FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    How to search login records by IP address and track password reset events?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    login-records audit ip-address password-reset webhooks
    1
    2
    11
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      I need to audit user activity and have two related questions:

      1. Search login records by IP address: Is there a built-in way to search Login Records by IP address? I want to identify if a specific IP is being used by multiple user accounts.

      2. Track password reset events: Are there logs that show when a user goes through the Forgot Password flow or updates their password? I can see the passwordLastUpdateInstant field in the user object, but I cannot determine how the password was updated (e.g., password expiration, forgot password flow, admin reset, etc.).

      Is there a way to get this information either through the admin UI or via API?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        Searching by IP Address

        There is no built-in search feature to filter login records by IP address directly in the FusionAuth admin UI or API. The Search Login Records API supports filtering by applicationId, userId, and date range (start/end), but not by IP address. While login records do include IP address information in the response data, there's no query parameter to filter by it.

        To accomplish IP address-based searching, you'll need to:

        1. Export the login records via the Download button on the Login Records page in the admin UI, or use the Export Login Records API
        2. The export will be in CSV format
        3. Search through the exported data for the IP address you're investigating

        Alternatively, you could retrieve login records using the Search Login Records API with other criteria (like date range or user ID) and then filter the results client-side based on the ipAddress field returned in the response.

        Tracking Password Reset Events

        By default, FusionAuth does not log forgot password flows or distinguish between different types of password updates. However, you can track these events going forward by setting up webhooks (note: this is an Enterprise-only feature):

        1. Configure the user.password.reset.success webhook to track when a password is successfully reset through the forgot password flow
        2. Configure the user.password.update webhook to track general password updates
        3. You can also track user.password.reset.start and user.password.reset.send events for additional context
        4. Send these events to your own logging system for audit purposes

        Note: These password-related webhooks are Enterprise features and require an Enterprise plan. Webhooks only track events going forward from when they're enabled — they cannot retroactively capture historical password reset activity. The passwordLastUpdateInstant field will still show when the password was last changed, but without the webhook, you won't have details about the method used for the change.

        Related Documentation

        • Search Login Records API - API for searching login records with supported parameters
        • Export Login Records API - API for exporting login records to CSV format
        • User Password Reset Success Event - Webhook event for successful password resets
        • User Password Update Event - Webhook event for password updates
        • Events & Webhooks Overview - General information on configuring webhooks
        • Change a User's Password API - API for programmatic password changes

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post