Integration: Kaseya SIEM and Okta
Kaseya SIEM
NAVIGATION Organizations > Edit Organization > Applications > New Application
PERMISSIONS Kaseya SIEM administrator permissions
Okta
NAVIGATION Applications > Applications
PERMISSIONS Okta administrator privileges
Overview
The Kaseya SIEM and Okta integration enables Kaseya SIEM to collect identity and authentication events from Okta. After the integration is configured, Kaseya SIEM can monitor activities such as authentication successes and failures, password resets, user account events, and other supported Okta audit events. This integration provides centralized visibility into Okta security events and helps security teams investigate identity-related activity alongside other telemetry available in Kaseya SIEM.
Prerequisites
Before configuring the integration:
-
Administrative access to the Okta tenant is required.
-
The Okta tenant URL must be available in the following format: https://yourdomain.okta.com
-
Permission to create an Okta application integration is required.
-
Permission to grant Okta API scopes within the Okta tenant is required.
How to...
To prepare Okta for use with Kaseya SIEM:
-
Sign in to the Okta Admin Console.
-
Navigate to Applications > Applications.
-
Select Create App Integration.
-
Select OIDC - OpenID Connect.
-
Select Web Application.
-
Enter Kaseya SIEM as the application name.
-
Enable the following grant types:
-
Authorization Code
-
Refresh Token
-
-
In Sign-in Redirect URIs, enter: https://manage.kaseyasiem.com/products/oauth2/redirect
-
Select Skip group assignment for now.
-
Create the application.
-
Grant the following API scope: okta.logs.read
-
Record the Client ID and Client Secret: The Client ID and Client Secret will be required when configuring the integration in Kaseya SIEM.
To complete the integration:
-
Navigate to Organizations.
-
Select the organization to configure.
-
Select the Edit icon.
-
Open the Applications tab.
-
Select + New Application.
-
Select Okta.
-
Enter the following information:
-
Domain
-
Client ID
-
Client Secret
-
-
Select Finish.
-
Complete the authorization process when prompted.
The Okta connection is activated after authorization is successfully completed, and Okta events can begin flowing into Kaseya SIEM.
To verify the integration:
-
Open the organization's Applications list.
-
Confirm that the Okta application displays an Active status.
-
Verify that events begin appearing within Kaseya SIEM.
Examples of Okta events that may appear in Kaseya SIEM include:
-
Authentication Success
-
Authentication Failure
-
OAuth Access Used for Foreign Application
-
User Logged Out
-
New User Added
-
Password Reset
To disable the integration:
-
Navigate to Organizations.
-
Select the organization.
-
Open the Applications tab.
-
Locate the Okta integration.
-
Disconnect or remove the integration.
No additional configuration changes are required in Okta unless you also want to delete the associated Okta application.
FAQ
After the integration is configured, Kaseya SIEM can collect supported Okta audit and authentication events. Examples include Authentication Success, Authentication Failure, OAuth Access Used for Foreign Application, User Logged Out, New User Added, and Password Reset.
After the integration is successfully authorized, event ingestion should begin automatically. The time required for events to appear depends on Okta activity and processing delays between the platforms.
If the Client Secret is regenerated, the existing integration may no longer be able to authenticate with Okta. Update the integration configuration in Kaseya SIEM using the new Client Secret.
Yes. Configure a separate integration for each Okta tenant you want Kaseya SIEM to monitor. Each tenant requires its own application registration, credentials, and authorization process.
Troubleshooting
Redirect URI mismatch
Issue: An error appears during authorization or authentication fails when connecting the integration.
Resolution: Verify that the Sign-in Redirect URI configured in Okta exactly matches the value documented for the Kaseya SIEM integration. Even minor differences can prevent authorization from completing successfully.
Authorization fails
Issue: Authorization cannot be completed.
Resolution: Verify the following:
-
The Client ID and Client Secret are correct.
-
The required Okta API scopes have been granted.
-
The account used during authorization has sufficient administrative permissions.
No events are appearing in Kaseya SIEM
Issue: The integration shows as connected, but Okta events are not appearing.
Resolution: Verify that the required okta.logs.read API scope has been granted in Okta and that authorization was completed successfully. Event ingestion may be delayed while the initial connection is established.
Authorization window does not open
Issue: The Okta sign-in or authorization window does not appear when connecting the integration.
Resolution: Verify that your browser is not blocking pop-up windows. If necessary, allow pop-ups for both Kaseya SIEM and Okta, then attempt the connection again.