Glossary
externalSessionId
The Okta session identifier in authenticationContext, used to group every event of one sign-in session and to spot a session replayed from elsewhere.
authenticationContext.externalSessionId identifies the Okta session an event belongs to. Grouping events by it shows everything done in one session; seeing the same value from two networks (ASNs) or two browsers is the classic trace of a stolen session cookie. Okta Security notes that this identifier can be regenerated after factor lifecycle events, while rootSessionId follows the whole interactive session (Okta Security), so investigators should pivot on both.
More in Okta session hijacking detection.