daily_brief
Run a morning Keycloak health check to detect anomalies: failed logins, active sessions, password updates, admin events, and flag brute-force or credential-spraying attacks.
Instructions
Run a morning Keycloak health check.
Checks (all scoped to the last since_hours hours):
Login statistics (success / failure totals, top failing IPs)
Active sessions by client
Password update events
Admin events (CREATE/UPDATE/DELETE on USER/CLIENT resources)
A single IP with login failures >= ip_failure_threshold is flagged
as WARNING (possible brute-force). Independently, the same login events
are run through the spray_check rule (external IP, >= 10 distinct
users, success rate < 20%); a match is a [SPRAY] WARNING and the
"Spray check" section lists the breached accounts with their evidence
tuples (time / ip / username / client). Only accounts in that list may be
called breached — see spray_check for the full row shape and to widen
the window or tune the thresholds.
since_hours defaults to 18 (≈ previous 15:00 for a 09:00 morning run).
Output tiers:
CRITICAL — API connection failure
WARNING — anomalies detected
OK — clean
Args: since_hours: Look-back window in hours (default 18). ip_failure_threshold: Login failures from a single IP that triggers a WARNING (default 50).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| since_hours | No | ||
| ip_failure_threshold | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |