event
field to view tenant traffic data. We recommend building a daily histogram of failure events of the following types:
Event Code | Event |
---|---|
f | Failed login |
fcoa | Failed cross-origin authentication |
feccft | Failed exchange |
fepft | Failed exchange |
fsa | Failed silent authentication |
fu | Failed login (invalid email/username) |
pla | Pre-login assessment |
sepft | Success exchange |
fu
which is a failed username (typical of a credential stuffing attack).
Event Code | Event |
---|---|
s | Login success |
fu | Failed login, invalid email/username |
fp | Failed login, incorrect password |
Event Code | Event |
---|---|
limit_mu | Blocked IP address |
limit_wc | Blocked account |
pwd_leak | Breached password during login |
signup_pwd_leak | Breached password during signup |
reset_pwd_leak | Breached password during password recovery |
ip
address data in conjunction with fu
event traffic to determine where the failure traffic is coming from.
IP geolocation data isn’t available in the tenant logs unless you’re able to enrich it from another location. The IP locale is only available from Kibana where the logs are already enriched with the information.
Here’s an example of what the data might look like: