↳ GitHub sourceConnector

OneLogin IAM Platform (via Codeless Connector Framework)

Description

The [OneLogin](https://www.onelogin.com/) data connector provides the capability to ingest common OneLogin IAM Platform events into Microsoft Sentinel through REST API by using OneLogin [Events API](https://developers.onelogin.com/api-docs/1/events/get-events) and OneLogin [Users API](https://developers.onelogin.com/api-docs/1/users/get-users). The connector provides ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
OneLogin IAM API Credentials
To create API Credentials follow the document link provided here, [Click Here](https://developers.onelogin.com/api-docs/1/getting-started/working-with-api-credentials). 
 Make sure to have an account type of either account owner or administrator to create the API credentials. 
 Once you create the API Credentials you get your Client ID and Client Secret.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

To ingest data from OneLogin IAM to Microsoft Sentinel, you have to click on Add Domain button below then you get a pop up to fill the details, provide the required information and click on Connect. You can see the domain endpoints connected in the grid. >
Add domain
Add domain
OneLogin Domain
For example, if your OneLogin Domain is test.onelogin.com, you need to enter only test in the above field.
Client ID
Client Secret
Connect OneLogin IAM Platform to Microsoft Sentinel

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
OneLoginIAMLogsCCPDefinition
Additional source files 2Solutions/OneLoginIAM/Data Connectors/OneLoginIAMLogs_ccp/OneLoginIAMLogs_ConnectorDefinition.jsonsource ↗Solutions/OneLoginIAM/Data/Solution_OneLoginIAM.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.