Troubleshoot the Okta System Logs connector
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Databricks previews.
Resolve common Okta System Logs connector errors, including invalid credentials, insufficient permissions, Okta API rate limits, and temporary service errors.
For general troubleshooting guidance that applies to all managed ingestion pipelines, see Troubleshoot managed ingestion pipelines.
Pipeline fails to authenticate
Cause: The domain or SSWS API token in the Unity Catalog connection is invalid, the token was revoked, the account that created the token is inactive, or the token owner can't read the System Log.
Solution:
- Confirm that Domain contains your Okta organization domain, either as a domain name or as a full HTTPS URL.
- In the Okta Admin Console, go to Security > API > Tokens.
- Confirm that the token is active and that its owner is an active administrator who can read the System Log.
- If necessary, create a new token and update the SSWS API token value in the Unity Catalog connection.
For setup details, see Configure authentication to Okta and Create an Okta System Logs connection.
Okta API rate limit exceeded
Cause: Okta returned an HTTP 429 response because requests associated with the API token exceeded the available rate-limit capacity.
Solution:
The connector retries HTTP 429 responses automatically. If rate limiting continues:
- In the Okta Admin Console, go to Security > API > Tokens.
- Select the API token used by the Unity Catalog connection.
- Under Token rate limits, click Edit.
- If your organization's policy permits, increase the percentage of each API rate limit allocated to the token.
- Reduce the number of concurrent pipelines that use the same token.
Okta API temporarily unavailable
Cause: Okta returned an HTTP 5xx server error.
Solution:
The connector retries temporary server errors automatically. If the issue persists after the retries finish, wait, then run the pipeline again.