heroui logo

Signal - Notion Login

Panther Rules

View Source
Summary
The Notion.Login rule is designed to track user login events in Notion through monitoring the Notion Audit Logs. When a user logs into the Notion platform, an event is logged that contains relevant details such as the actor's ID, email, IP address, timestamp of the event, and the type of event which is specified as 'user.login'. The rule is set up to validate a successful login by checking for the occurrence of this specific event type. There is a defined threshold of 1, indicating that if such an event occurs, it would be processed without generating an alert since `CreateAlert` is set to false. Furthermore, the `DedupPeriodMinutes` is set to 60, ensuring that subsequent identical events do not flood the logs or appear too frequently during this time period. The rule primarily serves for monitoring purposes and is categorized under the tags 'Notion' and 'Identity & Access Management'.
Categories
  • Cloud
  • Web
  • Identity Management
Data Sources
  • User Account
  • Application Log
  • Logon Session
Created: 2024-09-16