Configure OneLogin for Arctic Wolf monitoring

You can configure OneLogin® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • Access to the OneLogin admin portal with administrator permissions

Create new API credentials

  1. Sign in to the OneLogin admin portal with the format your_instance.onelogin.com.
  2. In the navigation menu, click Developers > API Credentials.
  3. Click New Credential.
  4. In the Create new API credential dialog, configure these settings:
    • Name — Enter a unique and descriptive name.
    • Read all — Select the checkbox.
  5. Click Done.
  6. Copy the Client ID and Client Secret values to a safe, encrypted location.
    You will provide them to Arctic Wolf later.

Provide OneLogin credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. ナビゲーションメニューで、[データ収集] > [クラウドセンサ]をクリックします。
  3. Click Add Account +.
  4. On the Add Account page, click OneLogin.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • Subdomain — Enter the subdomain from your OneLogin URL. For example, https://subdomain.onelogin.com.
    • Client ID — Enter the client ID from Create new API credentials.
    • Client Secret — Enter the client secret from Create new API credentials.
    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.