The SIEM app is now a part of the Elastic Security solution.
Click
here to view SIEM documentation for previous releases.
Threat Detected by Okta ThreatInsight
edit
IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.
Threat Detected by Okta ThreatInsight
editThis rule detects when Okta ThreatInsight identifies a request from a malicious IP address. Investigating requests from IP addresses identified as malicious by Okta ThreatInsight can help security teams monitor for and respond to credential-based attacks against their organization, such as brute-force and password-spraying attacks.
Rule type: query
Rule indices:
- filebeat-*
Severity: medium
Risk score: 47
Runs every: 5 minutes
Searches indices from: now-6m (Date Math format, see also Additional look-back time
)
Maximum alerts per execution: 100
References:
Tags:
- Elastic
- Okta
- SecOps
- Monitoring
- Continuous Monitoring
Version: 1
Added (Elastic Stack release): 7.9.0
Rule authors: Elastic
Rule license: Elastic License
Investigation guide
editThe Okta Filebeat module must be enabled to use this rule.
Rule query
editevent.module:okta and event.dataset:okta.system and event.action:security.threat.detected