Overview
The OneLogin integration uses the OneLogin Events API to ingest:
- User sign-in attempts and MFA outcomes
- App provisioning, role assignments, and access requests
- Policy and configuration changes
- Admin actions in the OneLogin portal
Prerequisites
- A OneLogin account with Account Owner or Administrator role.
- The region your OneLogin account is hosted in (
usoreu).
Step 1: Create an API credential in OneLogin
- Sign in to the OneLogin Admin portal.
- Go to Developers → API Credentials.
- Click New Credential.
- Name it
atatus-siemand choose the scope Read all (sufficient for log collection). - Click Save, then copy both the Client ID and Client Secret that are displayed.
Note: The Client Secret is shown only at creation. Store it securely before leaving the page.
Step 2: Connect OneLogin in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the OneLogin card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Client ID | The Client ID generated in Step 1. | 1234abcd... |
| Client Secret | The matching Client Secret. | •••••••• |
| Region | OneLogin region for your tenant. | us or eu |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The OneLogin card shows Configured.
- Events with source
oneloginappear in Security → Cloud SIEM → Audit Logs → Events within one poll cycle.
+1-415-800-4104