
GregH.00578 (Customer) asked a question.
We have a partner/subsidiary that uses our okta tenant for SSO to cloud apps via an agent on their domain.
We forward all syslog to our primary SIEM. They have requested to receive syslog events for their users only on their SIEM.
Is this possible in okta? I don't want them to receive our user data, so a simple duplication of the push is not an option.

Thank you for contacting Okta.
You can find all exporting log options in the following link:
https://support.okta.com/help/s/article/Exporting-Okta-Log-Data?language=en_US
If you only want the logs for a specific group, you can use the needed API call from the below article, but its implementation and how you pull the logs is not something that the support team can help with:
https://developer.okta.com/docs/reference/api/groups/