Document toolboxDocument toolbox

gateway.okta

Introduction

The tags beginning with gateway.okta identify events generated by Okta Access Gateway logs.

Valid tags and data tables

The full tag must have four levels. The first three are fixed as gateway.okta.oag. The fourth level indicates the event subtype.

Technology

Brand

Type

Subtype

gateway

okta

oag

  • access
  • audit
  • monitor

These are the valid tags and corresponding data tables that will receive the parsers' data:

Tag

Data table

gateway.okta.oag.accessgateway.okta.oag.access
gateway.okta.oag.auditgateway.okta.oag.audit
gateway.okta.oag.monitorgateway.okta.oag.monitor

How is the data sent to Devo?

Logs generated by okta must be sent to the Devo platform via the Devo Relay to secure communication. See the required relay rules below:

Log samples

The following are sample logs sent to each of the gateway.okta.oag data tables. Also, find how the information will be parsed in your data table under each sample log.