Integration: Kaseya SIEM and Okta

Overview

The Kaseya SIEM and Okta integration enables Kaseya SIEM to collect identity and authentication events from Okta. After the integration is configured, Kaseya SIEM can monitor activities such as authentication successes and failures, password resets, user account events, and other supported Okta audit events. This integration provides centralized visibility into Okta security events and helps security teams investigate identity-related activity alongside other telemetry available in Kaseya SIEM.

Prerequisites

Before configuring the integration:

  • Administrative access to the Okta tenant is required.

  • The Okta tenant URL must be available in the following format: https://yourdomain.okta.com

  • Permission to create an Okta application integration is required.

  • Permission to grant Okta API scopes within the Okta tenant is required.

How to...

FAQ

Troubleshooting

Redirect URI mismatch

Issue: An error appears during authorization or authentication fails when connecting the integration.

Resolution: Verify that the Sign-in Redirect URI configured in Okta exactly matches the value documented for the Kaseya SIEM integration. Even minor differences can prevent authorization from completing successfully.

Authorization fails

Issue: Authorization cannot be completed.

Resolution: Verify the following:

  • The Client ID and Client Secret are correct.

  • The required Okta API scopes have been granted.

  • The account used during authorization has sufficient administrative permissions.

No events are appearing in Kaseya SIEM

Issue: The integration shows as connected, but Okta events are not appearing.

Resolution: Verify that the required okta.logs.read API scope has been granted in Okta and that authorization was completed successfully. Event ingestion may be delayed while the initial connection is established.

Authorization window does not open

Issue: The Okta sign-in or authorization window does not appear when connecting the integration.

Resolution: Verify that your browser is not blocking pop-up windows. If necessary, allow pop-ups for both Kaseya SIEM and Okta, then attempt the connection again.