Skip to main content
Run any Skill in Manus
with one click

ingest-okta-system-log-ocsf

Stars3
Forks0
UpdatedJuly 11, 2026 at 02:43

Convert verified Okta System Log events into OCSF 1.8 or native Identity & Access Management records. The first slice maps session and SSO events to Authentication (3002), user lifecycle and account-control changes to Account Change (3001), app/group membership updates to User Access Management (3005), and a narrow verified set of Okta Verify MFA challenge and denial events to Authentication (3002). It preserves Okta natural IDs such as uuid, published, transaction.id, and authenticationContext.externalSessionId for SIEM-friendly dedupe and correlation. Use when the user mentions Okta System Log ingestion, Okta audit log normalization, cross-vendor identity telemetry, or feeding Okta identity events into an OCSF pipeline or native canonical-first flow. Do NOT use for raw Azure Entra, Google Workspace, or AWS IAM logs. Do NOT use as a detector or policy engine — this skill only normalizes verified Okta event payloads into OCSF or native output.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
7 files
SKILL.md
readonly