Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

eventType (Okta)

The dotted identifier that says what an Okta System Log event records, such as user.session.start or user.account.privilege.grant.

An eventType is the machine-readable name of an Okta System Log event, written as dotted segments: user.session.start (sign-in), user.mfa.factor.reset_all (all factors reset), system.idp.lifecycle.create (identity provider created). Okta publishes the full list in its event types catalog, with descriptions and the release in which each type appeared. Some types differ between Classic Engine and Identity Engine, so a detection should name every variant.

The eventType says what happened; the outcome, actor, target and network fields say whether it was legitimate. The responder's eventType list groups the important ones by attack stage.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.