<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00005nTwhmSACOkta Classic EngineIntegrationsAnswered2018-12-14T16:32:27.000Z2018-12-13T00:50:04.000Z2018-12-14T16:32:27.000Z
  • Hi,

     

    You should be able to take full advantage of your SIEM solution with Okta, we do have a guide specifically for this task, which details various usage scenarios with Okta via the API and different SIEM solutions, the Okta APIs that cover this would be the events API and the System logs API.

    The information is available in the "Exporting Okta Log Data" docs found at the following address:

    https://support.okta.com/help/s/article/Exporting-Okta-Log-Data

     

    Best Regards.

    Expand Post
  • BillH.93752 (GeoVera Holdings, Inc.)

    HHi Valeriu,

    Thank you for getting back to me so quickly. That seems like exactly what I need, but I have one question. My SIEM is LogRhythm and I see that it is supported so I read the documentation and generated an API key. I edited the okta.ini file as directed in the referenced document and pasted in my new API KEY. I added a new log source, and restarted the LogRhythm service and it looks like it trying to connect but getting this failure:

    12/13/2018 17:16:43.223008 [Kris] ***ERROR*** Exception in getting events: The remote server returned an error: (401) Unauthorized.
    12/13/2018 17:16:43.223008 [Kris] ***ERROR*** Bad response received from Okta server

    I wonder if the value I put in for URI is right. I guessed at
    https://geovera.okta.com since that is what we use to log in.

    Thanks,
    Bill
    Expand Post
  • BillH.93752 (GeoVera Holdings, Inc.)

    Nevermind. It was a copy/paste issue with the key. Working now.
This question is closed.
Loading
syslog to our SIEM?