User Audit Logs
LoginRadius records every meaningful action in your tenant — sign-ins, configuration changes, API calls, and access events — into searchable, exportable audit-log streams. Use them for forensics, compliance reports, and to feed your SIEM.
Access: Admin Console → Users → User Audit Logs. If the feature is not enabled on your tenant, contact support@loginradius.com.
Use cases
User Audit Logs give you a record of end-user activity you can act on. Common ways teams put it to work:
Cybersecurity incident detection
Alert on abnormal traffic to catch attacks early: a spike in API rate (DDoS), a surge of failed sign-in calls (brute force and credential stuffing), or a burst of account-delete calls (account takeover). Block the source before it reaches your users.
Regulatory compliance
Each call records the timestamp, user ID, and IP, the audit trail that ISO, SOC 2, HIPAA, and GDPR require, plus a defensible sequence of events in any dispute.
Data versioning
Every profile change is versioned per UID and retained, so you can answer consumer data-access requests and show exactly what changed and when.
Business intelligence
Chart authentication trends by device, location, and time. A spike in Forgot Password calls, for example, signals that Passwordless or OTP login would reduce friction.
Troubleshooting
Trace a user's API calls and their responses to pinpoint failures after a release or a bad integration.
What gets logged
User Audit Logs record end-user activity against your tenant. Each entry captures who the actor was, the API that ran, the resource affected, the response status, and the exact time.
- Sign-ins: credential, social, SSO, and Passwordless authentication attempts.
- Registrations: new account creation and verification.
- Profile changes: updates to end-user profile data.
- Session events: token issuance, refresh, and sign-out.
- MFA events: enrollment and verification.
- Account protection: password resets, email and phone changes, blocks, and failed-attempt lockouts.
- Consent and privacy: consent grants, policy acceptance, and account deletion.
Use the logs to trace a specific user's activity, investigate a failed sign-in, resolve a support ticket, and review end-user security events.
Retention: User Audit Logs are kept for 7 days. The view shows activity from the last 7 days only.
Column reference
Actor Type
Event
Target
Status Code
/authorize endpoint.Filtering & searching
Filters
Search by UID
Date Range
contains, equal, not equals) and a value. Click the + to add another rule — rules are combined with AND.Examples
Find every failed sign-in for one user
- Open the User Audit Logs view.
- Click Search by UID and paste the actor's UID — e.g.
a4f9c1…7b2d09. - Add filter:
Event · equal · login. - Add filter:
Status Code · equal · 401. - Apply. The table now lists only failed sign-ins for that user.
Exporting logs
Click the Export button at the top right of the table to download the filtered result as a CSV — up to 10,000 rows per export. The file reflects the active filters and date range, so what you see is what you get.