OneLogin: Detect API user account lock or suspension events

Flags OneLogin API events indicating a user account was locked or suspended.

FreeReviewedSigma · Low · v4
Product
onelogin
Service
onelogin.events
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-10-12
Updated
2026-07-31

What it detects

This rule flags OneLogin events where a user account is locked or suspended via API actions. Account state changes can indicate account disruption attempts or administrative enforcement, so tracking these transitions helps investigators assess impact. It relies on OneLogin event telemetry containing specific event_type_id values for locked and suspended states.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.