Skip to main content
Auth0 log streams deliver tenant logs in near real time to a custom webhook. Set the webhook’s Payload URL to your Flashduty push URL to send security-relevant tenant logs to Flashduty On-call: leaked password logins (pwd_leak), attack protection blocks (limit_wc, limit_mu, and others), failed logins and signups (f, fu, fp, fs, and others), MFA failures, and API rate limits. Successful logins, successful management operations, and other non-security logs do not create alerts.

In Flashduty On-call


You can get the integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channel and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Auth0 and click Save
  4. Open the new integration card and copy the Push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select Auth0 and enter an integration name
  3. Configure the default route and select a channel. You can add more rules under Routes after creation
  4. Click Save and copy the generated Push URL

In Auth0


1

Create the log stream

  1. Log in to the Auth0 Dashboard and go to Monitoring → Log Streams
  2. Click Create Log Stream, select Custom Webhook, and enter a name
  3. Fill in the following settings:
  1. Under Filter by Log Event Category, select only the error and warning categories to reduce volume. Leaving it unfiltered also works, because Flashduty ignores success logs
  2. Click Save
The Payload URL must be an HTTPS address with a certificate from a trusted authority. Auth0 does not support self-signed certificates.
2

Trigger and verify

  1. Open the stream’s Health tab in Monitoring → Log Streams and confirm the status is Active
  2. Log in to a test application with a wrong password to produce an fp (wrong password) log
  3. Confirm the alert arrives in Flashduty. If it does not, check the log stream delivery errors under Monitoring → Logs in Auth0
Auth0 log streams have no “send test notification” button.

Events and recovery


Auth0 sends each tenant log once and never sends an update or a recovery. Each log has a unique log_id, which Flashduty uses as the Alert Key. A retried delivery of the same log does not create a duplicate alert, and different logs each create their own Flashduty alert. Alerts do not recover automatically. Turn on the channel’s auto-resolve timeout (24 hours suggested), or close alerts by hand after handling them. When the same source IP triggers many logs, configure a noise-reduction rule on the channel to merge them into one incident.

Alert Key


The Alert Key is computed from the log’s log_id. An alertable log without log_id is rejected with an invalid-parameter error.

Severity


Severity follows the log type code (type); logs with any other type code are ignored: For the full list of type codes, see Auth0 log event type codes.

Labels


The alert description comes from the log’s description and details.error.message. Flashduty does not read the user’s email, the User-Agent, or other fields.

Troubleshooting


  • Flashduty returns an invalid-parameter error: confirm Content Type is application/json and check the integration_key in the Payload URL
  • No alert arrives: confirm the log type is in the table above, the Health tab shows Active, and the stream’s event category filter does not exclude that type
  • Too many alerts: narrow the categories under Filter by Log Event Category and configure a noise-reduction rule on the channel
  • Alerts never close: Auth0 sends no recovery, so turn on the channel’s auto-resolve timeout
For more settings, see the Auth0 documentation on custom webhook log streams.