Anomalous amount of failed sign-in attempts by 1Password user

Set up the 1password integration.


Detect failed sign-in attempts from a 1Password user.


This rule monitors 1Password logs to identify when an user generates an anomalous amount of failed sign-in events.

Triage and response

Investigate and determine if user {{}} with failed sign-in events {{@evt.outcome}}, attempting to authenticate from IP address {{@network.client.ip}} should have access.


Updated query by replacing @evt.category:*failed* with @evt.outcome:*failed*.