Reference Library for Okta Falco Threat Detection Rules

Sysdig Secure enables you to create and customize Threat Detection Rules to secure your environment. This topic provides all the fields and events that apply to Falco rules for Okta.

Fields

Field Class: JSON

NameTypeDescription
json.valueCHARBUFExtracts a value from a JSON-encoded input. Syntax is json.value[], where is a json pointer (see https://datatracker.ietf.org/doc/html/rfc6901)
json.objCHARBUFThe full json message as a text string.
json.rawtimeCHARBUFThe time of the event, identical to evt.rawtime.
jevt.valueCHARBUFAlias for json.value, provided for backwards compatibility.
jevt.objCHARBUFAlias for json.obj, provided for backwards compatibility.
jevt.rawtimeCHARBUFAlias for json.rawtime, provided for backwards compatibility.

Field Class: Okta

NameTypeDescription
okta.appCHARBUFApplication
okta.orgCHARBUFOrganization
okta.evt.typeCHARBUFEvent Type
okta.evt.legacytypeCHARBUFEvent Legacy Type
okta.severityCHARBUFSeverity
okta.messageCHARBUFMessage
okta.publishedCHARBUFEvent Source Timestamp
okta.actor.idCHARBUFActor ID
okta.actor.TypeCHARBUFActor Type
okta.actor.alternateidCHARBUFActor Alternate ID
okta.actor.nameCHARBUFActor Display Name
okta.client.zoneCHARBUFClient Zone
okta.client.ipCHARBUFClient IP Address
okta.client.deviceCHARBUFClient Device
okta.client.idCHARBUFClient ID
okta.client.geo.cityCHARBUFClient Geographical City
okta.client.geo.stateCHARBUFClient Geographical State
okta.client.geo.countryCHARBUFClient Geographical Country
okta.client.geo.postalcodeCHARBUFClient Geographical Postal Code
okta.client.geo.latCHARBUFClient Geographical Latitude
okta.client.geo.lonCHARBUFClient Geographical Longitude
okta.useragent.osCHARBUFUseragent OS
okta.useragent.browserCHARBUFUseragent Browser
okta.useragent.rawCHARBUFRaw Useragent
okta.resultCHARBUFOutcome Result
okta.reasonCHARBUFOutcome Reason
okta.transaction.idCHARBUFTransaction ID
okta.transaction.typeCHARBUFTransaction Type
okta.requesturiCHARBUFRequest URI
okta.principal.idCHARBUFPrincipal ID
okta.principal.alternateidCHARBUFPrincipal Alternate ID
okta.principal.typeCHARBUFPrincipal Type
okta.principal.nameCHARBUFPrincipal Name
okta.authentication.stepCHARBUFAuthentication Step
okta.authentication.sessionidCHARBUFExternal Session ID
okta.security.asnumberUINT64Security AS Number
okta.security.asorgCHARBUFSecurity AS Org
okta.security.ispCHARBUFSecurity ISP
okta.security.domainCHARBUFSecurity Domain
okta.target.user.idCHARBUFTarget User ID
okta.target.user.alternateidCHARBUFTarget User Alternate ID
okta.target.user.nameCHARBUFTarget User Name
okta.target.group.idCHARBUFTarget Group ID
okta.target.group.alternateidCHARBUFTarget Group Alternate ID
okta.target.group.nameCHARBUFTarget Group Name