Prioritized Log Streams is a Dashboard feature that highlights security events. In the event of an attack or otherwise increased user activity, Prioritized Log Streams and predefined events will remain active so downstream security automation and processes aren’t impacted. You can create a new prioritized log stream using a supported service or configure a custom webhook to stream to a service you already use, and all logs can be exported to an event analysis service. Prioritized Log streams do not count towards the log stream limit depicted in the pricing plan.

Configure a Prioritized Log Stream

  1. Follow the instructions on the Log Streams page to set up a new log stream.
  2. While configuring the new stream, go to the Settings tab on your Auth0 Dashboard and select the Prioritized Log checkbox to activate the predefined security events detailed below. Choose Save.
  3. Go to your Stream page and navigate to the Prioritized label.

Prioritized Logs Event Types

The following event codes are classified by Auth0 as security-related events:
Event CodeEvent
limit_muBlocked IP Address
limit_sulBlocked Account (IP Throttling)
limit_wcBlocked Account (Brute Force Protection)
pwd_leakBreached password on Login
ublkduUser login block released
signup_pwd_leakBreached Password on Signup
reset_pwd_leakBreached Password on Reset
gd_send_smsMFA SMS Sent