detect_login_loops
Scan Keycloak LOGIN events to identify users exceeding a login threshold within a set time window, flagging possible redirect loops.
Instructions
Detect users with rapid repeated logins (possible redirect loops).
Scans all LOGIN events and finds users who logged in more than threshold
times within window_seconds.
Time-bounded: this call stops after KEYCLOAK_DEADLINE seconds (default 45) and returns what it has; the counts are then a lower bound. The result then starts with a "PARTIAL RESULT" warning. Call again with a narrower window instead of retrying the same call. A wide window on a busy day is what triggers it.
Args: date_from: Start date (YYYY-MM-DD). Defaults to last 24h when omitted (KEYCLOAK_DEFAULT_DATE_FROM_HOURS). date_to: End date (YYYY-MM-DD). Empty for all. threshold: Minimum logins within the window to flag (default 10). window_seconds: Time window in seconds (default 60). top: Number of top users to show (default 20). Use 0 for all.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | ||
| date_to | No | ||
| date_from | No | ||
| threshold | No | ||
| window_seconds | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |