login_audit
Audit login logs to identify Google-auto-disabled accounts, suspicious logins, and top login failures. Customize the analysis by time window and domain.
Instructions
Audit the login log: Google-auto-disabled accounts, suspicious logins, failure top-N.
account_disabled_* events are how Google reports that IT locked an account
(leaked password, hijacking, spamming). Combine with a Directory
suspended-users snapshot (Phase 2) for current state. Each section carries
capped (window not fully scanned) — treat counts as lower bounds then.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | ||
| hours | No | ||
| domain | No | ||
| include_failures | No |