Okta System Logs connector

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Azure Databricks previews.

The managed Okta System Logs connector in Lakeflow Connect ingests audit and security events from your Okta organization into Azure Databricks.

The connector uses the Okta System Log API to ingest append-only events, including user activity, authentication, security, and configuration changes.

Feature availability

Feature Availability
UI-based pipeline authoring Red X icon Not supported
API-based pipeline authoring Green check icon Supported
Declarative Automation Bundles Green check icon Supported
Incremental ingestion Green check icon Supported
Unity Catalog governance Green check icon Supported
Orchestration using Databricks Workflows Green check icon Supported
API-based column selection and deselection Green check icon Supported
API-based row filtering Red X icon Not supported
SCD Type 2 Red X icon Not supported
Okta System Log events are append-only.
Automated schema evolution: New and deleted columns Green check icon Supported
Automated schema evolution: Data type changes Red X icon Not supported
Automated schema evolution: Column renames Green check icon Supported
Treated as a new column (new name) and deleted column (old name).

Authentication methods

Authentication method Availability
OAuth U2M Red X icon Not supported
OAuth M2M Red X icon Not supported
Basic authentication (username/password) Red X icon Not supported
SSWS API token Green check icon Supported

What to know before you start

Start ingesting from Okta

  1. Configure Okta for ingestion (Okta admins). Create an SSWS API token for Azure Databricks.
  2. Create a Unity Catalog connection (Admins). Create a connection in Catalog Explorer so pipeline authors don't need direct access to the API token.
  3. Create an ingestion pipeline (Admins or non-admins). Use Declarative Automation Bundles or a Azure Databricks notebook to create a pipeline from an existing connection.