Auth0 Logs (Beta)

Panther supports receiving Auth0 logs directly via webhook

Overview

Auth0 log ingestion is in open beta starting with Panther version 1.73. Please share any bug reports and feature requests with your Panther support team.

Panther ingests Auth0 tenant logs by configuring Auth0's log streaming service to post events to a Panther HTTP source.

How to onboard Auth0 logs to Panther

Step 1: Create a new Auth0 source in Panther

  1. In the left-side navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Auth0,” then click its tile.

    • In the slide-out panel, the Transport Mechanism dropdown in the upper-right corner will be pre-populated with the HTTP option.

  4. Click Start Setup. The Auth0 log source setup page is shown, in the Panther Console. In the upper-right corner, the Transport Mechanism dropdown has a value of "HTTP," and to its right is a Start Setup button. Both are circled.

  5. Follow Panther's instructions for configuring an HTTP Source.

    • You will be required to use bearer authentication. This is the only method of authentication Auth0 supports.

Step 2: Create a new Log Stream in Auth0

  1. Log in to your Auth0 tenant.

  2. From the dashboard, navigate to Monitoring > Streams.

  3. Click Create Stream.

  4. Select Custom Webhook.

  5. Give your Event Stream a descriptive name, e.g., Panther Log Stream.

  6. In the Payload URL field, paste the URL for the Auth0 HTTP source in Panther you generated in the previous step of this process.

  7. In the Authorization Token field, enter the bearer token you used when setting up the Auth0 source in Panther, in the previous step of this process.

    • Enter this value in the form Bearer <token value>.

  8. Click Save.

Panther-managed detections

See Panther-managed rules for Auth0 in the panther-analysis GitHub repository.

Supported log types

Required fields in the schema are listed as "required: true"

Auth0.Events

Auth0.Events are event logs from the Auth0 log stream. For more information, see Auth0's documentation on tenant log events.

Last updated

Was this helpful?