Skip to main content

Ingest data from Okta

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Databricks previews.

Use Declarative Automation Bundles or a Databricks notebook to create a managed Okta System Logs pipeline for the system_logs source table.

Requirements​

  • To create an ingestion pipeline, first meet the following requirements:

    • Your workspace must be enabled for Unity Catalog.

    • Serverless compute must be enabled for your workspace. See Serverless compute requirements.

    • To create a new connection, you must have CREATE CONNECTION privileges on the metastore. See Manage privileges in Unity Catalog.

      If the connector supports UI-based pipeline authoring, an admin can create the connection and the pipeline at the same time by completing the steps on this page. However, if the users who create pipelines use API-based pipeline authoring or are non-admin users, an admin must first create the connection in Catalog Explorer. See Connect to managed ingestion sources.

    • To use an existing connection, you must have USE CONNECTION privileges or ALL PRIVILEGES on the connection object.

    • You must have USE CATALOG privileges on the target catalog.

    • You must have USE SCHEMA and CREATE TABLE privileges on an existing schema or CREATE SCHEMA privileges on the target catalog.

  • Configure authentication from Databricks and create a connection. See Configure authentication to Okta and Create an Okta System Logs connection.

  • Use default.system_logs as the source object. For details, see Supported source tables.

Connector options​

The Okta System Logs connector doesn't define connector-specific pipeline options. For connection settings, see Connection options.

Create an ingestion pipeline​

Create the pipeline with Declarative Automation Bundles or a Databricks notebook. While the connector is in Beta, set the pipeline channel to PREVIEW.

Use Declarative Automation Bundles to manage Okta System Logs pipelines as code. Bundles can contain YAML definitions of pipelines and jobs, are managed using the Databricks CLI, and can be shared across development, staging, and production workspaces. For more information, see What are Declarative Automation Bundles?.

  1. Create a bundle using the Databricks CLI:

    Bash
    databricks bundle init
  2. Add a pipeline definition file, such as resources/okta_system_logs_pipeline.yml. See pipeline.ingestion_definition and Examples.

  3. Add a job definition file, such as resources/okta_system_logs_job.yml, to schedule the pipeline.

  4. Deploy the pipeline using the Databricks CLI:

    Bash
    databricks bundle deploy

Examples​

The Okta System Logs connector makes the system_logs source table available in the default source schema.

The following pipeline definition file ingests the system_logs table:

YAML
resources:
pipelines:
okta_system_logs_pipeline:
name: okta_system_logs_pipeline
channel: PREVIEW
catalog: 'main'
target: 'okta_system_logs_pipeline'
ingestion_definition:
connection_name: okta_system_logs_connection
objects:
- table:
source_schema: 'default'
source_table: 'system_logs'
destination_catalog: 'main'
destination_schema: 'okta_system_logs_data'
destination_table: 'system_logs'

Declarative Automation Bundles job definition file​

The following job definition runs the ingestion pipeline daily:

YAML
resources:
jobs:
okta_system_logs_job:
name: okta_system_logs_job
schedule:
quartz_cron_expression: '0 0 0 * * ?'
timezone_id: 'UTC'
tasks:
- task_key: okta_system_logs_ingestion
pipeline_task:
pipeline_id: ${resources.pipelines.okta_system_logs_pipeline.id}

Common patterns​

For advanced pipeline configurations, see Common patterns for managed ingestion pipelines.

Next steps​

Start, schedule, and set alerts on your pipeline. See Common pipeline maintenance tasks.

Additional resources​