Update rules/okta_rules.yaml

Signed-off-by: darryk10 <stefano.chierici@sysdig.com>
Co-authored-by: Thomas Labarussias <issif+github@gadz.org>
This commit is contained in:
schie
2022-03-23 17:03:11 +01:00
committed by poiana
parent 6a1492a828
commit 48041a517b

View File

@@ -26,7 +26,7 @@
- rule: User accessing app via single sign on OKTA - rule: User accessing app via single sign on OKTA
desc: Detect a user accessing an app via OKTA desc: Detect a user accessing an app via OKTA
condition: okta.evt.type = "user.authentication.sso" condition: okta.evt.type = "user.authentication.sso"
output: "A user has accessed and app using OKTA (user=%okta.actor.name, app=%okta.app)" output: "A user has accessed an app using OKTA (user=%okta.actor.name, app=%okta.app)"
priority: NOTICE priority: NOTICE
source: okta source: okta
tags: [okta] tags: [okta]