Lidar is Authdog's identity SIEM. Open it from the sidebar (/dashboard/security). Search the auth stream, correlate detections, and triage Signals for the selected environment. For the model, see Lidar concepts. Optional notification channels copy events to another SIEM if you already run one.
Lidar is gated. Request access on Overview. Until approved, detection panels stay locked.
What you do here
- Enable the environment. Wait for approval.
- Monitors — turn detectors on, edit the
detection:<id>query, set severity. - Signals — triage live findings by user, IP, type, and time.
- Scan Logs / Dashboards — confirm analysis is running and see severity over time.
Default monitors cover brute force, credential stuffing, impossible travel, MFA fatigue, bots, breached passwords, and related abuse. Disabled monitors produce no new Signals.
Use Generate events in dev to exercise the pipeline, then Clear synthetics.
Limits
- A selected environment is required.
- Access must be approved before protection is active.
- Breached-password policy in Authentication is a separate control.
Related
| Read | To learn how to |
|---|---|
| Lidar concepts | How monitors become Signals |
| Recipes | Pair Lidar with bot protection |
| Events & webhooks | Optional export to another SIEM |