OneLogin Logs

Panther supports pulling logs directly from OneLogin

Overview

Panther supports ingesting OneLogin logs via OneLogin's integration with Amazon EventBridge. This allows Panther to process OneLogin logs in a scalable, reliable, and low latency manner.

In order for Panther to process your OneLogin logs, you need to configure your OneLogin account to send data to Amazon EventBridge in your Panther Amazon Web Services (AWS) account.

How to onboard OneLogin logs to Panther

Configure OneLogin to send data to Panther

Note: Keep track of the AWS Account ID and AWS Region where your instance of Panther is deployed. You can find this information in your Panther Console under Settings > General in the footer of the page.

  1. In your OneLogin administrative console, go to Developers > Webhooks.

  2. Go to New Webhook > Event Webhook for Amazon EventBridge.

  3. Add a descriptive name. For example: Panther Integration

  4. Fill out the AWS Account ID and Region that you noted earlier and click Save.

  5. Click on the new integration that was just created. Keep note of the Event Source field, as it is used the next step.

    • It should be formatted aws.partner/onelogin.com/US-123456/ffffffffff.

Create a new OneLogin source in Panther

  1. In the left-hand navigation bar of the Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “OneLogin,” then click its tile.

  4. Click Start Setup.

  5. On the Configure Source page, fill in the following fields:

    • Name: A descriptive name for the source. For example: My OneLogin events

    • Log Types: Select OneLogin.Events

    • Bus Name: The field you noted in the previous text (formatted aws.partner/onelogin.com/US-123456/ffffffffff)

  6. Click Setup. You will be directed to a success screen:

    The success screen reads, "Everything looks good! Panther will now automatically pull & process logs from your account"
    • You can optionally enable one or more Detection Packs.

    • The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.

      The "Trigger an alert when no events are processed" toggle is set to YES. The "How long should Panther wait before it sends you an alert that no events have been processed" setting is set to 1 Day

Panther-managed detections

See Panther-managed rules for OneLogin in the panther-analysis GitHub repository.

Supported log types

Required fields in the schema are listed as "required: true" just below the "name" field.

OneLogin.Events

OneLogin provides single sign-on and identity management for organizations.

For more information, see the OneLogin Documentation on Event and Resource Types.

Last updated

Was this helpful?