loading
Preparing LoginRadius developer resources
Mission: Help enterprises accelerate digital transformation with our fully-managed Customer IAM technology.
Skip to main content
Documentation

User Audit Logs

LoginRadius records every meaningful action in your tenant — sign-ins, configuration changes, API calls, and access events — into searchable, exportable audit-log streams. Use them for forensics, compliance reports, and to feed your SIEM.

Access: Admin Console → Users → User Audit Logs. If the feature is not enabled on your tenant, contact support@loginradius.com.


Use cases

User Audit Logs give you a record of end-user activity you can act on. Common ways teams put it to work:

Cybersecurity incident detection

Alert on abnormal traffic to catch attacks early: a spike in API rate (DDoS), a surge of failed sign-in calls (brute force and credential stuffing), or a burst of account-delete calls (account takeover). Block the source before it reaches your users.

Regulatory compliance

Each call records the timestamp, user ID, and IP, the audit trail that ISO, SOC 2, HIPAA, and GDPR require, plus a defensible sequence of events in any dispute.

Data versioning

Every profile change is versioned per UID and retained, so you can answer consumer data-access requests and show exactly what changed and when.

Business intelligence

Chart authentication trends by device, location, and time. A spike in Forgot Password calls, for example, signals that Passwordless or OTP login would reduce friction.

Troubleshooting

Trace a user's API calls and their responses to pinpoint failures after a release or a bad integration.


What gets logged

User Audit Logs record end-user activity against your tenant. Each entry captures who the actor was, the API that ran, the resource affected, the response status, and the exact time.

Typical entries include:
  • Sign-ins: credential, social, SSO, and Passwordless authentication attempts.
  • Registrations: new account creation and verification.
  • Profile changes: updates to end-user profile data.
  • Session events: token issuance, refresh, and sign-out.
  • MFA events: enrollment and verification.
  • Account protection: password resets, email and phone changes, blocks, and failed-attempt lockouts.
  • Consent and privacy: consent grants, policy acceptance, and account deletion.

Use the logs to trace a specific user's activity, investigate a failed sign-in, resolve a support ticket, and review end-user security events.

Retention: User Audit Logs are kept for 7 days. The view shows activity from the last 7 days only.

Sample rows from the User Audit Logs view:
TimeUIDActor TypeEventTargetStatus
2026-05-19 10:20:35Anonymousapi_keyloginaccount200
2026-05-19 10:16:42a4f9c1…7b2d09api_keyloginaccount401
2026-05-19 10:16:33c08e22…91f3aaapi_keyregisteraccount201
2026-05-19 10:14:08a4f9c1…7b2d09api_keymfa_verifymfa200

Column reference

Every row in the audit logs has four key columns. Pick a tab to learn what its values mean.
The channel an action came through.
dashboard
A Team Member performing an action from the Admin Console.
api_key_secret
Action authenticated with an API key + secret pair (server-to-server).
api_key
Action authenticated with only an API key (public-side calls).
api_secret
Action authenticated with only an API secret.
m2m
A machine-to-machine call from a registered client.
oidc_client
An OIDC client driving the action — typically a federated app.
domain
A request from a registered Hub Domain or Custom Domain (browser-side).
org_user
An organization-scoped user acting within their org.

Filtering & searching

Both views share the same toolbar above the table. Pick a tab to see how each control works.
Combine any column with an operator (contains, equal, not equals) and a value. Click the + to add another rule — rules are combined with AND.
FiltersSearch by UIDSelect RuleSelect OperatorEnter valueCancelApplyATTRIBUTEOPERATORVALUEColumn to filter byHow to compareMatch value
Click Filters in the toolbar to open the rule builder.

Examples

Find every failed sign-in for one user
  1. Open the User Audit Logs view.
  2. Click Search by UID and paste the actor's UID — e.g. a4f9c1…7b2d09.
  3. Add filter: Event · equal · login.
  4. Add filter: Status Code · equal · 401.
  5. Apply. The table now lists only failed sign-ins for that user.

Exporting logs

Click the Export button at the top right of the table to download the filtered result as a CSV — up to 10,000 rows per export. The file reflects the active filters and date range, so what you see is what you get.

Export
The Export button sits at the top right of the audit logs table.
Want more than the 10,000-row export?Stream your audit logs straight into your own SIEM with Audit Log Integration. You get every record in real time, with no row cap and long-term retention.Explore Audit Log Integration →