elastic / elastic/integrations

[entityanalytics_okta]: provide alternative Okta Integration Network (OIN) authentication

Open
#12,663 2 comments 0 reactions 1 assignee Claimed by @chemamartinez View on GitHub
enhancement Integration:entityanalytics_okta meta needs:triage Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Okta Entity Analytics [entityanalytics_okta]

### Dataset Name

entityanalytics_okta.user

### Integration Version

1.8.0

### Agent Version

8.16.1

### OS Version and Architecture

Okta API

### User Goal

The general Okta logs integration offers to authenticate using OIN:
https://www.elastic.co/guide/en/integrations/current/okta.html#okta-okta-integration-network-oin

This is super simple to set up and configure on the Okta side, esp. since all minimal required scopes are assigned to the App, teher's no chance to "overprovision" the service account user.

Either a separate App, or hook up on the existing "Elastic Agent" app used for Okta logs ingestion.

### Existing Features

Currently, have to create a service account, with some admin role applied. The documentation doesn't really specify which of the available Admin roles to choose from, so it's easy to assign more rights than necessary this way.

### What did you see?

only being able to use a api key of a service account.

### Anything else?

It probably would be cleanest to provide a separate App on the Okta side, i.e. "Elastic Entityanalytics" alongside to the "Elastic Agent" app, but on the other hand, folks that ingest Okta logs, might want the asset information as well....

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.