Glossary
eventType (Okta)
The dotted identifier that says what an Okta System Log event records, such as user.session.start or user.account.privilege.grant.
An eventType is the machine-readable name of an Okta System Log event, written as dotted segments: user.session.start (sign-in), user.mfa.factor.reset_all (all factors reset), system.idp.lifecycle.create (identity provider created). Okta publishes the full list in its event types catalog, with descriptions and the release in which each type appeared. Some types differ between Classic Engine and Identity Engine, so a detection should name every variant.
The eventType says what happened; the outcome, actor, target and network fields say whether it was legitimate. The responder's eventType list groups the important ones by attack stage.