JIMMY WARNERNETWORK / LOG WORKSPACE

FROM SIGNAL TO UNDERSTANDING

Investigate with evidence.

Upload a log export. Review authentication patterns. Decide where to look next.

BROWSER PROCESSING

This prototype uses two explainable authentication rules. Findings are prompts for review; they do not establish a breach. No AI model or live monitoring is connected.

Start with your security logs

Drop one file here, or choose a file. JSON, JSONL, NDJSON or CSV · up to 5 MiB / 10,000 rows

No file selected. The sample contains invented events and documentation-only IP addresses.

A FOCUSED FIRST STEP

See the sequence.
Understand the signal.

Identify failure bursts and successful logins following repeated failures. Each finding links back to the events that triggered it.

Explainable rules Evidence timelines JSON report export
Supported format and detection rules

Prepare a log export

Use a JSON array, an object with an events array, one JSON object per line, or a CSV with a header row. Timestamps must include an explicit timezone, such as 2026-10-04T09:00:00Z. Events with invalid fields are skipped and listed above.

timestamp,action,outcome,user,source_ip,host,message
2026-10-04T09:00:00Z,login,failure,alex,192.0.2.10,app-01,Invalid credentials

The canonical fields are timestamp, action, outcome, user, source_ip, host and message. An explicit authentication action is required for detection; other valid events remain visible.

Two rules, clear limits

  • At least five authentication failures from one IP address within five minutes.
  • At least three authentication failures followed by a success for the same account and IP within ten minutes.

Duplicate normalized events are removed before analysis. This version does not detect all threats, infer missing timezones, connect to your environment, or send selected log contents to a server.