event contains information about the request such as client, device and ip details.
Example System Log Event #
{
"published": 1784282811881,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000088",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36",
"os": "Windows 10",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.30",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000292",
"type": "PublicClientApp",
"alternateId": null,
"displayName": "DW Harness 101",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.30",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"ipServiceCategories": [
{
"type": "Proxy",
"isAnonymous": false
}
]
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "system.client.rate_limit.violation",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000048",
"detail": {}
},
"debugContext": {
"debugData": {
"clientId": "0oa00000000000000292",
"ip": "192.0.2.30",
"threshold": "60",
"requestUri": "/oauth2/v1/authorize",
"orgId": "00o00000000000000286",
"url": "/oauth2/v1/authorize?client_id=c2c00000000000000295&redirect_uri=00000000000000000000000000000000000000000000000002&scope=ceo00000000000000296&response_type=code&state=000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002",
"deviceTokenHash": "0000000000000000000000000000000000000000014=",
"clientType": "OAUTH2",
"requestId": "00000000000000000000000000000048",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000027",
"timeSpan": "1",
"threatSuspected": "false",
"timeUnit": "MINUTES"
}
},
"displayMessage": "Client rate limit violation",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1110, T1498↳ also matches system.client.concurrency_rate_limit.violation, system.operation.rate_limit.violation, system.org.rate_limit.violation
References #
system.csv.import_user
#Description
Import of user from CSV is skipped. Informs when import of a user from CSV has been skipped due to reasons such as missing required attributes or unknown unique identifier. This event is logged when import of a user is skipped during CSV directory import workflow for on-premises systems using Okta provisioning agent.
References #
system.custom_email_server.lifecycle.activate
#Description
Enable a custom email server. Audit the enablement of a custom email server.
References #
system.custom_email_server.lifecycle.create
#Description
Create a custom email server. Audit the creation of a custom email server.
References #
system.custom_email_server.lifecycle.deactivate
#Description
Disable a custom email server. Audit the disablement of a custom email server.
References #
system.custom_email_server.lifecycle.delete
#Description
Delete a custom email server. Audit the deletion of a custom email server.
References #
system.custom_email_server.lifecycle.update
#Description
Update a custom email server. Audit an update to the configuration of a custom email server.
References #
system.custom_error.delete
#Description
Custom error page is deleted. Can be used to identify when an admin has deleted the custom error page. Event fired when the custom error page is deleted.
References #
system.custom_error.update
#Description
Custom error page is updated. Can be used to identify when an admin has customized the error page. Event fired when the error page is successfully updated.
References #
system.custom_signin.delete
#Description
Custom sign-in page is deleted. Can be used to identify when an admin has deleted the custom sign-in page. Event fired when custom sign-in page is deleted.
References #
system.custom_signin.update
#Description
Custom sign-in page is updated. Can be used to identify when an admin has customized the sign-in page. Event fired when custom sign-in page is updated.
References #
system.custom_signout.update
#Description
Custom sign-out page is updated. Admin has updated the custom sign-out page. Event fired when custom sign-out page is updated.
References #
system.custom_url_domain.cert_renew
#Description
Okta managed certificates for custom domain are renewed. Can be used to identify when okta managed certificate renewal batch job has renewed certificates for custom domain. When fired, the event contains information about the domain name and certificate source type.
References #
system.custom_url_domain.cert_upload
#Description
Custom domain certificates are uploaded by an admin or generated by Okta. Can be used to identify when custom domain certificates are uploaded by an admin or generated by Okta. When fired, the event contains information about the domain name and certificate source type.
References #
system.custom_url_domain.delete
#Description
Custom domain is deleted. Can be used to identify when an admin has deleted their custom domain. When fired, the event contains information about the domain name that was deleted.
References #
system.custom_url_domain.initiate
#Description
Custom domain setup is initiated. Admin has initiated custom domain setup by inputting their custom domain for DNS verification. When fired, the event contains information about the domain name, certificate source type and domain validation status.
References #
system.custom_url_domain.update
#Description
Custom domain brand association is updated. Admin has updated the custom domain association with the brand. When fired, the event contains the domain name, certificate source type, domain validation status and information about the brand it is associated with.
References #
system.custom_url_domain.verify
#Description
Verify custom domain ownership. Identifies whether an admin has succeeded or failed to verify the ownership of the domain name. When fired, the event contains information about the domain name, certificate source type and domain validation status.
References #
system.directory.debugger.extend
#Description
Extend Directory Debugger access for Okta support. This can be used to audit the Directory Debugger access extension. When fired, this event contains information about Directory Debugger access extension.
References #
system.directory.debugger.grant
#Description
Grant Directory Debugger access for Okta support. This can be used to audit the Directory Debugger access grants to Okta support. When fired, this event contains information about Directory Debugger access grant.
References #
system.directory.debugger.query_executed
#Description
A read-only query executed against AD/LDAP instance by Okta support using the Directory Debugger tool. This can be used to audit the queries executed by Okta support using Directory Debugger. When fired, this event contains information about Directory Debugger query.
References #
system.directory.debugger.revoke
#Description
Revoke Directory Debugger access for Okta support. This can be used to audit the Directory Debugger access revoke. When fired, this event contains information about Directory Debugger access revoke.
References #
system.dr.failback
#Description
The Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. Triggered when the Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. This event is fired when the Enhanced Disaster Recovery (EDR) failback operation for the org domains were initiated. If failback is successful, the outcome for this event will be SUCCESS. If failback is not successful, the outcome for this event will be FAILURE.
References #
system.dr.failover
#Description
The Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. Triggered when the Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. This event is fired when the Enhanced Disaster Recovery (EDR) failover operation for the org domains were initiated. If failover is successful, the outcome for this event will be SUCCESS. If failover is not successful, the outcome for this event will be FAILURE.
References #
system.email.account_unlock.sent_message
#Description
Send self-service account unlock email.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004↳ also matches system.email.password_reset.sent_message, system.sms.send_account_unlock_message, system.sms.send_password_reset_message, system.voice.send_account_unlock_call, system.voice.send_password_reset_call
References #
system.email.bounce.removal
#Description
Attempted removal of one or more emails from bounce list. Identify email addresses which were submitted to Okta for removal from the email bounce list. This event does not guarantee that an email was removed from the bounce list, it only indicates that Okta contacted the email provider to attempt to remove if from the bounce list. The debugData object contains a reference to the email provider contacted by Okta which maintains the bounce list. The target object contains a list of email addresses which were submitted. A single target contains a maximum of 50 email addresses. Multiple events may be fired in response to a removal request.
References #
system.email.challenge_factor_redeemed
#Description
User completed an email factor challenge. This can be used to identify when a credential sent in an email to a user has been redeemed (the link was clicked or the code was entered). When fired, this event contains information about the result. Success if successful or error reasons should be present for failure cases (e.g. incorrect code, timeout, expired, etc.). The event also contains a debugData with the action (the link was clicked or the code was entered).
Example System Log Event #
{
"published": 1785244702483,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000089",
"actor": {
"id": "00u00000000000000297",
"type": "User",
"alternateId": "user65@dw-harness.example",
"displayName": "DW Harness 102",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"os": "Windows 11",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": {
"id": null,
"name": null,
"os_platform": null,
"os_version": null,
"managed": null,
"registered": null,
"device_integrator": {
"DEVICE_IDP": {}
},
"disk_encryption_type": null,
"screen_lock_type": null,
"jailbreak": null,
"secure_hardware_present": null
},
"events": null,
"target": [
{
"id": "00u00000000000000297",
"type": "User",
"alternateId": "user65@dw-harness.example",
"displayName": "DW Harness 102",
"detailEntry": {
"realmId": "guo00000000000000044"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.email.challenge_factor_redeemed",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000049",
"detail": {}
},
"debugContext": {
"debugData": {
"sameBrowser": "true",
"behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
"origin": "https://app.example.com",
"requestUri": "/idp/idx/introspect",
"url": "/idp/idx/introspect?",
"flowContinuation": "new tab",
"authnRequestId": "00000000000000000000000000000050",
"requestId": "00000000000000000000000000000049",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000028",
"action": "link clicked",
"risk": "{level=LOW}",
"threatSuspected": "false",
"verification": "link clicked"
}
},
"displayMessage": "Credential in email has been redeemed",
"gatewayContext": null,
"legacyEventType": "system.email.challenge_factor_redeemed",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "LOW"
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "NEGATIVE"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "NEGATIVE"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "NEGATIVE"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "NEGATIVE"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "NEGATIVE"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "NEGATIVE"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000298",
"externalSessionId": "idx00000000000000298"
}
}
References #
system.email.delivery
#Description
An email's delivery status was updated. Used to notify admins of a bounced or dropped email. For certain bounce events, the context information may be lost by the email provider(s) due to email server communication delays. Such delayed bounce events will not appear in syslog. As of the 2022.08.0 release, this is also used to identify other email events e.g. delivered, deferred. See the event debugData for help identifying a remediation, such as updating an incorrect email address.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "SystemPrincipal",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000077",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Email delivery",
"eventType": "system.email.delivery",
"outcome": {
"result": "DEFERRED",
"reason": "deferred"
},
"published": "2026-07-02T18:36:06.442Z",
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"severity": "INFO",
"debugContext": {
"debugData": {
"appContextName": "None",
"emailProvider": "sendgrid",
"category": "email.welcome",
"userId": "",
"emailRequestId": "00000000000000000000000000000004"
}
},
"legacyEventType": null,
"transaction": {
"type": "JOB",
"id": "00000000000000000000",
"detail": {}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": []
},
"target": [
{
"id": "00000000000000000000",
"type": "email",
"alternateId": null,
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
system.email.mfa_enroll_notification.sent_message
#Description
MFA enrollment notification email sent. Used to notify admins MFA enrollment notification email has been sent.
Example System Log Event #
{
"published": 1781380212664,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000090",
"actor": {
"id": "00u00000000000000299",
"type": "User",
"alternateId": "user66@dw-harness.example",
"displayName": "DW Harness 103",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "app.example.com.mobile/9.63.0 OktaDeviceSDK/0.0.1 macOS/26.3.2 Apple/Mac17,9 00000000-0000-0000-0000-000000000091",
"os": "Mac OS X",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.31",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000299",
"type": "User",
"alternateId": "user66@dw-harness.example",
"displayName": "DW Harness 103",
"detailEntry": {
"realmId": "guo00000000000000044"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.31",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.email.mfa_enroll_notification.sent_message",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000051",
"detail": {}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000051",
"requestUri": "/idp/authenticators",
"url": "/idp/authenticators?"
}
},
"displayMessage": "Send Example App 61 MFA enrollment notification email",
"gatewayContext": null,
"legacyEventType": "core.user.email.message_sent.mfa_enroll_notification",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000300",
"externalSessionId": "trs00000000000000300"
}
}
References #
system.email.mfa_reset_notification.sent_message
#Description
MFA reset notification email sent. Used to notify admins MFA reset notification email has been sent.
Example System Log Event #
{
"published": 1780408053181,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000092",
"actor": {
"id": "00u00000000000000164",
"type": "User",
"alternateId": "user03@dw-harness.example",
"displayName": "DW Harness 04",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00u00000000000000301",
"type": "User",
"alternateId": "user67@dw-harness.example",
"displayName": "DW Harness 104",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.email.mfa_reset_notification.sent_message",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000052",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000052",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000029",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000000000000000000000002",
"url": "00000000000000000000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Send Example App 61 MFA reset notification email",
"gatewayContext": null,
"legacyEventType": "core.user.email.message_sent.mfa_reset_notification",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000302",
"externalSessionId": "10200000000000000302"
}
}
References #
system.email.new_device_notification.sent_message
#Description
New device signin notification email sent.
Example System Log Event #
{
"published": 1780189574865,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000093",
"actor": {
"id": "00u00000000000000303",
"type": "User",
"alternateId": "user68@dw-harness.example",
"displayName": "DW Harness 105",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.35",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": {
"id": null,
"name": null,
"os_platform": null,
"os_version": null,
"managed": null,
"registered": null,
"device_integrator": {
"DEVICE_IDP": {}
},
"disk_encryption_type": null,
"screen_lock_type": null,
"jailbreak": null,
"secure_hardware_present": null
},
"events": null,
"target": [
{
"id": "00u00000000000000303",
"type": "User",
"alternateId": "user68@dw-harness.example",
"displayName": "DW Harness 105",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.35",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.email.new_device_notification.sent_message",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000053",
"detail": {}
},
"debugContext": {
"debugData": {
"authnRequestId": "00000000000000000000000000000054",
"deviceFingerprint": "00000000000000000000000000000055",
"behaviors": "{New Geo-Location=UNKNOWN, New Device=UNKNOWN, New ASN=UNKNOWN, New IP=UNKNOWN, New State=UNKNOWN, New Country=UNKNOWN, Velocity=UNKNOWN, New City=UNKNOWN}",
"requestId": "00000000000000000000000000000053",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000030",
"risk": "{reasons=Anomalous Location, Anomalous Device, level=HIGH}",
"requestUri": "/idp/idx/challenge/answer",
"threatSuspected": "false",
"url": "/idp/idx/challenge/answer?"
}
},
"displayMessage": "Send Example App 61 new device notification email",
"gatewayContext": null,
"legacyEventType": "core.user.email.message_sent.new_device_notification",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "HIGH",
"reasons": [
"Anomalous Location",
"Anomalous Device"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "UNKNOWN"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "UNKNOWN"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "UNKNOWN"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "UNKNOWN"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "UNKNOWN"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "UNKNOWN"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "UNKNOWN"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "UNKNOWN"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000304",
"externalSessionId": "idx00000000000000304"
}
}
References #
system.email.password_reset.sent_message
#Description
Send self-service password reset email.
Example System Log Event #
{
"published": 1785244692098,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000094",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"os": "Windows 11",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": {
"id": null,
"name": null,
"os_platform": null,
"os_version": null,
"managed": null,
"registered": null,
"device_integrator": {
"DEVICE_IDP": {}
},
"disk_encryption_type": null,
"screen_lock_type": null,
"jailbreak": null,
"secure_hardware_present": null
},
"events": null,
"target": [
{
"id": "00u00000000000000297",
"type": "User",
"alternateId": "user65@dw-harness.example",
"displayName": "DW Harness 102",
"detailEntry": {
"emailAddress": "user65@dw-harness.example",
"realmId": "guo00000000000000044"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.email.password_reset.sent_message",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000056",
"detail": {}
},
"debugContext": {
"debugData": {
"authnRequestId": "00000000000000000000000000000050",
"deviceFingerprint": "00000000000000000000000000000057",
"behaviors": "{New Geo-Location=NEGATIVE, New Device=NEGATIVE, New ASN=NEGATIVE, New IP=NEGATIVE, New State=NEGATIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
"requestId": "00000000000000000000000000000056",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000028",
"origin": "https://app.example.com",
"risk": "{level=LOW}",
"requestUri": "/idp/idx/challenge",
"threatSuspected": "false",
"url": "/idp/idx/challenge?"
}
},
"displayMessage": "Send self-service password reset email",
"gatewayContext": null,
"legacyEventType": "core.user.email.message_sent.self_service.password_reset",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "LOW"
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "NEGATIVE"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "NEGATIVE"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "NEGATIVE"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "NEGATIVE"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "NEGATIVE"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "NEGATIVE"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "idx00000000000000298",
"externalSessionId": "idx00000000000000298"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004↳ also matches system.email.account_unlock.sent_message, system.sms.send_account_unlock_message, system.sms.send_password_reset_message, system.voice.send_account_unlock_call, system.voice.send_password_reset_call
References #
system.email.send_factor_verify_message
#Description
An email was sent to a user for verification. Used to notify admins that an email was sent to a user for verification. When fired, this event contains information about the token lifetime in the debugData.
References #
system.email.template.create
#Description
This event is fired when a custom email template is created. Developers and Org Admins can use this to identify when a default email template has been overridden with a new template. The event details can be used to identify the template type and template engine. Usually this event will precede "system.email.template.update" or "system.email.template.delete" events.
References #
system.email.template.delete
#Description
This event is fired when a custom email template is deleted. Developers and Org Admins can use this to identify when a custom email template has been deleted to fall back to default template. The event details can be used to identify the template type and template engine. Usually this event will follow "system.email.template.create" or "system.email.template.update" events.
References #
system.email.template.settings_changed
#Description
This event is fired when the settings for an email template is changed. Developers and Org Admins can use this to identify when an email template setting has been changed. When fired, this event contains information about the email template and settings that were changed.
References #
system.email.template.update
#Description
This event is fired when a custom email template has been updated. Developers and Org Admins can use this to identify when a custom email template has been updated. The event details can be used to identify the template type and template engine. Usually this event will follow "system.email.template.create" and precede "system.email.template.delete" events.
References #
system.email_domain.create
#Description
Email domain is created. Admin has initiated email domain setup by inputting their domain details for DNS verification. When fired, the event contains information about the domain name, display name, user name, brand id and validation status.
References #
system.email_domain.delete
#Description
Email domain is deleted. Can be used to identify when an admin has deleted their email domain. When fired, the event contains information about the email domain that was deleted.
References #
system.email_domain.update
#Description
Email domain is updated. Admin has updated the email domain. When fired, the event contains information about the email domain that was updated.
References #
system.email_domain.verify
#Description
Verify email domain. Identifies whether an admin has succeeded or failed to verify the email domain. When fired, the event contains information about the email domain that is being verified.
References #
system.feature.disable
#Description
Fired when self service features are requested to be disabled by admins. Use to determine who enabled the features and any limitations the features have. When fired, this event contains information about the requested features, their names and lifecycle state, the admin who made the change, and any possible limitations associated with the features. Related events include 'system.feature.enable'.
References #
system.feature.ea_auto_enroll
#Description
Fired when an org has subscribed to or unsubscribed from EA Feature Auto Enroll. This can be used to understand the status of EA Feature Auto Enroll subscription and identify who has made changes to the subscription. When fired, this event contains information about the status of EA Feature Auto enroll subscription, as well as the admin who made any subscription changes.
References #
system.feature.enable
#Description
Fired when self service features are requested to be enabled by admins. Use to determine who enabled the features and any limitations the features have. When fired, this event contains information about the requested features, their names and lifecycle state, the admin who made the change, and any possible limitations associated with the features. Related events include 'system.feature.disable'.
References #
system.hook.key.created
#Description
Create a new hook key. This event can be used to identify when an admin created a new hook key. When triggered, this events contains information about the created hook key.
References #
system.hook.key.deleted
#Description
Delete a hook key. This event can be used to identify when an admin deleted a hook key. When triggered, this events contains information about the deleted hook key.
References #
system.hook.key.updated
#Description
Update a hook key. This event can be used to identify when an admin updated a hook key. When triggered, this events contains information about the updated hook key.
References #
system.identity_sources.bulk_delete
#Description
Upload bulk delete data. Loads bulk data into an Identity Source Session for deactivation in Okta for an identity source. This event can be used to track the deactivations of user profiles in Okta from the custom identity source.
References #
system.identity_sources.bulk_group_delete
#Description
Upload bulk groups delete data. Loads bulk groups data into an Identity Source Session for deactivation in Okta for an identity source. This event can be used to track the deactivations of groups profiles in Okta from the custom identity source.
References #
system.identity_sources.bulk_group_membership_delete
#Description
Upload bulk group membership delete data. Loads bulk group membership data into an Identity Source Session to delete group membership in Okta for an identity source. This event can be used to track the deletion of group membership in Okta from the custom identity source.
References #
system.identity_sources.bulk_group_membership_upsert
#Description
Upload bulk group membership upsert data. Loads bulk group membership data into an Identity Source Session for adding group membership in Okta for an identity source. This event can be used to track the addition of group membership in Okta from the custom identity source.
References #
system.identity_sources.bulk_group_upsert
#Description
Upload bulk groups upsert data. Loads bulk groups data into an Identity Source Session for inserting or updating groups profiles in Okta for an identity source. This event can be used to track the insertions and updates of group profiles in Okta from the custom identity source.
References #
system.identity_sources.bulk_upsert
#Description
Upload bulk upsert data. Loads bulk data into an Identity Source Session for inserting or updating user profiles in Okta for an identity source. This event can be used to track the insertions and updates of Okta user profiles from the custom identity source.
References #
system.identity_sources.group.create
#Description
Create an identity source group. Creates a new group in Okta from an identity source. This event tracks the creation of a group in Okta sourced from a custom identity source.
References #
system.identity_sources.group.delete
#Description
Delete an identity source group. Deletes a group in Okta from an identity source. This event tracks the deletion of a group in Okta sourced from a custom identity source.
References #
system.identity_sources.group.update
#Description
Update an identity source group. Updates a group in Okta from an identity source. This event tracks the update of a group profile in Okta sourced from a custom identity source. Payload must include changeDetails.
References #
system.identity_sources.group.user.assign
#Description
Assign a user to an identity source group. Assigns a user to an identity source group in Okta. This event tracks the assignment of a user to a group in Okta sourced from a custom identity source.
References #
system.identity_sources.group.user.revoke
#Description
Revoke a user from an identity source group. Revokes a user from an identity source group in Okta. This event tracks the removal of a user from a group in Okta sourced from a custom identity source.
References #
system.identity_sources.user.create
#Description
Create an identity source user. Creates a new user in Okta from an identity source. This event tracks the creation of a user in Okta sourced from a custom identity source.
References #
system.identity_sources.user.delete
#Description
Delete an identity source user. Deletes a user in Okta from an identity source. This event tracks the deletion of a user in Okta sourced from a custom identity source.
References #
system.identity_sources.user.update
#Description
Update an identity source user. Updates a user in Okta from an identity source. This event tracks the update of a user profile in Okta sourced from a custom identity source. Payload must include changeDetails.
References #
system.idp.key.create
#Description
Identity provider key credential created. This can be used to audit that a new identity provider key credential has been created. When fired, this event indicates a new X.509 certificate credential is added to the IdP key store.
References #
system.idp.key.delete
#Description
Identity provider key credential deleted. This can be used to audit that an identity provider key credential has been deleted. When fired, this event indicates a X.509 certificate credential by kid is deleted if it isn't currently being used by an active or inactive IdP.
References #
system.idp.key.update
#Description
Identity provider key credential updated. This can be used to audit that an identity provider key credential has been updated. When fired, this event indicates a X.509 certificate credential is updated in the IdP key store.
References #
system.idp.lifecycle.activate
#Description
Identity provider activated. This can be used to audit that an identity provider has been activated. When fired, this event indicates an Identity provider was activated. This event also indicates the type of the identity provider that was activated.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000069",
"externalSessionId": "trs00000000000000069"
},
"displayMessage": "Activate an Identity Provider",
"eventType": "system.idp.lifecycle.activate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:24:02.106Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"protocol": "OIDC",
"requestId": "00000000000000000000000000000077",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/idps/0oa00000000000000067/lifecycle/activate",
"url": "/api/v1/idps/0oa00000000000000067/lifecycle/activate?"
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000077",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000089",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000067",
"type": "IdentityProvider",
"alternateId": "oidc_idp",
"displayName": "DW Harness 29",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1087, T1087.004↳ also matches system.idp.lifecycle.create, system.idp.lifecycle.deactivate, system.idp.lifecycle.delete Panther #
T1098, T1199, T1556↳ also matches system.idp.lifecycle.create, system.idp.lifecycle.deactivate, system.idp.lifecycle.delete, system.idp.lifecycle.read_client_secret, system.idp.lifecycle.update
References #
system.idp.lifecycle.create
#Description
Identity provider created. This can be used to audit that a new identity provider has been created. When fired, this event indicates an Identity provider was successfully created. This event also indicates the type of the identity provider that was created.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000040",
"externalSessionId": "0000000000000000000000040"
},
"displayMessage": "Create an Identity Provider",
"eventType": "system.idp.lifecycle.create",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:24:01.398Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"protocol": "OIDC",
"requestId": "00000000000000000000000000000074",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/idps",
"url": "/api/v1/idps?"
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000074",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000086",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000067",
"type": "IdentityProvider",
"alternateId": "oidc_idp",
"displayName": "DW Harness 29",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098, T1098.001Elastic #
Splunk #
T1087, T1087.004↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.deactivate, system.idp.lifecycle.delete Panther #
T1098, T1199, T1556↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.deactivate, system.idp.lifecycle.delete, system.idp.lifecycle.read_client_secret, system.idp.lifecycle.update
References #
system.idp.lifecycle.deactivate
#Description
Identity provider deactivated. This can be used to audit that an identity provider has been deactivated. When fired, this event indicates an Identity provider has been deactivated. This event also indicates the type of the identity provider that was deactivated.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000068",
"externalSessionId": "trs00000000000000068"
},
"displayMessage": "Deactivate an Identity Provider",
"eventType": "system.idp.lifecycle.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:24:01.800Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"protocol": "OIDC",
"requestId": "00000000000000000000000000000076",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/idps/0oa00000000000000067/lifecycle/deactivate",
"url": "/api/v1/idps/0oa00000000000000067/lifecycle/deactivate?"
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000076",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000088",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000067",
"type": "IdentityProvider",
"alternateId": "oidc_idp",
"displayName": "DW Harness 29",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1087, T1087.004↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.create, system.idp.lifecycle.delete Panther #
T1098, T1199, T1556↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.create, system.idp.lifecycle.delete, system.idp.lifecycle.read_client_secret, system.idp.lifecycle.update
References #
system.idp.lifecycle.delete
#Description
Identity provider deleted. This can be used to audit that an identity provider has been deleted. When fired, this event indicates an Identity provider was deleted. This event also indicates the type of the identity provider that was deleted.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000070",
"externalSessionId": "trs00000000000000070"
},
"displayMessage": "Delete an Identity Provider",
"eventType": "system.idp.lifecycle.delete",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-25T23:24:02.758Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"protocol": "OIDC",
"requestId": "00000000000000000000000000000078",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/idps/0oa00000000000000067",
"url": "/api/v1/idps/0oa00000000000000067?"
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000078",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000090",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000067",
"type": "IdentityProvider",
"alternateId": "oidc_idp",
"displayName": "DW Harness 29",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1087, T1087.004↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.create, system.idp.lifecycle.deactivate Panther #
T1098, T1199, T1556↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.create, system.idp.lifecycle.deactivate, system.idp.lifecycle.read_client_secret, system.idp.lifecycle.update
References #
system.idp.lifecycle.read_client_secret
#Description
Identity provider(s) with a client secret is read. This can be used to audit that identity provider(s) with a client secret has been read. When fired, this event indicates one or more Identity providers with a client secret was read.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000058",
"externalSessionId": "trs00000000000000058"
},
"displayMessage": "Read an Identity Provider",
"eventType": "system.idp.lifecycle.read_client_secret",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-24T03:47:48.717Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"idpIdsWithSecrets": "[0oa00000000000000057]",
"protocol": "OIDC",
"requestId": "00000000000000000000000000000068",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/idps/0oa00000000000000057",
"url": "/api/v1/idps/0oa00000000000000057?"
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000068",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000079",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000057",
"type": "IdentityProvider",
"alternateId": "oidc_idp",
"displayName": "DW Harness 21",
"detailEntry": null
}
]
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1098, T1199, T1556↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.create, system.idp.lifecycle.deactivate, system.idp.lifecycle.delete, system.idp.lifecycle.update
References #
system.idp.lifecycle.update
#Description
Identity provider updated. This can be used to audit that an identity provider configuration has been updated. When fired, this event indicates an Identity provider configuration was updated. This event also indicates the type of the identity provider that was updated.
Example System Log Event #
{
"actor": {
"alternateId": "user03@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 22",
"id": "000000000000000084",
"type": "User"
},
"authenticationContext": {
"authenticationProvider": null,
"authenticationStep": 0,
"credentialProvider": null,
"credentialType": null,
"externalSessionId": "0000000000000000000000085",
"interface": null,
"issuer": null,
"rootSessionId": "0000000000000000000000086"
},
"client": {
"device": "Unknown",
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"id": null,
"ipAddress": "203.0.113.144",
"userAgent": {
"browser": "UNKNOWN",
"os": "Unknown",
"rawUserAgent": "pekko-http/1.2.0"
},
"zone": "null"
},
"debugContext": {
"debugData": {
"dtHash": "000000000000000000000000000000000000000000000000000000000000087",
"protocol": "SAML 2.0",
"requestId": "000000000000000000000000088",
"requestUri": "/api/v1/idps/1i600000000000000010",
"url": "/api/v1/idps/1i600000000000000010?"
}
},
"device": null,
"displayMessage": "Update an Identity Provider",
"eventType": "system.idp.lifecycle.update",
"legacyEventType": null,
"outcome": {
"reason": null,
"result": "SUCCESS"
},
"published": "2025-08-19T19: 49: 51.342Z",
"request": {
"ipChain": [
{
"geographicalContext": null,
"ip": "198.51.100.12",
"source": null,
"version": "V4"
},
{
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"ip": "203.0.113.144",
"source": null,
"version": "V4"
}
]
},
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"domain": "example.com",
"isProxy": false,
"isp": "example-isp"
},
"severity": "INFO",
"target": [
{
"alternateId": "user14@dw-harness.example",
"changeDetails": {
"from": {
"policySubject": {
"filter": "^$",
"matchType": "USERNAME",
"userNameTemplate": {
"template": "idpuser.email"
}
}
},
"to": {
"policySubject": {
"filter": "^.+@(?i)(?:example\\.com)$",
"matchType": "USERNAME",
"userNameTemplate": {
"template": "idpuser.email"
}
}
}
},
"detailEntry": null,
"displayName": "DW Harness 23",
"id": "00000000000000000000089",
"type": "IdentityProvider"
}
],
"transaction": {
"detail": {
"requestApiTokenId": "00000000000000000090",
"rootApiTokenId": "00000000000000000090"
},
"id": "000000000000000000000000088",
"type": "WEB"
},
"uuid": "000000000000000000000000000000000091",
"version": "0"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1098, T1199, T1556↳ also matches system.idp.lifecycle.activate, system.idp.lifecycle.create, system.idp.lifecycle.deactivate, system.idp.lifecycle.delete, system.idp.lifecycle.read_client_secret
References #
system.import.clear.unconfirmed.users.summary
#Description
Clear Unconfirmed Imported Users. Can be used for clearing unconfirmed imported users from last import result. Note that a single event is fired for clearing unconfirmed imported users instead of fire delete event on each user.
References #
system.import.complete
#Description
Import process complete.
Example System Log Event #
{
"published": 1781014987808,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000095",
"actor": {
"id": "00u00000000000000246",
"type": "User",
"alternateId": "user56@dw-harness.example",
"displayName": "DW Harness 79",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij000000000000000305",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 59",
"totalTime": "0 seconds"
}
},
"displayMessage": "Import process complete",
"gatewayContext": null,
"legacyEventType": "app.generic.import.complete",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000248",
"externalSessionId": "trs00000000000000306"
}
}
References #
system.import.complete_batch
#Description
Batch import process complete.
Example System Log Event #
{
"published": 1780928948593,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000096",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.complete_batch",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 59",
"totalTime": "1 minute and 15 seconds"
}
},
"displayMessage": "Batch import process complete",
"gatewayContext": null,
"legacyEventType": "app.generic.import.batch.complete",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.custom_object.complete
#Description
Import of custom objects completed.
Example System Log Event #
{
"published": 1781014987799,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000097",
"actor": {
"id": "00u00000000000000246",
"type": "User",
"alternateId": "user56@dw-harness.example",
"displayName": "DW Harness 79",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.custom_object.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij000000000000000305",
"detail": {}
},
"debugContext": {
"debugData": {
"deletedObjects": "0",
"addedObjects": "0",
"appname": "Example App 59",
"totalObjects": "0",
"updatedObjects": "0",
"unchangedObjects": "0"
}
},
"displayMessage": "Import of custom objects completed",
"gatewayContext": null,
"legacyEventType": "app.generic.import.summary.custom_object",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000248",
"externalSessionId": "trs00000000000000306"
}
}
References #
system.import.custom_object.create
#Description
Create custom object triggered by import process.
References #
system.import.custom_object.delete
#Description
Delete custom object triggered by import process.
References #
system.import.custom_object.update
#Description
Update custom object triggered by import process.
References #
system.import.download.complete
#Description
Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record.
Example System Log Event #
{
"published": 1780156929845,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000098",
"actor": {
"id": "00u00000000000000179",
"type": "User",
"alternateId": "user44@dw-harness.example",
"displayName": "DW Harness 59",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.download.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gij00000000000000310",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "gij00000000000000310",
"appname": "Example App 84",
"detailedmessage": "Download object phase completed."
}
},
"displayMessage": "Download object phase completed.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000183",
"externalSessionId": "trs00000000000000311"
}
}
References #
system.import.download.start
#Description
Fired at the start of the download objects phase, when the objects (users, groups, devices) to be imported are being downloaded from the system of record. This can be used to determine when an import has started, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the download objects phase, when the objects (users, groups, devices) to be imported are being downloaded from the system of record.
Example System Log Event #
{
"published": 1780156929170,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000099",
"actor": {
"id": "00u00000000000000179",
"type": "User",
"alternateId": "user44@dw-harness.example",
"displayName": "DW Harness 59",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.download.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gij00000000000000310",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "gij00000000000000310",
"appname": "Example App 84",
"detailedmessage": "Download object phase started."
}
},
"displayMessage": "Download object phase started.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000183",
"externalSessionId": "trs00000000000000311"
}
}
References #
system.import.entitlement
#Description
Emitted during the entitlement discovery process to identify entitlement schemas, excluding assignments. Tracks entitlement discovery status. In case of a NullPointerException (NPE), the outcome.result will be 'SKIPPED'. Use this event to track the status of entitlements during discovery.
References #
system.import.entitlement.mismatch
#Description
Skipping of entitlement during import of an user. This event will be emitted during import whenever a user has some entitlement associated with it that are not present in Okta. This event can be use to track the entitlement of user which were skipped during import.
References #
system.import.group.complete
#Description
Import of groups completed.
Example System Log Event #
{
"published": 1781014987802,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000100",
"actor": {
"id": "00u00000000000000246",
"type": "User",
"alternateId": "user56@dw-harness.example",
"displayName": "DW Harness 79",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.group.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij000000000000000305",
"detail": {}
},
"debugContext": {
"debugData": {
"deletedObjects": "0",
"addedObjects": "0",
"appname": "Example App 59",
"totalObjects": "0",
"updatedObjects": "0",
"unchangedObjects": "0"
}
},
"displayMessage": "Import of groups completed",
"gatewayContext": null,
"legacyEventType": "app.generic.import.summary.group",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000248",
"externalSessionId": "trs00000000000000306"
}
}
References #
system.import.group.start
#Description
Start importing groups from refreshing AppGroups.
Example System Log Event #
{
"published": 1780156929165,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000102",
"actor": {
"id": "00u00000000000000179",
"type": "User",
"alternateId": "user44@dw-harness.example",
"displayName": "DW Harness 59",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.group.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gij00000000000000310",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 84"
}
},
"displayMessage": "Start importing groups from refreshing AppGroups",
"gatewayContext": null,
"legacyEventType": "app.generic.import.import_groups",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000183",
"externalSessionId": "trs00000000000000311"
}
}
References #
system.import.group_membership.complete
#Description
Import of application group members completed.
Example System Log Event #
{
"published": 1781014987805,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000101",
"actor": {
"id": "00u00000000000000246",
"type": "User",
"alternateId": "user56@dw-harness.example",
"displayName": "DW Harness 79",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.group_membership.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij000000000000000305",
"detail": {}
},
"debugContext": {
"debugData": {
"deletedObjects": "0",
"addedObjects": "0",
"appname": "Example App 59",
"totalObjects": "0",
"updatedObjects": "0",
"unchangedObjects": "0"
}
},
"displayMessage": "Import of application group members completed",
"gatewayContext": null,
"legacyEventType": "app.generic.import.summary.group_membership",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000248",
"externalSessionId": "trs00000000000000306"
}
}
References #
system.import.implicit_deletion.complete
#Description
Fired upon completion of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects.
Example System Log Event #
{
"published": 1780928918178,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000103",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.implicit_deletion.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "Deletion processing phase completed."
}
},
"displayMessage": "Deletion processing phase completed.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.implicit_deletion.start
#Description
Fired at the start of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the implicit deletion phase, when Okta checks for the deletion of users, groups, and custom objects.
Example System Log Event #
{
"published": 1780928913927,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000104",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.implicit_deletion.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "Deletion processing phase started."
}
},
"displayMessage": "Deletion processing phase started.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.import_profile
#Description
Import user profile triggered by import process.
References #
system.import.import_provisioning_info
#Description
Import provisioning info triggered by import process.
Example System Log Event #
{
"published": 1781014987343,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000105",
"actor": {
"id": "00u00000000000000246",
"type": "User",
"alternateId": "user56@dw-harness.example",
"displayName": "DW Harness 79",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.import_provisioning_info",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij000000000000000305",
"detail": {}
},
"debugContext": {
"debugData": {
"appname": "Example App 59"
}
},
"displayMessage": "Import provisioning info triggered by import process",
"gatewayContext": null,
"legacyEventType": "app.generic.import.provisioning_data",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000248",
"externalSessionId": "trs00000000000000306"
}
}
References #
system.import.membership_processing.complete
#Description
Fired upon completion of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from.
Example System Log Event #
{
"published": 1780928918496,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000106",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.membership_processing.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "Membership processing phase completed."
}
},
"displayMessage": "Membership processing phase completed.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.membership_processing.start
#Description
Fired at the start of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the membership processing phase, when Okta checks which groups users being imported into Okta should be added to/removed from.
Example System Log Event #
{
"published": 1780928918182,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000107",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.membership_processing.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "Membership processing phase started."
}
},
"displayMessage": "Membership processing phase started.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.object_creation.complete
#Description
Fired upon completion of the object creation phase, when the first batch of objects is created/updated. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the object creation phase, when the first batch of objects is created/updated.
Example System Log Event #
{
"published": 1780928913922,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000108",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.object_creation.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "Object creation phase completed."
}
},
"displayMessage": "Object creation phase completed.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.object_creation.start
#Description
Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the completion of the download objects phase, when the objects (users, groups, devices) to be imported have been downloaded from the system of record.
Example System Log Event #
{
"published": 1780156929847,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000109",
"actor": {
"id": "00u00000000000000179",
"type": "User",
"alternateId": "user44@dw-harness.example",
"displayName": "DW Harness 59",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.object_creation.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gij00000000000000310",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "gij00000000000000310",
"appname": "Example App 84",
"detailedmessage": "Object creation phase started."
}
},
"displayMessage": "Object creation phase started.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000183",
"externalSessionId": "trs00000000000000311"
}
}
References #
system.import.roadblock
#Description
Import roadblock triggered due to exceeded threshold.
References #
system.import.roadblock.reschedule_and_resume
#Description
The affected import from AppInstance has been rescheduled. All other imports will resume.
References #
system.import.roadblock.resume
#Description
The affected import from AppInstance has been canceled. All other imports will resume.
References #
system.import.roadblock.updated
#Description
Fired when an import roadblock (aka, Import Safeguard) has been updated. This event can be used to identify when an admin updated the Max Import Unassignment roadblock setting, and what the setting was updated to. This event includes details on what the roadblock was updated to and who made the change.
References #
system.import.schedule
#Description
Import process was scheduled. This event can be used to track when import jobs were triggered, which helps with audit trails. This event may also be useful when troubleshooting a failed import, as it indicates the time at which the process was first triggered and the user or application that invoked the import. Import is a multi-stage process which may import users, groups, and group memberships. Each stage has corresponding events in the system log. For example 'system.import.user.start' indicates beginning of user import process.
Example System Log Event #
{
"published": 1780928872549,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000110",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.20",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": [
{
"ip": "192.0.2.20",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.schedule",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000058",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000058",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
"origin": "https://app.example.com App app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000004",
"url": "00000000000000000000000000000000000000000000000000004?"
}
},
"displayMessage": "Import process was scheduled.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "10200000000000000308"
}
}
References #
system.import.session.cancelled
#Description
Import session for identity source canceled. This event appears when an import session is canceled and not available for further activity. Only sessions that are in CREATED or IN_PROGRESS status can be canceled. Previously uploaded entities are deleted from a canceled identity import session.
References #
system.import.session.created
#Description
Create new import session for identity source. This event appears when a new import session is created for a given identity source to bulk upload entities. This event includes information on when the session was created.
References #
system.import.session.expired
#Description
Import session for identity source expired. This event appears when a session in CREATED or IN_PROGRESS status is marked as EXPIRED after 24 hours of inactivity. Expired sessions can no longer be used for import operations.
References #
system.import.session.triggered
#Description
Triggered import session for identity source. This event appears when import session was triggered. It's used to make changes in Okta to insert, update, or delete the entities that are submitted by the identity source.
References #
system.import.start
#Description
import started.
Example System Log Event #
{
"published": 1782502956369,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000111",
"actor": {
"id": "00u00000000000000117",
"type": "User",
"alternateId": "user29@dw-harness.example",
"displayName": "DW Harness 44",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "prj00000000000000119",
"detail": {
"rootApiTokenId": "00t00000000000000120"
}
},
"debugContext": {
"debugData": {
"jobId": "prj00000000000000119",
"importType": "Incremental",
"appname": "Example App 59",
"importLastToken": "2026-06-08T07:27:53.237Z",
"importTrigger": "Manual action"
}
},
"displayMessage": "import started",
"gatewayContext": null,
"legacyEventType": "app.generic.import.started",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000121",
"externalSessionId": "trs00000000000000122"
}
}
References #
system.import.user.complete
#Description
Import of user completed.
Example System Log Event #
{
"published": 1780156929921,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000112",
"actor": {
"id": "00u00000000000000179",
"type": "User",
"alternateId": "user44@dw-harness.example",
"displayName": "DW Harness 59",
"detailEntry": null
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000165",
"type": "AppInstance",
"alternateId": "user40@dw-harness.example",
"displayName": "DW Harness 47",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "gij00000000000000310",
"detail": {}
},
"debugContext": {
"debugData": {
"deletedObjects": "0",
"addedObjects": "0",
"appname": "Example App 84",
"totalObjects": "0",
"updatedObjects": "0",
"unchangedObjects": "0"
}
},
"displayMessage": "Import of Example App 61 completed",
"gatewayContext": null,
"legacyEventType": "app.generic.import.summary.user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000183",
"externalSessionId": "trs00000000000000311"
}
}
References #
system.import.user.create
#Description
Create user triggered by import process.
Example System Log Event #
{
"published": 1780928898079,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000113",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000312",
"type": "AppUser",
"alternateId": "user69@dw-harness.example",
"displayName": "DW Harness 106",
"detailEntry": null
},
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user.create",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Create Example App 61 triggered by import process",
"gatewayContext": null,
"legacyEventType": "app.generic.import.details.add_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.user.delete
#Description
Delete user triggered by import process.
Example System Log Event #
{
"published": 1780928917042,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000114",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000313",
"type": "AppUser",
"alternateId": "user70@dw-harness.example",
"displayName": "DW Harness 107",
"detailEntry": null
},
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user.delete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Delete Example App 61 triggered by import process",
"gatewayContext": null,
"legacyEventType": "app.generic.import.details.delete_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.user.match
#Description
Assign user triggered by import process with callback. This event can be used to alter the matching result for a given imported user. This event is fired when the matching result is altered by the synchronous callback.
References #
system.import.user.unsuspend_after_confirm
#system.import.user.update
#Description
Update user triggered by import process.
Example System Log Event #
{
"published": 1780928893392,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000118",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0ua00000000000000315",
"type": "AppUser",
"alternateId": "user71@dw-harness.example",
"displayName": "DW Harness 108",
"detailEntry": null
},
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {}
},
"displayMessage": "Update Example App 61 triggered by import process",
"gatewayContext": null,
"legacyEventType": "app.generic.import.details.update_user",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.user.update_user_lifecycle_from_master
#Description
Update user status triggered by import process.
References #
system.import.user_csv.complete
#Description
Bulk Import users from CSV is completed. Informs when bulk user import from CSV has been completed. This event is logged when bulk user import from CSV has completed with the outcome as success or failure. When fired, this event also contains debug context about the number of users added/updated/unchanged or with errors.
References #
system.import.user_csv.start
#Description
Bulk Import of users from CSV is started. Informs when bulk import of users from CSV has been attempted to be uploaded. This event is logged when bulk user import from CSV has started and is a precursor to user.lifecycle.create; user.lifecycle.activate events.
References #
system.import.user_match.confirm
#Description
Import user matching assignment confirmed. This event can be used to track when the confirmation of user matching assignments was triggered on the Import page, which helps with audit trails. This event may also be useful when troubleshooting incorrect user matches. After users are imported from the app, they're matched and assigned with existing Okta users on the basis of Name, Username, and Email. The assignment confirmation is a manual step, needing admin intervention.
Example System Log Event #
{
"published": 1782501745846,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000115",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user_match.confirm",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000059",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000059",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
"origin": "https://app.example.com App app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000004",
"url": "00000000000000000000000000000000000000000000000000000000000004?"
}
},
"displayMessage": "Import Example App 61 matching assignment confirmed.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000314",
"externalSessionId": "10200000000000000314"
}
}
References #
system.import.user_match.unignore
#Description
Assignment was unignored. This event indicates that a user match, which was previously marked to be ignored during imports, has been reactivated for consideration. It's important for tracking changes in user matching policies and decisions during the import process. This event can be of critical importance for auditing purposes, especially when investigating why certain user accounts were matched or updated after being ignored in previous imports. It helps maintain the accuracy and integrity of user data by ensuring that valid matches are not permanently overlooked.
References #
system.import.user_match.update
#Description
Assignment was modified. This event can be used to track when an assignment was modified. This may also be useful when troubleshooting incorrect user assignments. After users are imported from the app, they're matched and assigned with existing Okta users on the basis of Name, Username, and Email. Assignments can be modified by the admin through a manual intervention.
References #
system.import.user_matching.complete
#Description
Fired upon completion of the user matching phase, when Okta attempts to match imported users to existing Okta users. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired upon completion of the user matching phase, when Okta attempts to match imported users to existing Okta users.
Example System Log Event #
{
"published": 1780928951337,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000116",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user_matching.complete",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "User matching phase completed."
}
},
"displayMessage": "User matching phase completed.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.import.user_matching.start
#Description
Fired at the start of the user matching phase, when Okta attempts to match imported users to existing Okta users. This can be used to determine the progress of an import, as well as to monitor to trigger processes that should run concurrently with the import. Fired at the start of the user matching phase, when Okta attempts to match imported users to existing Okta users.
Example System Log Event #
{
"published": 1780928918504,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000117",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": null,
"zone": null,
"device": null,
"id": null,
"ipAddress": null,
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000154",
"type": "AppInstance",
"alternateId": "user38@dw-harness.example",
"displayName": "DW Harness 55",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": []
},
"version": "0",
"severity": "INFO",
"eventType": "system.import.user_matching.start",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "JOB",
"id": "ij100000000000000307",
"detail": {}
},
"debugContext": {
"debugData": {
"jobId": "ij100000000000000307",
"appname": "Example App 59",
"detailedmessage": "User matching phase started."
}
},
"displayMessage": "User matching phase started.",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000308",
"externalSessionId": "trs00000000000000309"
}
}
References #
system.iwa_agentless.auth_after_redirect
#Description
Fired after redirection from Agentless DSSO failure. This can be used to track the start of a subsequent authentication request after Agentless DSSO fails. This can also be used for end-to-end tracking of an ADSSO failure to the subsequent authentication it is redirected to by searching for the common stateTokenHash. When fired, this event contains the stateTokenHash which will be common before and after the redirection occurs.
References #
system.iwa_agentless.redirect
#Description
Fired when an Agentless DSSO authentication request is redirected to an onprem IWA authentication or the default login page. This can be used to identify when an agentless authentication request resulted in a redirect to an onprem IWA or default login page. This can also be used to identify the potential cause of the redirect. When fired, this event identifies the cause of the redirection. When a custom error page is defined, a redirect event is not always generated when a redirection occurs.
References #
system.iwa_agentless.user.not_found
#Description
Fired when a user could not be found during Agentless DSSO authentication, resulting in an authentication failure. This can be used to identify when an agentless authentication request resulted in a failure. The failure could be due to the user not being found in Okta, Okta not being able to connect to AD, or the user not being found in AD. This can also be used to identify the potential cause of the failure. When fired, this event contains information about the potential cause of the failure.
References #
system.iwa_agentless_kerberos.update
#Description
Fires when a Kerberos realm settings is updated by an admin. This event fires when the update is successful or fails. This can be used to audit Kerberos realm setting, and troubleshoot why Kerberos authentication failed. When fired, this event indicates whether Kerberos realm setting update has been successful or failed. This event also indicates the initiator of the event and the current setting for Kerberos Realm. Related events: none, all debugging context is included in this event.
References #
system.ldapi.admin_limit_exceeded
#Description
This event indicates that an administrative limit was exceeded when processing an LDAP interface operation. It can be used to audit and debug failures caused by exceeding an administrative limit. This event may occur periodically when an LDAP operation results in a large number of corresponding actions in the Okta directory. These errors are often temporary and will subside when Okta has processed the actions. Contact Okta support if you see such errors consistently over the course of a day or more.
References #
system.ldapi.bind
#Description
Fired when a user performs a BIND to LDAP Interface. Can be used to identify when a user attempted to perform an LDAP authentication for audit or debugging purposes. The firing of this event is subject to LDAPi event filtering rules and is only logged when a failure is returned for the given LDAP operation.
References #
system.ldapi.search
#Description
Fired when a user performs a SEARCH to LDAP Interface. Can be used to identify when a user attempted to perform a search on LDAP Interface for audit or debugging purposes. The firing of this event is subject to LDAPi event filtering rules and is only logged when a failure is returned for the given LDAP operation.
References #
system.ldapi.unbind
#Description
Fired when a user performs an UNBIND to LDAP Interface. Can be used to identify when a user attempted to end an LDAP Interface session for audit or debugging purposes. The firing of this event is subject to LDAPi event filtering rules and is only logged when a failure is returned for the given LDAP operation.
References #
system.log_stream.lifecycle.activate
#Description
Log stream activated. This event can be used to track and audit when a user activates a log stream. When fired, this event indicates that a user activated a log stream configuration.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000092",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Activate a Log Stream",
"eventType": "system.log_stream.lifecycle.activate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:55:05.656Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/logStreams/0oa00000000000000020/lifecycle/activate",
"url": "/api/v1/logStreams/0oa00000000000000020/lifecycle/activate?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "LogStream",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
system.log_stream.lifecycle.create
#Description
Log stream created. This event can be used to track and audit when a user creates a log stream. When fired, this event indicates that a user created a log stream configuration.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000093",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Create a Log Stream",
"eventType": "system.log_stream.lifecycle.create",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:55:05.398Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/logStreams",
"url": "/api/v1/logStreams?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "LogStream",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
system.log_stream.lifecycle.deactivate
#Description
Log stream deactivated. This event can be used to track and audit when a user or Okta deactivates a log stream. When fired, this event indicates that a user or Okta deactivated a log stream configuration.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000094",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Deactivate a Log Stream",
"eventType": "system.log_stream.lifecycle.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:55:05.519Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/logStreams/0oa00000000000000020/lifecycle/deactivate",
"url": "/api/v1/logStreams/0oa00000000000000020/lifecycle/deactivate?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "LogStream",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
system.log_stream.lifecycle.delete
#Description
Log stream deleted. This event can be used to track and audit when a user deletes a log stream. When fired, this event indicates that a user deleted a log stream configuration.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000095",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "Delete a Log Stream",
"eventType": "system.log_stream.lifecycle.delete",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-02T18:55:06.335Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/logStreams/0oa00000000000000020",
"url": "/api/v1/logStreams/0oa00000000000000020?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "LogStream",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
}
]
}
References #
system.log_stream.lifecycle.update
#Description
Log stream updated. This event can be used to track and audit when a user updates a log stream. When fired, this event indicates that a user updated a log stream configuration.
Example System Log Event #
{
"actor": {
"id": "00u00000000000000002",
"type": "User",
"alternateId": "user02@dw-harness.example",
"displayName": "DW Harness 02",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000036",
"externalSessionId": "0000000000000000000000036"
},
"displayMessage": "Update a Log Stream",
"eventType": "system.log_stream.lifecycle.update",
"outcome": {
"result": "SUCCESS",
"reason": null
},
"published": "2026-07-24T03:47:51.776Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000075",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"requestUri": "/api/v1/logStreams/0oa00000000000000062",
"url": "/api/v1/logStreams/0oa00000000000000062?"
}
},
"gatewayContext": null,
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000075",
"detail": {
"rootApiTokenId": "00T00000000000000004",
"requestApiTokenId": "00T00000000000000004"
}
},
"uuid": "00000000-0000-0000-0000-000000000086",
"version": "0",
"request": {
"ipChain": [
{
"ip": "198.51.100.2",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "0oa00000000000000062",
"type": "LogStream",
"alternateId": "user12@dw-harness.example",
"displayName": "DW Harness 22",
"detailEntry": null
}
]
}
References #
system.mfa.factor.activate
#Description
Activate a new authentication factor. Can be used to identify when an admin has enabled a new factor for authentication. When fired the event will contain details of which factor is enabled.
Example System Log Event #
{
"published": 1784656596937,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000119",
"actor": {
"id": "00u00000000000000026",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000027"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00o00000000000000316",
"type": "MFA Factor",
"alternateId": null,
"displayName": null,
"detailEntry": {
"factorType": "FIDO_WEBAUTHN"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.mfa.factor.activate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000040",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000040",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000003",
"url": "00000000000000000000000000000000000000000000000000000000000003?"
}
},
"displayMessage": "MFA factor enabled",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Device",
"id": "bhv00000000000000031",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000032",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000033",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000034",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000035",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000036",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000037",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000038",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000281",
"externalSessionId": "10200000000000000281"
}
}
References #
system.mfa.factor.deactivate
#Description
Deactivate MFA factor. Can be used to identify when an admin has disabled a factor for MFA. When fired the event will contain details of which factor is disabled.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType (panther rule field) | in | user.account.reset_password | 1 rule | panther |
eventType (panther rule field) | in | user.mfa.factor.update | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1098, T1556↳ also matches system.api_token.create, system.api_token.revoke Panther #
T1199
References #
system.oauth2.token.request_outside_allowed_range
#Description
Request with valid bearer tokens made from outside the allowed network zone. Use to detect when a bearer token comes from an IP address that's outside of the specified allowed zone. Fired when a bearer token comes from an IP address that's outside of the specified allowed zone of the client.
References #
system.operation.concurrency_limit.violation
#Description
Operation concurrency limit violation. This can be used to track if there are too many concurrent operations of the given type. The operation type information is available in debugData. When fired, this event contains information about the operation such as its actor, type, scope and threshold details. OperationRateLimitType in debugData will indicate the category to which the concurrency limit is being applied (e.g. web_request), OperationRateLimitSubtype defines specific subtypes (e.g. ssws_token) and OperationRateLimitScope will indicate the scope of the rate limit (e.g. token).
Example System Log Event #
{
"published": 1785203175533,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000120",
"actor": {
"id": "0oa00000000000000317",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 109",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "unknown",
"os": "unknown",
"browser": "unknown"
},
"zone": "null",
"device": "unknown",
"id": null,
"ipAddress": "192.0.2.32",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0oa00000000000000317",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 109",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": [
{
"ip": "192.0.2.32",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "system.operation.concurrency_limit.violation",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000060",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000019",
"requestApiTokenId": "0000000000000000000000000000000000000000000019",
"requestApiTokenClientId": "0oa00000000000000317"
}
},
"debugContext": {
"debugData": {
"operationRateLimitSubtype": "oauth_client",
"operationRateLimitScopeType": "application",
"requestId": "00000000000000000000000000000060",
"operationRateLimitThreshold": "37",
"requestUri": "0000000000000000000000000000000000000000000020",
"operationRateLimitType": "web_request",
"url": "0000000000000000000000000000000000000000000020?limit=500"
}
},
"displayMessage": "This application has made too many concurrent requests",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000318",
"externalSessionId": "trs00000000000000318"
}
}
References #
system.operation.rate_limit.violation
#Description
Operation rate limit violation. This can be used to track if an operation is exceeding its rate limit. When fired, this event contains information about the operation such as actor, type, scope and threshold details. OperationRateLimitType in debugData will indicate the category to which the rate limit is being applied (e.g. authenticator_otp_verification), OperationRateLimitSubtype defines specific subtypes (e.g. Email Factor for authenticator_otp_verification) and OperationRateLimitScope will indicate the scope of the rate limit (e.g. user or org level). Formerly, this event was used to indicate blocked SMS/Call transactions, please see system.sms.send*/system.voice.send* for blocked transactions.
Example System Log Event #
{
"published": 1785225661392,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000121",
"actor": {
"id": "00u00000000000000139",
"type": "User",
"alternateId": "user33@dw-harness.example",
"displayName": "DW Harness 51",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Go-http-client/2.0",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "192.0.2.34",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "00000000-0000-0000-0000-000000000122",
"type": "Bucket UUID",
"alternateId": null,
"displayName": null,
"detailEntry": null
},
{
"id": "00t00000000000000319",
"type": "Token",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 110",
"detailEntry": null
}
],
"outcome": null,
"request": {
"ipChain": [
{
"ip": "192.0.2.34",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "system.operation.rate_limit.violation",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000061",
"detail": {
"rootApiTokenId": "00t00000000000000319",
"requestApiTokenId": "00t00000000000000319"
}
},
"debugContext": {
"debugData": {
"operationRateLimitSubtype": "ssws_token",
"operationRateLimitTimeUnit": "MINUTES",
"operationRateLimitScopeType": "token",
"operationRateLimitSecondsToReset": "57",
"requestId": "00000000000000000000000000000061",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000031",
"operationRateLimitThreshold": "50",
"operationRateLimitTimeSpan": "1",
"requestUri": "fr100000000000000320",
"operationRateLimitType": "web_request",
"url": "fr100000000000000320?limit=200"
}
},
"displayMessage": "This API token has made too many requests",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000321",
"externalSessionId": "trs00000000000000321"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1110, T1498↳ also matches system.client.concurrency_rate_limit.violation, system.client.rate_limit.violation, system.org.rate_limit.violation
References #
system.operation.rate_limit.warning
#Description
Operation rate limit warning. This can be used to track if an operation is approaching its rate limit. When fired, this event contains information about the operation such as actor, type, scope and threshold details. OperationRateLimitType in debugData will indicate the category to which the rate limit is being applied (e.g. authenticator_otp_verification), OperationRateLimitSubtype defines specific subtypes (e.g. Email, SMS or Voice call for authenticator_otp_verification type) and OperationRateLimitScope will indicate the scope of the rate limit (e.g. user or org level).
References #
system.org.captcha.activate
#Description
Enable org-wide captcha support. Indicates when org-wide captcha support is enabled, for which pages and using which captcha instance. This event is fired when org admin enables org-wide captcha for any supported pages.
References #
system.org.captcha.deactivate
#Description
Disable org-wide captcha support. Indicates when org-wide captcha support is disabled. This event is fired when org admin disables org-wide captcha support for all pages.
References #
system.org.rate_limit.burst
#Description
Fired when burst rate limit capacity is activated. This can be used to identify when an API in the Org exceeds standard rate limits and the frequency with which the activities occur. This event is fired after a corresponding warning event. If usage continues on this API the risk is hitting a rate limit violation which will fire a corresponding violation event. The event contains a burst rate limit threshold which informs how much capacity is remaining before a violation occurs.
Example System Log Event #
{
"published": 1783545338762,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000123",
"actor": {
"id": "0oa00000000000000123",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 46",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "local-v2-sdk/0.0.0 golang/go1.26.2 linux/arm64 okta-terraform/6.12.0",
"os": "Linux",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.25",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0000000000000000002",
"type": "URL Pattern",
"alternateId": null,
"displayName": null,
"detailEntry": null
},
{
"id": "00000000-0000-0000-0000-000000000124",
"type": "Bucket Uuid",
"alternateId": null,
"displayName": null,
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.25",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.org.rate_limit.burst",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000062",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000021",
"requestApiTokenId": "0000000000000000000000000000000000000000000021",
"requestApiTokenClientId": "0oa00000000000000123"
}
},
"debugContext": {
"debugData": {
"burstRateLimitUrlPattern": "/api/v1/groups/{id}",
"requestId": "00000000000000000000000000000062",
"burstRateLimitBucketUuid": "00000000-0000-0000-0000-000000000124",
"burstRateLimitExpirationDate": "",
"burstThreshold": "5000",
"baseThreshold": "1000",
"timeSpan": "1",
"requestUri": "je900000000000000322",
"userId": "",
"url": "je900000000000000322?",
"timeUnit": "MINUTES"
}
},
"displayMessage": "Burst rate limit activated",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000323",
"externalSessionId": "trs00000000000000323"
}
}
References #
system.org.rate_limit.expiration.warning
#Description
Rate limit approaching expiration date.
References #
system.org.rate_limit.violation
#Description
Rate limit violation.
Example System Log Event #
{
"published": 1781435035381,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000125",
"actor": {
"id": "0oa00000000000000112",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 42",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "okta-sdk-python/2.9.13 python/3.12.13 Linux/5.10.253-286.1015.amzn2.x86_64",
"os": "Linux",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.16",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "0000000000004",
"type": "URL Pattern",
"alternateId": null,
"displayName": null,
"detailEntry": null
},
{
"id": "00000000-0000-0000-0000-000000000126",
"type": "Bucket Uuid",
"alternateId": null,
"displayName": null,
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.16",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "system.org.rate_limit.violation",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000063",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000022",
"requestApiTokenId": "0000000000000000000000000000000000000000000022",
"requestApiTokenClientId": "0oa00000000000000112"
}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000063",
"rateLimitBucketUuid": "00000000-0000-0000-0000-000000000126",
"rateLimitSecondsToReset": "17",
"threshold": "600",
"timeSpan": "1",
"rateLimitScopeType": "ORG",
"requestUri": "00000000000000000000000000000000000000012",
"url": "00000000000000000000000000000000000000012?",
"timeUnit": "MINUTES"
}
},
"displayMessage": "Rate limit violation",
"gatewayContext": null,
"legacyEventType": "core.framework.ratelimit.exceeded",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000324",
"externalSessionId": "trs00000000000000324"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1498, T1499, T1499.002, T1499.003↳ also matches system.org.rate_limit.warning Panther #
T1110, T1498↳ also matches system.client.concurrency_rate_limit.violation, system.client.rate_limit.violation, system.operation.rate_limit.violation
References #
system.org.rate_limit.warning
#Description
Rate limit warning.
Example System Log Event #
{
"published": 1780264594853,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000127",
"actor": {
"id": "0oa00000000000000325",
"type": "PublicClientAppEntity",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 111",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "graphrest-python",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "192.0.2.33",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "000000000002",
"type": "URL Pattern",
"alternateId": null,
"displayName": null,
"detailEntry": null
},
{
"id": "00000000-0000-0000-0000-000000000122",
"type": "Bucket Uuid",
"alternateId": null,
"displayName": null,
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.33",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "system.org.rate_limit.warning",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000064",
"detail": {
"rootApiTokenId": "0000000000000000000000000000000000000000000023",
"requestApiTokenId": "0000000000000000000000000000000000000000000023",
"requestApiTokenClientId": "0oa00000000000000325"
}
},
"debugContext": {
"debugData": {
"requestId": "00000000000000000000000000000064",
"warningPercent": "90",
"rateLimitBucketUuid": "00000000-0000-0000-0000-000000000122",
"rateLimitSecondsToReset": "33",
"threshold": "100",
"timeSpan": "1",
"rateLimitScopeType": "ORG",
"requestUri": "iq300000000000000326",
"url": "iq300000000000000326?limit=500",
"timeUnit": "MINUTES"
}
},
"displayMessage": "Rate limit warning",
"gatewayContext": null,
"legacyEventType": "core.framework.ratelimit.warning",
"resourceDetails": null,
"securityContext": {
"asNumber": null,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": null
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "trs00000000000000327",
"externalSessionId": "trs00000000000000327"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1498, T1499, T1499.002, T1499.003↳ also matches system.org.rate_limit.violation
References #
system.push.send_factor_verify_push
#Description
Fired when a Push notification is sent to a device. Used to notify admins when a push was sent to a user for verification. Note that this event is fired whenever a Push is sent.
Example System Log Event #
{
"actor": {
"alternateId": "user15@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 24",
"id": "0000000000000000096",
"type": "User"
},
"authenticationContext": {
"authenticationProvider": null,
"authenticationStep": 0,
"credentialProvider": null,
"credentialType": null,
"externalSessionId": "0000000000000000000000097",
"interface": null,
"issuer": null,
"rootSessionId": "0000000000000000000000097"
},
"client": {
"device": "Computer",
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"id": null,
"ipAddress": "198.51.100.13",
"userAgent": {
"browser": "CHROME",
"os": "Windows 10",
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
},
"zone": "null"
},
"debugContext": {
"debugData": {
"authnRequestId": "00000000000000000000000000000005",
"behaviors": "{New Geo-Location=POSITIVE, New Device=POSITIVE, New IP=POSITIVE, New State=POSITIVE, New Country=NEGATIVE, Velocity=NEGATIVE, New City=NEGATIVE}",
"deviceCategory": "SmartPhone_IPhone",
"devicePlatform": "IOS",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000098",
"requestId": "00000000000000000000000000000099",
"requestUri": "/idp/idx/challenge",
"risk": "{reasons=Anomalous Device, level=MEDIUM}",
"threatSuspected": "false",
"url": "/idp/idx/challenge?"
}
},
"device": null,
"displayMessage": "A push was sent to a user for verification",
"eventType": "system.push.send_factor_verify_push",
"legacyEventType": null,
"outcome": {
"reason": null,
"result": "SUCCESS"
},
"published": "2024-11-18T22:34:55.603Z",
"request": {
"ipChain": [
{
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"ip": "198.51.100.13",
"source": null,
"version": "V4"
}
]
},
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"domain": "example.com",
"isProxy": false,
"isp": "example-isp"
},
"severity": "INFO",
"target": [
{
"alternateId": "user15@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 24",
"id": "0000000000000000096",
"type": "User"
}
],
"transaction": {
"detail": {},
"id": "00000000000000000000000000000099",
"type": "WEB"
},
"uuid": "00000000-0000-0000-0000-000000000015",
"version": "0"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
debugContext.debugData.factor (splunk rule field) | eq | okta_verify_push | 2 rules | splunk |
eventType (splunk rule field) | eq | system.push.send_factor_verify_push | 2 rules | splunk |
eventType (splunk rule field) | eq | user.authentication.auth_via_mfa | 1 rule | splunk |
okta::eventType (kusto rule field) | eq | user.authentication.auth_via_mfa | 1 rule | kusto |
okta::eventType (kusto rule field) | eq | user.mfa.okta_verify.deny_push | 1 rule | kusto |
ratio (splunk rule field) | lt | 0.5 | 1 rule | splunk |
security_result.detection_fields["factor"] (Chronicle) | eq | OKTA_VERIFY_PUSH | 1 rule | chronicle |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1110T1621Kusto #
T1621YARA-L #
T1110T1621
References #
system.rate_limit.configuration.update
#Description
Rate limit configuration update. This can be used to trace the change that an org admin updates rate limit configuration. This event is triggered when an admin updates rate limit related settings in the admin portal, including but not limited to:1. update client rate limit enforcement mode2. enable or disable rate limit notification3. update the warning threshold of rate limit notification4. update rate limit percentage of API token.
References #
system.self_service.configuration.update
#Description
Self-service for apps configuration updated. Identify changes to self-service application request settings which may allow a user to request to add an application to their end user dashboard. Self-service application requests are different than Okta Identity Governance (OIG) Access requests. See events beginning with access.request for events relevant to OIG Access requests.
Example System Log Event #
{
"published": 1782836082885,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000128",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "00o00000000000000328",
"type": "Org",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 112",
"detailEntry": null,
"changeDetails": {
"from": {
"selfServiceForPersonalApps": true
},
"to": {
"selfServiceForPersonalApps": false
}
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "system.self_service.configuration.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000065",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000065",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
"origin": "https://app.example.com App app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "000000000000000000000000000000000000000000003",
"url": "000000000000000000000000000000000000000000003?"
}
},
"displayMessage": "Self Service configuration updated",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000329",
"externalSessionId": "10200000000000000329"
}
}
References #
system.sms.receive_status
#Description
Fired when receiving a status update on SMS message from provider. This event can be used by Org Admins to identify users that are/aren't getting one-time passcodes delivered successfully via SMS, provider status can be obtained from status field in debug data. For any system.sms.send_* event, there should be exactly one of this event.
References #
system.sms.send_account_unlock_message
#Description
Send self-service account unlock SMS message. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004↳ also matches system.email.account_unlock.sent_message, system.email.password_reset.sent_message, system.sms.send_password_reset_message, system.voice.send_account_unlock_call, system.voice.send_password_reset_call
References #
system.sms.send_factor_verify_message
#Description
Send second factor auth SMS. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
References #
system.sms.send_okta_push_verify_message
#Description
Send activate Okta Verify Push for mobile SMS. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
References #
system.sms.send_password_reset_message
#Description
Send self-service password reset SMS message. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004↳ also matches system.email.account_unlock.sent_message, system.email.password_reset.sent_message, system.sms.send_account_unlock_message, system.voice.send_account_unlock_call, system.voice.send_password_reset_call
References #
system.sms.send_phone_verification_message
#Description
Send phone verification SMS message. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
References #
system.theme.update
#Description
This event is fired when the theme resource is updated. Developer and org admins can use this event to identify when and how the theme resource was updated. Event details can be used to identify changes made to theme assets including updates to theme hex codes, logo, background image, and favicon. This event also tracks which combination of theme assets was applied to end users pages such as the sign-in page, error pages, and email templates.
References #
system.voice.receive_status
#Description
Fired when receiving a status update on voice call from provider. This event can be used by Org Admins to identify users that are/aren't getting one-time passcodes delivered successfully via voice call, provider status can be obtained from status field in debug data. For any system.voice.send_* event, there should be exactly one of this event.
References #
system.voice.send_account_unlock_call
#Description
Send self-service account unlock call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004↳ also matches system.email.account_unlock.sent_message, system.email.password_reset.sent_message, system.sms.send_account_unlock_message, system.sms.send_password_reset_message, system.voice.send_password_reset_call
References #
system.voice.send_mfa_challenge_call
#Description
Send second factor auth call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
References #
system.voice.send_password_reset_call
#Description
Send self-service password reset call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004↳ also matches system.email.account_unlock.sent_message, system.email.password_reset.sent_message, system.sms.send_account_unlock_message, system.sms.send_password_reset_message, system.voice.send_account_unlock_call
References #
system.voice.send_phone_verification_call
#Description
Send phone verification call. As of the 2022.06.0 release this event is also used to identify transactions blocked by Okta, which is indicated by a "deny" outcome. Previously, the system.operation.rate_limit.violation was used to identify blocked transactions. Additionally, the method of generating the MobilePhone ID in the event has changed for Okta Classic. It has not changed for Okta Identity Engine.
References #
system.well_known_uri.update
#Description
The well-known URI was updated. Identify the previous and current versions of a well-known URI for a custom brand, such as a assetlinks.json. The brand id and specific well-known URI are available in the target resource.
References #
system.identity_sources.bulk_device_delete
#Description
Upload bulk devices delete data. Loads bulk device data into an Identity Source Session for deletion in Okta for an identity source. This event can be used to track the deletion of device profiles in Okta from the custom identity source.
References #
system.identity_sources.bulk_device_upsert
#Description
Upload bulk devices upsert data. Loads bulk device data into an Identity Source Session for inserting or updating device profiles in Okta for an identity source. This event can be used to track the insertions and updates of device profiles in Okta from the custom identity source.