Issues and alerts
Security monitoring
Report sign-in attempts and Blipit turns bursts and unusual locations into security issues with their own alerts. Sending is covered under Login attempts; Odoo does it for you once login monitoring is ticked. This page explains the rules.
1Thresholds
Alerts, Security thresholds, per project or for the whole workspace. Defaults, all in a 10-minute window: 5 failed logins, 1 blocked login, 10 password reset requests, 1 privilege granted. Successful logins have no count threshold; they feed the new-IP and new-country checks. Thresholds go up to 1,000 and windows up to 1,440 minutes, and each kind can be turned off. Only owners and admins can change this; members can see it.
2What raises an issue
By actor: the same login name crosses the threshold within the window (brute force on one account). By IP: one address crosses it across more than one account (spraying). New IP: a known actor signs in successfully from an address never seen for them. New country: the same, for a country never seen for them; the first country ever seen is the baseline and never alerts, and a login that is both a new IP and a new country alerts once, as a new country.
3Alerts
One security alert per issue per window, sent to your email rules, Slack, Teams and webhooks, or to the owners when you have none. Snooze does not apply. Security events always keep their full payload.
Good to know
- Security events must be sent with the secret key; the public key gets 403 security_needs_secret_key, so a visitor cannot poison the baseline of known addresses.
- On a plan without security monitoring, ingest answers 403 security_monitoring_not_in_plan and the Odoo module pauses login reports for ten minutes.
- The Security page lists the security issues of the workspace; the country comes from the IP.
Stuck? Email support@blipit.io. Keys and the exact DSN for each project are under API keys in app.blipit.io.

Sign in