
bb59t (bb59t) asked a question.
In my okta system logs, some users have logOnlySecurityData field in user.session.start logs while in some other users log its present.
What this implies? are there certain cases only where this field is present? I thought for each and every login session it will evaluated and the the field would be present.

Hello @bb59t (bb59t) Thank you for posting on our Community page!
Based on our doc below, "Okta evaluates all sign-in requests for risk and changes in user behavior. The results of the risk and behavior evaluation are added to the DebugContext section in the System Log in the LogOnlySecurityData field. See Risk Scoring and Behavior Detection."
https://help.okta.com/en-us/content/topics/security/security_risk_scoring.htm
From this, if the user hits a Sign on policy that does not have Risk Scoring and Behavior Detection setup the log would not show in the System log.
Please also see: https://help.okta.com/en-us/content/topics/security/risk-behavior-eval.htm
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.