
DannyM.95900 (Customer) asked a question.
Is there an easier way to read the syslog to see the outcomes of actual sessions for a user? It is difficult to see a bunch of successes and a single failure in the middle and actually determine if the user was able to log in or not. Am I missing a session identifier so I can at least see which actions are all grouped together?

Hi @DannyM.95900 (Customer) , thank you for contacting okta Community.
After researching the matter with our extended team, there are a few filtering options you could try:
The externalSessionId search is detailed in this article.
The transactionId can be a good alternative if externalSessionId is unavailable.
However, there are cases where externalSessionId changes, even though the actions can ultimately be attributed to the same user. The rootSessionId addresses this well, with the exception that it doesn't apply to Workflows, PAM, or some on-prem events (e.g., Radius).
NOTE: rootSessionId is a new feature currently only available on preview orgs. It will become available for production orgs starting next week.
Regards.
--
Ask Us Anything thru 9/3 Okta’s New MFA Requirement for Admin Console Access