- 12 Jul 2022
- 3 Minutes to read
On-Prem Okta Authentication with Group Sync
- Updated on 12 Jul 2022
- 3 Minutes to read
Graylog provides Okta single sign-on (SSO) for your organization. In addition to Active Directory and LDAP, Graylog administrators can synchronize Okta group members to teams in Graylog. If you are using Okta and have already authenticated yourself on the external Okta site, Graylog can use the same session and will not prompt you to re-authenticate. However, this requires the use of third-party cookies, which are typically disabled in modern browsers. Be sure to enable third-party cookies in your browser settings to avoid re-authentication.
In order to start the Graylog connection, you need to create the OIDC application that you want to authenticate on Graylog. Make sure both the Okta developer console and the Graylog UI are accessible. Perform the following steps.
Graylog UI Server
- Login to Graylog.
- Navigate to the Authentication submenu in System.
- Select Okta from the dropdown, found on the Create New Authentication Service menu.
- Click the Get Started button, which takes you to a form required to configure the Okta service.
- Fill out the form with corresponding values, which helps you create the service:
|Title||Name the service.|
|Description||(Optional) Add a description.|
|Okta Base URL||Add the root URL of the Okta client, e.g.
|Callback URL||Enter your Graylog URL that Okta redirects back to after authentication. It could be the base URL of your Okta environment or a custom server configured for Okta sessions.|
- Navigate to the Okta console to configure the application(s) you want to use to authenticate Graylog via Okta.
Okta developer console
- Log into your Okta admin dashboard.
- Click on Applications under Applications on the left menu
- Click on Create App Integration; this prompts you to a modal called Create a new app integration.
- Select the OIDC - OpenID Connect radio button from the modal
- Select Web Application and click Next.
- Enter a name in the App Integration Name field, on the New Web App Integration form.
- Ensure the following are selected:
- Client Credentials
- Authorization Code
- Refresh Token
- Add your callback URL (obtained from Graylog when creating the authentication service).
- Under assignments, ensure that you select the appropriate access, i.e. the Allow everyone in your organization radio button.
- Click Save, to take you back to the Applications page.
- Save the Client ID and Client secret. (These values are needed to complete the Okta authentication form in Graylog.)
Graylog UI Server Configuration
- Navigate to the Create Okta Authentication Service form.
- Finish the Server Configuration form:
|Field Name||Entry / Action|
|OAuth Client ID||Pass the secret value from the Applications section (Okta).|
|OAuth Client Secret||Enter the password associated with this Client ID, from the Applications section (Okta).|
|Token Verifier Connect Timeout||Determine the time interval in seconds, till connection reset.|
|Default Roles||Determine the roles you want to delegate through this 3rd party Okta session.|
- Click Test Server Connection to validate the configuration.
In this section, make sure you still have access to Okta and the Graylog UI.
- Navigate to the Okta dashboard.
- Click API under Security in the left menu.
- Click the Token tab.
- Click the Create Token button to generate the Create Token modal.
- Enter a name in the field What do you want your token to be named?.
- Click the Create Token button to generate the token string (Token Value).
- Click the copy/paste button or save the token string for the Graylog Group Synchronization tab.
**Graylog UI **
On the Group Synchronization tab, perform the following:
- Click Next: Group Synchronization, which takes you to the next tab: Group Synchronization (Optional).
- Check the Synchronize Groups box to Enable Group Synchronization.
- Copy the token string into the Okta API Token field.
- Click the Load matching groups button. This will port the full list of group members from Okta.
- Select from either All groups, Include selected, Exclude selected in Select groups to import. This depends on the members chosen (or excluded) from the imported groups mentioned in Step 4.
- Click the Finish & Save Service button to complete the configuration steps. This takes you to the All Authentication Services pane.
- Click Activate the start the new authentication service you configured in this guide.
A new log-in page appears when you log out to start a new session with Okta in place. To get to this screen:
- Log out of Graylog. You will notice a login page with the text Login with default method.
- Log back in to Graylog under you Okta credentials to authenticate as new delegated Okta group member.