9% of the exam — the smallest of the first four domains.
3 sub-topics · this deck covers sub-topic 1 of 3
↑ Module 1 OverviewEvery action in Okta leaves a trace. This sub-topic is about where that trace lives and what it actually captures.
The System Log records "details of all logged events for your org" — time, actor, target, and event type. Sensitive values like clientSecret are hashed before being logged.
Location: Admin Console > Reports > System Log.
By default, filters show all events for the last 7 days.
Beyond basic viewing: drag across the graph to expand a time range, click a row's arrow for full event detail, download as CSV, toggle between the table and a geolocation map view, jump to the Rate Limit Dashboard straight from a violation event, and track MFA abandonment metrics.
Watch for scenario questions built around this trap:
→ "An admin needs to export System Log data for an external audit." = CSV download, directly from the System Log view.
Sources: help.okta.com — Reports_SysLog.htm
Next: Sub 2 →