Overview

The Okta integration polls the Okta System Log API and ingests events covering:

  • Successful and failed logins, including MFA challenges
  • Password changes, account lockouts, and session termination
  • User, group, and application lifecycle changes
  • Admin console activity and policy modifications

Prerequisites

  • An Okta org with Super Admin or a custom admin role that includes the okta.logs.read permission.
  • The fully qualified Okta domain (for example, yourorg.okta.com or yourorg.oktapreview.com).

Step 1: Create an API token in Okta

  1. Sign in to the Okta Admin Console.
  2. Navigate to Security → API → Tokens.
  3. Click Create token.
  4. Give the token a descriptive name such as atatus-siem.
  5. Copy the generated token value immediately — Okta only shows it once.

Note: API tokens inherit the permissions of the user that creates them. Create the token from a service account that has only the read permissions Atatus needs, not from a personal admin account.


Step 2: Connect Okta in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Okta card and click Connect.
  3. Fill in the form:
Field Description Example
Okta API Token The token created in Step 1. 00aB...xyz
Okta Domain Your Okta tenant domain, without https://. yourorg.okta.com
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The Okta card on the Integrations tab shows Configured.
  • Within one poll cycle, events appear in Security → Cloud SIEM → Audit Logs → Events with the source okta.