
Summary
The rule 'OpenAI Failed Login (Base Rule)' is designed to detect failed login attempts within the OpenAI environment. It serves as a foundational rule for building more complex correlation rules rather than triggering alerts independently. The primary function is to log when a user fails to authenticate, specifically tracking errors related to invalid login credentials. The rule does not have any alerting capabilities on its own and operates under an information severity level. It processes logs of type 'OpenAI.Audit' and deduplicates findings within a 60-minute window to reduce repetitive alerts. The rule is capable of recognizing failed login events while ignoring successful logins, thus enabling related rules that might subsequently react to patterns indicating unauthorized access attempts.
Categories
- Cloud
- Identity Management
- Web
Data Sources
- User Account
- Application Log
Created: 2026-01-13