Okta
Overview
AlphaSOC normalizes Okta telemetry into the Open Cybersecurity Schema Framework (OCSF) format. The fields listed below are available for use in Sigma detection rules. For complete field definitions and semantics, refer to the linked OCSF class schema pages.
Okta: Authentication
OCSF Category: Identity & Access Management
OCSF Class: Authentication
OCSF Fields
activity_idactivity_nameactor.user.email_addractor.user.nameactor.user.typeactor.user.type_idactor.user.uidcategory_namecategory_uidclass_nameclass_uiddevice.is_manageddevice.namedevice.os.typedevice.os.type_iddevice.os.versiondevice.uiddst_endpoint.svc_namehttp_request.uidhttp_request.user_agentmessagemetadata.event_codemetadata.product.namemetadata.product.versionmetadata.uidmetadata.versionsession.issuersession.uidsession.uid_altseverityseverity_idsrc_endpoint.autonomous_system.namesrc_endpoint.autonomous_system.numbersrc_endpoint.domainsrc_endpoint.ipsrc_endpoint.ispsrc_endpoint.location.citysrc_endpoint.location.countrysrc_endpoint.location.latsrc_endpoint.location.longsrc_endpoint.location.postal_codesrc_endpoint.typesrc_endpoint.type_idsrc_endpoint.uidsrc_endpoint.zonestatusstatus_detailstatus_idtimetype_nametype_uiduser.email_addruser.nameuser.typeuser.type_iduser.uid