All templates

Automated Ping Identity Failed Login Alerts

Every hour, WebRun opens Ping Identity, checks failed login attempts across your applications for spikes against a single account, logs any spike in a Google Sheet with the account and attempt count, and emails your security team the moment one crosses your threshold.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Ping Identity check failed login attempts
2 Google Sheets log the spike
3 Gmail email your security team
In short

How do I get alerted the moment failed logins spike on Ping Identity?

WebRun checks Ping Identity every hour for failed login attempts that spike against a single account, logs the account and attempt count in a Google Sheet, and emails your security team the moment a spike crosses your threshold. It never locks an account or blocks an IP itself, leaving that decision to your team.

  • Failed login spikes get an email alert within the hour they happen
  • Every spike has a logged record for later investigation
  • Routine, low-volume failures produce no alert at all

Built for security teams · IT admins · identity administrators · SaaS companies

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.pingidentity.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Ping Identity - check failed login attempts
    pingidentity.com
    WebRun in Ping Identity: check failed login attempts
    WebRun opens Ping Identity to check failed login attempts.
    • Open Ping Identity and check failed login attempts from the past hour
    • Group failed attempts by account and source IP
    • Flag any account with failed attempts above your normal threshold

    Done when This hour's failed logins have been checked against threshold.

  3. 2
    Google Sheets - log the spike
    google.com
    WebRun in Google Sheets: log the spike
    WebRun opens Google Sheets to log the spike.
    • Open the failed login log sheet
    • Add a row for each flagged account with attempt count and source IP
    • Keep prior hours' rows so patterns are easy to compare

    Done when This hour's flagged spike, if any, is logged in the sheet.

  4. 3
    Gmail - email your security team
    gmail.com
    WebRun in Gmail: email your security team
    WebRun opens Gmail to email your security team.
    • Send an email to the security team the moment an account crosses threshold
    • Name the account, the attempt count, and the source IP
    • Stay quiet when no account crosses threshold this hour

    Done when Any spike this hour has triggered a security team email.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.pingidentity.com
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Failed login alert · Gmail
OutputWhat each run produces - An hourly check of Ping Identity failed logins, with a logged spike and an email alert only when threshold is crossed.
Alert
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does WebRun lock the account or block the IP itself?

No. WebRun only reports the spike. Locking an account, blocking an IP, or resetting a credential is left for your security team to decide and do.

Will I get an email for a single failed login?

No. It only emails when failed attempts on one account cross your set threshold within the hour, not for one or two routine misses.

Does WebRun ever see or store a password?

No. It reads only Ping Identity's failed attempt counts and account names. It never sees, types, or stores the password being entered.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.