Skip to main content

Investigating - Login Analyzer

Updated over 3 months ago

This guide will walk you through the process of investigating login events using the login analyzer tool.


STEP ONE:

Sign into your Cloud Access Monitor instance.


STEP TWO:

Navigate to the Audit & Control page, and select the Name of your desired Cloud Environment. (Global Views will show all accounts in your domain, while filtered views will show only users for that view)


STEP THREE:

Navigate to the Accounts tab, and select the "Login Analyzer" subtab above the search bar.

Screenshot_2023-01-27_121924.png

STEP FOUR:

By default the tool will show all login data in the results table. You can use as many of the filtering parameters at the top of the page as you'd like to search through and filter the data.

mceclip0.png
  • Note: Username formats containing "#." can cause blank search results. Please search using partial inputs on the "User" field if results are blank after using full username.

  • Example: "[email protected]" should be partial searched as "lastname2023"


STEP FIVE:

To see more information, click the "Event Type" on the far right of the row.

mceclip6.png
  • A popup will appear showing the location on a map, as well as all other information about the login event.

mceclip5.png

STEP SIX:

Clicking the globe icon from the "Actions" column will evaluate if the IP is associated with a VPN service.

mceclip0.png
  • A new tab will open providing full details around the IP in question. These details outline any suspected VPN abnormalities.

mceclip1.png
mceclip2.png
Did this answer your question?