↳ GitHub sourceConnector

Auth0 Logs (via Codeless Connector Framework)

Description

The [Auth0](https://auth0.com/docs/api/management/v2/logs/get-logs) data connector ingests tenant log events from the Auth0 Management API into Microsoft Sentinel. Built on the Codeless Connector Framework, it supports connecting multiple Auth0 hosts and tags each record with its Auth0 domain.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Auth0 API credentials
**Auth0 Management API** credentials are required: Domain, Client ID, and Client Secret from a Machine-to-Machine application authorized for `read:logs` and `read:logs_users`.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Configure the Auth0 Management API application
Follow these steps to obtain the credentials: 1. In the Auth0 Dashboard, go to **Applications > Applications**. 2. Select (or create) a **Machine-to-Machine** application authorized against the Auth0 Management API with at least the **read:logs** and **read:logs_users** permissions. 3. From the application settings, copy the **Domain** (it must start with `https://`), **Client ID**, and **Client Secret**. To collect logs from multiple Auth0 hosts, add a separate connection for each host. Every record is tagged with its **Auth0Domain** so you can differentiate hosts.
Add Auth0 host
Add Auth0 Connection
Domain
Client ID
Client Secret
Create a separate connection for each Auth0 host you want to collect logs from.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
Auth0ConnectorCCPDefinition
Additional source files 2Solutions/Auth0/Data Connectors/Auth0_CCP/DataConnectorDefinition.jsonsource ↗Solutions/Auth0/Data/Solution_Auth0.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.