Integrations
- Integrations
- 1Password
- Abnormal
- Absolute
- AbuseIPDB
- Acronis
- Active Directory On-Prem
- Adaptive Shield
- Adobe Cloud
- ADP
- Agari Phishing Response
- Airlock
- Airlock Digital
- Akamai Identity Cloud Social
- Alert Logic
- AlgoSec Firewall Analyzer
- Alienvault OTX
- Alienvault USM
- Anodot
- Ansible
- Anthropic
- Anvilogic
- Any Run
- Apex One
- ArcSight ESM
- Ardoq
- Area 1
- Armis Centrix
- Asana
- Asset Panda
- Astrix
- Atlassian Crowd
- Atlassian User Management
- Atlassian User Provisioning
- AuditBoard
- auth0
- Authentik
- Authomize
- Automox
- AWS
- AWS IAM Identity Center
- Axonius
- Azure
- Azure Data Explorer
- Azure DevOps
- Azure Log Analytics
- Azure Storage
- BambooHR
- Big Fix
- BigPanda
- Bitbucket
- Bitdefender
- Bitsight
- Bitwarden
- Black Duck
- Black Kite
- Blink
- BMC Remedy
- Box
- Brinqa
- Cato Networks
- Censys
- Chorus
- Cisco Advanced Phishing Protection
- Cisco Domain Protection
- Cisco Meraki
- Cisco Talos
- Cisco Umbrella
- Cisco Webex
- Claroty CTD
- Claroty xDome
- ClearPass
- ClickHouse
- ClickUp
- Cloud Custodian
- Cloudflare
- Cloudflare R2
- Cobalt.io
- Check Point Harmony
- Check Point Infinity Events
- Check Point Management
- Check Point XDR/XPR
- Checkmarx SAST
- Checkmarx One
- Chronicle
- Compass
- Confluence
- Confluence Data Center
- Coralogix
- Coralogix Incident Management
- Cortex XDR
- Cortex Xpanse
- Coupa Compass
- CredStash
- Cribl
- CrowdStrike
- CyberArk
- Cybersixgill
- CyCognito
- Cyera
- Cylance
- Cyware CTIX
- Darktrace
- Dasera
- Databricks
- Datadog
- DataSet
- Delighted
- Delinea
- Devo
- Digital-Shadows
- Discord
- Docusign
- Domo
- Drata
- Dropbox
- Dropbox Business
- druva
- Duo
- Duo Auth
- Dynatrace
- EasyVista
- EchoTrail
- Egnyte
- Egnyte Secure Govern
- Elasticsearch
- Entro
- Entrust Certificate Services
- Ermetic
- Exabeam
- Exchange Online
- Expel
- F5
- Falcon LogScale
- Falcon Surface
- Fastly
- Flare.io
- Forcepoint DLP
- Forescout
- FortiGate
- Freshservice
- GCP
- Gemini
- Ghostwriter
- Git
- GitHub
- GitLab
- Glean
- Gmail
- Google Calendar
- Google Chat
- Google Docs
- Google Drive
- Google Forms
- Google Looker
- Google Meet
- Google Sheets
- Google Workspace
- Grafana
- Greenhouse
- GreyNoise
- Grip Security
- GYTPOL
- HackerOne
- HackNotice
- Halo PSA
- Have I Been Pwned
- HiBob
- HubSpot
- Hunters
- Hybrid Analysis
- Hyperproof
- IBM CLoud
- IBM NS1 Connect
- IBM Security Verify
- IBM X Force
- Imperva
- Incident.io
- Infobip
- Infoblox Cloud Services Portal
- Intercom
- Intezer
- IP API
- IPinfo
- IPWHOIS
- Ironscales
- Ivanti RiskSense
- Jamf
- JetBrains
- JFrog
- Jira
- Jira Data Center
- Joe Sandbox
- JumpCloud
- Kandji
- Keeper Secrets Manager
- Kenna Security
- KnowBe4
- KnowBe4 Events
- Kubernetes
- Lacework
- LaunchDarkly
- LimaCharlie
- Linear
- Litmos
- Living Security
- LogicMonitor
- LogRhythm
- Manage Engine ServiceDesk Plus
- Mattermost
- Maven
- Microsoft Defender For Cloud
- Microsoft Defender For Cloud Apps
- Microsoft Defender For Endpoints
- Microsoft Defender XDR
- Microsoft E-Discovery
- Microsoft Entra ID
- Microsoft Excel
- Microsoft Graph
- Microsoft Intune
- Microsoft Office 365 Management Activity
- Microsoft Outlook
- Microsoft Purview
- Microsoft Sentinel
- Microsoft SQL Server
- Microsoft Teams
- Mimecast
- MISP
- Monday
- MongoDB Atlas
- MxToolbox
- Neo4j
- NetBox
- Netography
- Netskope
- New Relic
- Nexthink
- Nightfall AI
- NinjaOne
- Notion
- Nozomi Networks
- Nuclei
- Nucleus
- Nutanix Hypervisor
- Obsidian
- Okta
- Okta
- Actions
- Overview
- Activate User
- Add User To Group
- Create Group
- Create User
- Deactivate User
- Delete User
- End Current User Sessions
- Get A User's Factors
- Get Group By Display Name
- Get Logs
- Get User By Email
- List All Devices
- List Application Users By ID
- List Applications
- List Group Members
- List Groups
- List Policies
- List User Groups
- List Users
- Okta Custom Action
- Remove User From Group
- Reset Password
- Revoke All User Sessions
- Suspend User
- Unsuspend User
- Update User
- Triggers
- OneDrive
- OneLogin
- OneTrust
- Oort
- OpenAI
- OpenCTI
- Opsgenie
- OPSWAT
- Oracle Cloud
- Oracle HCM
- Oracle NetSuite
- Oracle PeopleSoft
- Orca Security
- OWASP ZAP
- PagerDuty
- Palo Alto NGFW
- Palo Alto Firewall
- Panther
- Pentera
- Perception Point
- PhishLabs
- PhishLabs Incident Data
- PhishLabs Open Web Monitoring
- Pingdom
- PingID
- PingOne
- PlexTrac
- PortSwigger
- Postman
- Postman SCIM
- Power BI
- PowerShell
- Prisma Access
- Prisma Cloud
- Prisma Cloud CWP
- Prometheus
- Proofpoint
- Proofpoint ITM
- Proofpoint Protection Server
- Proofpoint Security Awareness Training
- Proofpoint TAP
- Proofpoint TRAP
- Pub-Sub
- QRadar
- Qualys
- Rapid7
- Rapid7 InsightIDR
- Rapid7 InsightVM Cloud
- Rapid7 Threat Command
- Reco
- Recorded Future
- Recorded Future Triage Cloud
- Red Hat IDM
- Rippling
- Rubrik
- runZero
- SafeBase
- SafeBreach
- Sage HR
- SailPoint
- SailPoint IdentityIQ
- Salesforce
- SAP Ariba
- Sap Concur
- ScienceLogic
- Securin
- Securin VI
- SecurityScorecard
- Securonix
- Seemplicity
- Sekoia.io
- SemGrep
- SentinelOne
- ServiceNow
- SharePoint
- Shodan
- Shopify
- Silverfort
- Slack
- Smartsheet
- Snipe IT
- Snowflake
- Snyk
- SolarWinds Information Service
- SolarWinds Service Desk
- SonarQube
- Sophos
- Split
- Splunk
- Splunk Observability
- Splunk SOAR
- Spur
- StrongDM
- Sumo Logic
- Symantec EDR
- Sysdig
- Tableau
- Tanium
- TeamCity
- TeamViewer
- Telegram
- Tempo
- Tenable
- Tenable Security Center
- Terraform
- Terraform Cloud
- Tessian
- TheHive
- Thinkst Canary
- Thomson Reuters
- ThreatQuotient
- Trellix Email Security
- Trello
- Trend Vision One
- Twilio
- UKG HR
- Uptycs
- URLScan
- Vault
- Veracode
- Verkada
- Vertica
- VMware vSphere
- VMware Carbon Black
- VirusTotal
- WeChat
- WhatsApp
- WhoIs
- WildFire
- Wiz
- Workday
- Workspace ONE UEM
- YesWeHack
- Zendesk
- Zero Networks
- Zoom
- Zscaler Internet Access
- Zscaler Private Access
Actions
Get Logs
The Okta System Log API provides read access to your organization’s system log. This API provides more functionality than the Events API.
External Documentation
To learn more, visit the Okta documentation.
Basic Parameters
Parameter | Description |
---|---|
Query | Filters the log events results by one or more exact keywords. |
Return All Pages | Automatically fetch all resources, page by page. |
Since | Filters the lower time bound of the log events published property for bounded queries or persistence time for polling queries. |
Until | Filters the upper time bound of the log events published property for bounded queries or persistence time for polling queries. |
Advanced Parameters
Parameter | Description |
---|---|
Filter | Filter Expression that filters the results, for more information visit https://developer.okta.com/docs/reference/api/system-log/#expression-filter |
Limit | Sets the number of results that are returned in the response. |
Sort Order | The order of the returned events. |
Example Output
Copy
Ask AI
[
{
"actor": {
"id": "<string>",
"type": "<string>",
"alternateId": "<string>",
"displayName": "<string>",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "<string>",
"os": "<string>",
"browser": "<string>"
},
"zone": "<string>",
"device": "<string>",
"id": null,
"ipAddress": "<string>",
"geographicalContext": {
"city": "<string>",
"state": "<string>",
"country": "<string>",
"postalCode": "<string>",
"geolocation": {
"lat": 16,
"lon": 36
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 1,
"rootSessionId": "<string>",
"externalSessionId": "<string>"
},
"displayMessage": "<string>",
"eventType": "<string>",
"outcome": {
"result": "<string>",
"reason": "<string>"
},
"published": "2001-11-12T14:30:22.922Z",
"securityContext": {
"asNumber": 16883,
"asOrg": "<string>",
"isp": "<string>",
"domain": null,
"isProxy": false
},
"severity": "<string>",
"debugContext": {
"debugData": {
"authnRequestId": "<string>",
"deviceFingerprint": "<string>",
"oktaUserAgentExtended": "<string>",
"requestId": "<string>",
"dtHash": "<string>",
"challengeAuthenticatorsList": "<string>",
"requestUri": "<string>",
"threatSuspected": "<string>",
"url": "<string>",
"logOnlySecurityData": "<string>"
}
},
"legacyEventType": null,
"transaction": {
"type": "<string>",
"id": "<string>",
"detail": {}
},
"uuid": "<string>",
"version": "<string>",
"request": {
"ipChain": [
{
"ip": "<string>",
"geographicalContext": {
"city": "<string>",
"state": "<string>",
"country": "<string>",
"postalCode": "<string>",
"geolocation": {
"lat": 9,
"lon": 50
}
},
"version": "<string>",
"source": null
}
]
},
"target": [
{
"id": "<string>",
"type": "<string>",
"alternateId": "<string>",
"displayName": "<string>",
"detailEntry": {
"signOnModeType": "<string>",
"signOnModeEvaluationResult": "<string>"
}
},
{
"id": "<string>",
"type": "<string>",
"alternateId": "<string>",
"displayName": "<string>",
"detailEntry": {
"policyName": "<string>",
"policyRuleFactorMode": "<string>"
}
}
]
},
{
"actor": {
"id": "<string>",
"type": "<string>",
"alternateId": "<string>",
"displayName": "<string>",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "<string>",
"os": "<string>",
"browser": "<string>"
},
"zone": "<string>",
"device": "<string>",
"id": null,
"ipAddress": "<string>",
"geographicalContext": {
"city": "<string>",
"state": "<string>",
"country": "<string>",
"postalCode": "<string>",
"geolocation": {
"lat": 70,
"lon": 31
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": "<string>",
"credentialProvider": null,
"credentialType": "<string>",
"issuer": null,
"interface": "<string>",
"authenticationStep": 1,
"rootSessionId": "<string>",
"externalSessionId": "<string>"
},
"displayMessage": "<string>",
"eventType": "<string>",
"outcome": {
"result": "<string>",
"reason": null
},
"published": "2017-12-14T07:43:21.762Z",
"securityContext": {
"asNumber": 2191,
"asOrg": "<string>",
"isp": "<string>",
"domain": null,
"isProxy": false
},
"severity": "<string>",
"debugContext": {
"debugData": {
"agentid": "<string>",
"delauthtimeout": "<string>",
"deviceFingerprint": "<string>",
"behaviors": "<string>",
"requestUri": "<string>",
"delauthtimespentatagent": "<string>",
"url": "<string>",
"authnRequestId": "<string>",
"requestId": "<string>",
"dtHash": "<string>",
"actionid": "<string>",
"delauthtimetotal": "<string>",
"risk": "<string>",
"threatSuspected": "<string>",
"delauthtimespentatdomaincontroller": "<string>"
}
},
"legacyEventType": "<string>",
"transaction": {
"type": "<string>",
"id": "<string>",
"detail": {}
},
"uuid": "<string>",
"version": "<string>",
"request": {
"ipChain": [
{
"ip": "<string>",
"geographicalContext": {
"city": "<string>",
"state": "<string>",
"country": "<string>",
"postalCode": "<string>",
"geolocation": {
"lat": 47,
"lon": 51
}
},
"version": "<string>",
"source": null
}
]
},
"target": [
{
"id": "<string>",
"type": "<string>",
"alternateId": "<string>",
"displayName": "<string>",
"detailEntry": null
},
{
"id": "<string>",
"type": "<string>",
"alternateId": "<string>",
"displayName": "<string>",
"detailEntry": null
}
]
}
]
Workflow Library Example
Get Logs with Okta and Send Results Via Email
Preview this Workflow on desktop
Was this page helpful?
Assistant
Responses are generated using AI and may contain mistakes.