Okta System Logs connector
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Databricks previews.
The managed Okta System Logs connector in Lakeflow Connect ingests audit and security events from your Okta organization into Databricks.
The connector uses the Okta System Log API to ingest append-only events, including user activity, authentication, security, and configuration changes.
Feature availability
Feature | Availability |
|---|---|
UI-based pipeline authoring |
|
API-based pipeline authoring |
|
Declarative Automation Bundles |
|
Incremental ingestion |
|
Unity Catalog governance |
|
Orchestration using Databricks Workflows |
|
API-based column selection and deselection |
|
API-based row filtering |
|
SCD Type 2 |
Okta System Log events are append-only. |
Automated schema evolution: New and deleted columns |
|
Automated schema evolution: Data type changes |
|
Automated schema evolution: Column renames |
Treated as a new column (new name) and deleted column (old name). |
Authentication methods
Authentication method | Availability |
|---|---|
OAuth U2M |
|
OAuth M2M |
|
Basic authentication (username/password) |
|
SSWS API token |
|
What to know before you start
Before starting, review the Databricks user persona, supported interfaces, ingestion frequency, and common patterns.
Start ingesting from Okta
- Configure Okta for ingestion (Okta admins). Create an SSWS API token for Databricks.
- Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so pipeline authors don't need direct access to the API token.
- Create an ingestion pipeline (Admins or non-admins). Use Declarative Automation Bundles or a Databricks notebook to create a pipeline from an existing connection.