Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

Okta System Log

The audit log of an Okta org: every sign-in, MFA challenge, session, admin change and app access, recorded as LogEvent objects and kept for 90 days.

The Okta System Log is the audit trail of an Okta organisation. Each record is a LogEvent with an eventType, an actor, targets, client and network context, an outcome and a unique uuid. It is available in the Admin Console (Reports › System Log), through the /api/v1/logs API, and through log streaming to external platforms. Okta returns 90 days of data (Okta Developer), so anything older must have been exported or streamed beforehand.

For responders it is the primary evidence of an identity attack. See how to export it and how to investigate a compromise.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.