<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to search login records by IP address and track password reset events?]]></title><description><![CDATA[<p dir="auto">I need to audit user activity and have two related questions:</p>
<ol>
<li>
<p dir="auto"><strong>Search login records by IP address</strong>: Is there a built-in way to search Login Records by IP address? I want to identify if a specific IP is being used by multiple user accounts.</p>
</li>
<li>
<p dir="auto"><strong>Track password reset events</strong>: Are there logs that show when a user goes through the Forgot Password flow or updates their password? I can see the <code>passwordLastUpdateInstant</code> field in the user object, but I cannot determine <em>how</em> the password was updated (e.g., password expiration, forgot password flow, admin reset, etc.).</p>
</li>
</ol>
<p dir="auto">Is there a way to get this information either through the admin UI or via API?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3167/how-to-search-login-records-by-ip-address-and-track-password-reset-events</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 23:58:19 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3167.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 29 Sep 2026 17:57:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to search login records by IP address and track password reset events? on Tue, 29 Sep 2026 17:57:32 GMT]]></title><description><![CDATA[<h2>Searching by IP Address</h2>
<p dir="auto">There is no built-in search feature to filter login records by IP address directly in the FusionAuth admin UI or API. The <a href="https://fusionauth.io/docs/apis/login/search" rel="nofollow ugc">Search Login Records API</a> supports filtering by <code>applicationId</code>, <code>userId</code>, and date range (start/end), but not by IP address. While login records do include IP address information in the response data, there's no query parameter to filter by it.</p>
<p dir="auto">To accomplish IP address-based searching, you'll need to:</p>
<ol>
<li>Export the login records via the <strong>Download button</strong> on the Login Records page in the admin UI, or use the <a href="https://fusionauth.io/docs/apis/login/export" rel="nofollow ugc">Export Login Records API</a></li>
<li>The export will be in CSV format</li>
<li>Search through the exported data for the IP address you're investigating</li>
</ol>
<p dir="auto">Alternatively, you could retrieve login records using the <a href="https://fusionauth.io/docs/apis/login/search" rel="nofollow ugc">Search Login Records API</a> with other criteria (like date range or user ID) and then filter the results client-side based on the <code>ipAddress</code> field returned in the response.</p>
<h2>Tracking Password Reset Events</h2>
<p dir="auto">By default, FusionAuth does not log forgot password flows or distinguish between different types of password updates. However, you can track these events going forward by setting up webhooks (note: this is an Enterprise-only feature):</p>
<ol>
<li>Configure the <a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-reset-success" rel="nofollow ugc">user.password.reset.success webhook</a> to track when a password is successfully reset through the forgot password flow</li>
<li>Configure the <a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-update" rel="nofollow ugc">user.password.update webhook</a> to track general password updates</li>
<li>You can also track <a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-reset-start" rel="nofollow ugc">user.password.reset.start</a> and <a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-reset-send" rel="nofollow ugc">user.password.reset.send</a> events for additional context</li>
<li>Send these events to your own logging system for audit purposes</li>
</ol>
<p dir="auto"><strong>Note</strong>: These password-related webhooks are Enterprise features and require an Enterprise plan. Webhooks only track events going forward from when they're enabled — they cannot retroactively capture historical password reset activity. The <code>passwordLastUpdateInstant</code> field will still show when the password was last changed, but without the webhook, you won't have details about the method used for the change.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/apis/login/search" rel="nofollow ugc">Search Login Records API</a> - API for searching login records with supported parameters</li>
<li><a href="https://fusionauth.io/docs/apis/login/export" rel="nofollow ugc">Export Login Records API</a> - API for exporting login records to CSV format</li>
<li><a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-reset-success" rel="nofollow ugc">User Password Reset Success Event</a> - Webhook event for successful password resets</li>
<li><a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/user/password/user-password-update" rel="nofollow ugc">User Password Update Event</a> - Webhook event for password updates</li>
<li><a href="https://fusionauth.io/docs/extend/events-and-webhooks/" rel="nofollow ugc">Events &amp; Webhooks Overview</a> - General information on configuring webhooks</li>
<li><a href="https://fusionauth.io/docs/apis/users/change-password" rel="nofollow ugc">Change a User's Password API</a> - API for programmatic password changes</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8671</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8671</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Tue, 29 Sep 2026 17:57:32 GMT</pubDate></item></channel></rss>