<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008giIq9CAEOkta Classic EngineInsights and ReportingAnswered2023-01-19T06:01:33.000Z2023-01-18T21:31:34.000Z2023-01-19T06:01:33.000Z

DavidR.11757 (Customer) asked a question.

Anybody using Wazuh to ingest and analyze Okta system logs?

We're new to Okta at my institution and I'm looking at ways for us to ingest Okta logs into a SIEM solution. Wazuh is likely what we're going to use for that. It looks like it's non-trivial to get the logs out of Okta. Is anyone doing this? If so, can you share advice for how you implemented it?

 

Thanks!


  • DonF.81354 (Customer)

    Not too bad actually, although we are using Splunk so I really can’t comment on the complexity involved for Wazuh or another solution.

     

    From the Okta end, you need to generate an API key and provide that to your SIEM team for use. From there, they will use that for ingestion of logs by querying the Okta System Log API. May I recommend that this API key be generated with a Read-Only admin account, as do be aware API keys have the power of the admin that generated them.

     

    I do hope that helps! Pleas let me know if you have any questions. See relevant links below:

     

    Exporting Okta Log Data

     

    Create an API Token

     

    Thanks!

     

    Expand Post
This question is closed.
Loading
Anybody using Wazuh to ingest and analyze Okta system logs?