ReEntra logoReEntraLocal only

Detection Settings

Rule thresholds

Adjust sliders to tune detection sensitivity — findings recompute live.

10

Trigger 'high failed count' finding when a single user exceeds this many failures.

20

Trigger a finding when a single source IP exceeds this many failures.

5

How many distinct accounts one IP must target inside the window.

60min

Time window in minutes for spray detection.

5

Spray is 'low-volume, wide' — cap attempts per user to distinguish from brute-force.

10

Failures against one user within the window to fire brute-force.

30min

Time window for brute-force detection.

800km/h

Minimum implied travel speed to flag as impossible.

500km

Ignore hops shorter than this — reduces noise from ISP hopping.

5min

Ignore back-to-back sign-ins closer than this.

22

Start of the 'off-hours' window used for off-hours findings and the timeline heatmap.

6

End of the off-hours window.

30days

Silence before a sign-in counts as a dormant account reactivation.

24h

How long a source IP must be silent before a burst is interesting.

15

Events within one hour after the quiet period to fire the finding.

Tenant timezone

Off-hours detection and the timeline heatmap use this offset instead of your browser timezone, so the same log file always produces the same findings.

Trusted / known entities
Rule muting

Muted rules still run but their findings are suppressed.

Settings are stored in your browser's localStorage. Findings are recomputed automatically when values change.