ingest-okta-system-log-ocsf
Installation
SKILL.md
ingest-okta-system-log-ocsf
Convert raw Okta System Log payloads into OCSF 1.8 or native IAM events with deterministic IDs and verified field mappings.
Use when
- You have Okta System Log exports from the
/api/v1/logsAPI, event hooks, or archived JSON and need OCSF output - You want to normalize Okta identity telemetry for SIEM, lake, MCP, or downstream detection use
- You need a portable identity event stream that preserves Okta
uuid,published, session, and transaction identifiers - You want app and group membership updates represented as OCSF user access events instead of vendor-only audit records
Do NOT use
- On Entra, Workspace, CloudTrail, or Kubernetes audit logs
- To collect live Okta logs by itself — upstream collection and auth stay outside this skill
- To infer ATT&CK techniques or create findings directly
- To rewrite or mutate Okta objects, users, groups, apps, or sessions