Authdog

Lidar

Last updated Sep 3, 2026
View as Markdown

Lidar is Authdog's identity SIEM. Open it from the sidebar (/dashboard/security). Search the auth stream, correlate detections, and triage Signals for the selected environment. For the model, see Lidar concepts. Optional notification channels copy events to another SIEM if you already run one.

Lidar is gated. Request access on Overview. Until approved, detection panels stay locked.

What you do here

  1. Enable the environment. Wait for approval.
  2. Monitors — turn detectors on, edit the detection:<id> query, set severity.
  3. Signals — triage live findings by user, IP, type, and time.
  4. Scan Logs / Dashboards — confirm analysis is running and see severity over time.

Default monitors cover brute force, credential stuffing, impossible travel, MFA fatigue, bots, breached passwords, and related abuse. Disabled monitors produce no new Signals.

Use Generate events in dev to exercise the pipeline, then Clear synthetics.

Limits

  • A selected environment is required.
  • Access must be approved before protection is active.
  • Breached-password policy in Authentication is a separate control.
Read To learn how to
Lidar concepts How monitors become Signals
Recipes Pair Lidar with bot protection
Events & webhooks Optional export to another SIEM

Learn more