Skip to main content
Sumo Logic

Install the Okta App and view the Dashboards

The Sumo Logic App for Okta helps you monitor the admin actions, failed logins, successful logins, and user activities to your applications through Okta. The App consists of dashboards that give you visibility into the applications, accesses, user events, and Multi-factor Authentication (MFA).

Install the Sumo Logic App

Now that you have set up collection for Okta, install the Sumo Logic App for Okta to use the preconfigured searches and Dashboards that provide insight into your data. 

To install the app:

  1. Select App Catalog, search for and select the app, and click Add to Library. (In the classic UI, click Library, click Apps, select the app, and click Install. If you don't find the app under Apps, it might be a preview app. Try clicking Preview to find the app.)
  2. Click Preview Dashboards if you'd like to see a preview of the dashboards included with the app before installing.
  3. In the Install Application dialog box, select the installation path (the default is the Personal folder in the library), or click New Folder to add a new folder.
  4. Select either of these options for the log data source.
  • Choose Select from Existing Source Categories, and select the source catalog from the Source Category list.
  • Choose Enter a Custom Data Filter and enter a custom source category beginning with an underscore. Example: (_sourceCategory=MyCategory).
  1. Click Add to Library.

Once an app is installed, it will appear in your Personal folder, or other folder that you specified. From here, you can share it with your organization. See Welcome to the New Library for information on working with the library in the new UI.

Panels will start to fill automatically. It's important to note that each Panel slowly fills with data matching the time range query and received since the Panel was created. Results won't immediately be available, but with a bit of time, you'll see full graphs and maps. 

Dashboards

Okta - Administrative Actions

Shows the details of administrative actions such as the geolocation of application events, severity of events over time, application events, deactivated applications, application creation and deletion, admin accesses, and AD agent connection to Okta.

Okta Admin Actions

Geolocation of Application Events. See the number of application events across the world on a map in the last 24 hours. 

Application Events by Severity Over Time. See the count of application events by severity in the last 24 hours on a line chart.

Application Events by Severity. See the count of application events by severity in the last 24 hours on a column chart.

Breakdown by Events. See the breakdown of administrative actions by events in the last 24 hours on a pie chart.

Deactivated Application. See the app name, user ID, outcome of access attempt, display message, and count of the deactivated applications in the last 24 hours displayed in a table.

Application Created. See the count of applications created in the last 24 hours along with the application name, user ID, message displayed, and the outcome result shown in a table.

Application Deleted. See the count of applications deleted in the last 24 hours along with the application name, user ID, message displayed, and the outcome result shown in a table.

Okta Admin Access. See the user ID, city, display message, outcome result, and count of the Okta Admin Access in the last 24 hours displayed in a table.

Connect AD Agent to Okta. See the details of connect AD agent to Okta such as the Okta user ID, outcome result, display message, and count, in the last 24 hours.

Okta - Application Access

Shows the details of accesses by different applications, the location of logins, top 10 active users, successful and failed accesses by applications.

Okta Application Access

Breakdown By Application. See the Okta access broken down by application in a pie chart for the last three days.

Geolocation of Application Logins. See the number of logins to the application across the world on a map for the last three days.

Top 10 Applications. See the name and count of the top 10 applications accessing Okta in the last three days in a table.

Top 10 Active users. See the name and count of the top 10 users accessing Okta the last three days displayed in a table.

Successful Application Access Over Time. See the successful application accesses over the last three days in a line chart.

Successful Distinct Application Access by User. See the successful application accesses by users over the last three days in a line chart.

Failed Application Access by Users. See the app name, user ID, outcome of access attempt, display message, and count of the failed access by users in the last three days displayed in a table.

Failed Application Access by Users over Time. See the failed accesses by users in the last three days on a line chart.

Outlier in Successful Application Access by User. See the outlier in the successful accesses in the last three days by user ID and count statistics displayed in a table.

Outlier in Failed Application Access by User. See the outlier in the failed accesses in the last three days by user ID and count statistics displayed in a table.

Okta - Failed Login Activity

Shows the details of failed logins to Okta such as the geolocation, country, state, OS, browser, device, top 10 users, and application.

Okta failed logins

Geolocation of Logins. See the number of failed logins across the world on a map for the last three days. 

Login breakdown by Country and State. See the count of failed logins broken down by country and state in a stacked column chart on a timeline for the last three days.

Breakdown by Client OS and Browser. See the count of failed logins by browsers broken down by OS in a stacked column chart on a timeline for the last three days.

Logins Overtime. See the count of failed logins over time in the last three days on a column chart.

Login - Outlier. See the failed logins in an outlier chart on a timeline for the last three days.

Breakdown by Client Device and Browser. See the count of failed logins by browsers broken down by devices in a stacked column chart on a timeline for the last three days.

Top 10 Users by Login Attempt Count. See the top 10 users with the count of failed login attempts for the last three days in a table.

App Login. See the breakdown of failed logins by applications for the last three days on a pie chart.

Okta - Successful Login Activity

Shows the details of successful logins to Okta such as the device, browser, country, state, OS, geolocation, logins overtime, outlier, top 10 users, and application.

Okta successful login

Geolocation of Logins. See the number of successful logins across the world on a map for the last three days. 

Login breakdown by Country and State. See the count of successful logins broken down by country and state in a stacked column chart on a timeline for the last three days.

Breakdown by Client OS and Browser. See the count of successful logins by browsers broken down by OS in a stacked column chart on a timeline for the last three days.

Logins Overtime. See the count of successful logins over time in the last three days on a column chart.

Login - Outlier. See the successful logins in an outlier chart on a timeline for the last three days.

Breakdown by Client Device and Browser. See the count of successful logins by browsers broken down by devices in a stacked column chart on a timeline for the last three days.

Top 10 Users by Login Count. See the top 10 users with the count of successful logins for the last three days in a table.

App Login. See the breakdown of successful logins by applications for the last three days on a pie chart.

Okta - User Activity 

Shows the details of user activity such as the geolocation, top 10 users, user events, events by users, events by severity, password resets, password updates, and user account locks.

Okta user activity

Geolocation of User Activity. See the number of user activities across the world on a map for the last 24 hours.

Top 10 Active Users. See the top 10 active users in the last 24 hours displayed on a bar chart.

User Events Breakdown. See the breakdown of user events in the last 24 hours on a pie chart.

Events by User. See the count of events per user in the last 24 hours on a column chart.

User Events by Severity. See the count of user events by severity for the last 24 hours on a column chart.

Events by Severity Over Time. See the count of events by severity for the last 24 hours on a line chart.

Password Reset Event. See the details of password reset events such as the username, actor, outcome result, country, state, and count, in the last 24 hours displayed in a table.

Password Update Event. See the details of password update events such as the username, actor, outcome result, country, state, and count, in the last 24 hours displayed in a table.

User Account Lock. See the details of locked user accounts in the last 24 hours such as the actor, actor ID, outcome result, displayed message, and count, shown in a table.

Okta - User Authentication and MFA

Shows the details of user authentication and Multi-Factor Authentication (MFA) activities such as the user authentication over time, MFA events, MFA deactivation, and user authentication using MFA.

Okta user authentication and MFA

User Authentication. See the count of user authentication in the last 24 hours on a column chart.

User MFA Events Over Time. See the count of user MFA events in the last 24 hours on a column chart.

User Authentication via MFA. See the details of user authentication using MFA such as the user ID, factor, user agent, display message, outcome result, and count, in the last 24 hours displayed in a table.

User Authentication Activity. See the count of user authentication activities in the last 24 hours on a stacked column chart.

MFA Deactivate Event. See the details of MFA deactivate event in the last 24 hours such as the user ID, actor, outcome result, country, state, and count, shown in a table.

User MFA Activity. See the details of user MFA activities such as the event type, result, reason, user ID, username, and count, in the last 24 hours, displayed in a table.