Okta blocked numerous requests from a malicious IP
Set up the okta integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when a request is blocked due to a block list rule (such as an IP network zone or location rule).
Strategy
This rule lets you monitor the following Okta events to detect when a malicious IP address communicates with your Okta account:
Triage & Response
- Verify with the owner of
{{@usr.name}}
that they were attempting a request to {{@target_app}}
. - If the request cannot be verified with the user, correlate with other log sources to see if the blocked IP in the
title
of {{@title}}
has communicated elsewhere on the network.