Skip to main content

Okta System Logs connector reference

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Databricks previews.

The managed Okta System Logs connector supports one source table. This reference lists the source table, connection options, and destination fields.

Supported source tables​

The Okta System Logs connector supports the following source table in the default source schema:

Source table

Primary key

Description

Sync mode

Cursor field

system_logs

lw_id

Audit and security events from your Okta organization.

Incremental

time

Source table

Primary key

Description

Sync mode

Cursor field

system_logs

lw_id

Audit and security events from your Okta organization.

Incremental

time

Use the following source name in a pipeline definition:

YAML
objects:
- table:
source_schema: 'default'
source_table: 'system_logs'

For a complete pipeline definition, see Examples.

Connection options​

Option

Type

Required

Description

domain

String

Yes

The Okta organization domain. You can provide a domain name or a full URL; Databricks normalizes the value to the domain name.

ssws_token

String

Yes

The secret SSWS API token used to authenticate requests to the Okta API.

Option

Type

Required

Description

domain

String

Yes

The Okta organization domain. You can provide a domain name or a full URL; Databricks normalizes the value to the domain name.

ssws_token

String

Yes

The secret SSWS API token used to authenticate requests to the Okta API.

Destination table schema​

The destination table includes Databricks-added fields and Okta System Log fields. For Okta field definitions and nested field details, see the Okta System Log API reference.

Primary key: lw_id Cursor field: time

The connector copies the Okta published timestamp into time and generates lw_id from uuid and published.

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

published

TIMESTAMP

eventType

STRING

version

STRING

severity

STRING

legacyEventType

STRING

displayMessage

STRING

actor

STRUCT

authenticationContext

STRUCT

client

STRUCT

debugContext

STRUCT

outcome

STRUCT

device

STRUCT

transaction

STRUCT

request

STRUCT

target

ARRAY<STRUCT>

securityContext

STRUCT

Field

Data type

lw_id

STRING

time

TIMESTAMP

uuid

STRING

published

TIMESTAMP

eventType

STRING

version

STRING

severity

STRING

legacyEventType

STRING

displayMessage

STRING

actor

STRUCT

authenticationContext

STRUCT

client

STRUCT

debugContext

STRUCT

outcome

STRUCT

device

STRUCT

transaction

STRUCT

request

STRUCT

target

ARRAY<STRUCT>

securityContext

STRUCT

Required Okta account permissions​

The administrator account that creates the SSWS API token must be able to read the System Log. The token inherits the permissions of that account. A read-only administrator account provides read access to the System Log without broader administrative permissions.