Measure Security and audit-log analytics and check the results
To measure security and audit-log analytics, choose one workflow and its owner. Define the events, test them with known inputs, and write a query that answers a specific question.
- 1
Choose when to log
List where users authenticate and where privileged actions run.
- 2
Capture the outcome
Begin with authentication_completed, authorization_denied, privileged_action_completed and document the grain of each event.
- 3
Check the stored rows
Exercise denied, failed, successful, and suspicious paths before alerting.
- 4
Make the decision
Which login method has a sustained failure spike?
Agent prompt
Paste this into your coding agent
Replace YOUR_API_KEY after signup, then ask the agent to run the product flow and verify the first events.
Security and audit-log analytics setup prompt
Instrument security and audit-log workflows with Telemetry.
Use /skill.md and this Telemetry API key: YOUR_API_KEY
Log controlled authentication and authorization outcomes with event_id, actor_id, target_id, authentication_method, action, outcome, failure_reason, policy_version, session_id, ip_country when approved, environment, release, and timestamp_utc.
Create queries for authentication failure rate, affected identities, denied actions, policy changes, and an incident timeline. Document retention and access ownership.
Never log passwords, tokens, cookies, full IP addresses, authorization headers, recovery codes, or raw identity-provider payloads. Route suspicious behavior through the security response process rather than treating a generic product alert as an intrusion detector.Setup steps
- 1List where users authenticate and where privileged actions run.
- 2Define controlled outcomes and reasons with a security owner.
- 3Use privacy-safe actor and target identifiers with explicit retention.
- 4Exercise denied, failed, successful, and suspicious paths before alerting.
Events to capture
Questions you can answer
- Which login method has a sustained failure spike?
- How many distinct identities are affected?
- Which privileged actions occurred during an incident window?
Example event schemas
Event schemas for this workflow
Check what each event records, when to send it, and which field types it needs. Review the example payload and privacy checklist before using it in production.
Use these queries in Telemetry
Learn about Structured events
Send events with consistent names and field types. Choose which context to include before sending it.
Related SQL recipes
More SQL recipes
Run the query using this workflow's event fields and check the example result. Save the result to a dashboard or set up an alert.
Analyze authentication failure rate
Which authentication methods and failure reasons need investigation?
Open recipeDetect suspicious authentication bursts
Which authentication windows show concentrated failure activity?
Open recipeAnalyze access-policy denials
Which access policies deny the most actors and actions?
Open recipeAudit API-key lifecycle events
Which API-key lifecycles require owner review?
Open recipeReview sensitive data exports with SQL
Which sensitive export classes or actor roles require review?
Open recipeAudit privileged actions with SQL
Which privileged actions fail or require human review most often?
Open recipeNext step
Create the API key your agent will use
The free plan is enough to run the prompt, send test events, and review the first dashboard.
Related pages