Ingest logs and data from Okta - Learn more about Ingesting logs and data from Okta for use in Cortex Cloud. - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-10
Category
Administrator Guide
Abstract

Learn more about Ingesting logs and data from Okta for use in Cortex Cloud.

Prerequisite

Administrator privileges: Your Okta user must have a role capable of creating API tokens, such as Read-only Administrator, Super Administrator, or Organization Administrator. For more information, see the Okta Administrators Documentation.

To receive logs and configuration data from Okta, configure the Data Sources & Integrations settings in Cortex Cloud. Once enabled, the system immediately begins ingesting activity logs and identity configuration metadata, according to your configuration settings.

Activity logs are searchable using the Cortex Query Language (XQL). For more information, see Perform advanced Identity Security investigations using XQL.

Configuration data is used for Identity Security visibility and is searchable in Identity SecurityIdentity Asset Inventory and using the ciem_permissions_with_last_access dataset.