There is no built-in search feature to filter login records by IP address directly in the FusionAuth admin UI or API. The Search Login Records API supports filtering by applicationId, userId, and date range (start/end), but not by IP address. While login records do include IP address information in the response data, there's no query parameter to filter by it.
To accomplish IP address-based searching, you'll need to:
Export the login records via the Download button on the Login Records page in the admin UI, or use the Export Login Records API The export will be in CSV format Search through the exported data for the IP address you're investigatingAlternatively, you could retrieve login records using the Search Login Records API with other criteria (like date range or user ID) and then filter the results client-side based on the ipAddress field returned in the response.
Tracking Password Reset EventsBy default, FusionAuth does not log forgot password flows or distinguish between different types of password updates. However, you can track these events going forward by setting up webhooks (note: this is an Enterprise-only feature):
Configure the user.password.reset.success webhook to track when a password is successfully reset through the forgot password flow Configure the user.password.update webhook to track general password updates You can also track user.password.reset.start and user.password.reset.send events for additional context Send these events to your own logging system for audit purposesNote: These password-related webhooks are Enterprise features and require an Enterprise plan. Webhooks only track events going forward from when they're enabled — they cannot retroactively capture historical password reset activity. The passwordLastUpdateInstant field will still show when the password was last changed, but without the webhook, you won't have details about the method used for the change.
Related Documentation Search Login Records API - API for searching login records with supported parameters Export Login Records API - API for exporting login records to CSV format User Password Reset Success Event - Webhook event for successful password resets User Password Update Event - Webhook event for password updates Events & Webhooks Overview - General information on configuring webhooks Change a User's Password API - API for programmatic password changes