Hey all, I'm pretty new to Security and Chronicle and while looking into log ingestion in Chronicle I encountered the topic of ingesting Okta logs into Chronicle, particularly for two customer usecases: system logs and user_context logs. By googling I was able to find this resource for system logs, but wasn't able to find much documentation for steps to follow to get user_context logs. I'm looking for something that can provide steps like getting the API key and plugging it into Chronicle like I see with other log sources.
Any help would be appreciated!
Solved! Go to Solution.
Hi,
Please follow the same process, but select the "OKTA USER CONTEXT" log type instead of the "OKTA" log type.
Hi,
Please follow the same process, but select the "OKTA USER CONTEXT" log type instead of the "OKTA" log type.