Security Logs Module Documentation
Table of Contents
Section titled βTable of Contentsβ- Navigation & Access
- Screenshots & Visual Interface
- Module Overview (Technical)
- Module Overview (Commercial/Business)
- Module Overview (End User/Administrator)
- Security Event Reference
- Common Scenarios & Examples
- Limitations & Important Notes
- Troubleshooting Tips
- Glossary
- Model Context Protocol (MCP) AI Integration
Navigation & Access
Section titled βNavigation & AccessβTo access the Security Logs surveillance ledger:
- Log in to the Ring2All Web Portal (
https://<domain-or-ip>/login). - In the left navigation sidebar, expand Reports.
- Under System Reports, click Security Logs (
/reports/system/security). - Review authentication trials, failed login alerts, password alterations, and access violations.
Screenshots & Visual Interface
Section titled βScreenshots & Visual InterfaceβSystem Security & Authentication Audit Trail
Section titled βSystem Security & Authentication Audit TrailβFocused security event stream tracking login triumphs, authentication rejections, MFA challenges, credential refreshes, source IP locations, and security alert severity levels.

1. Module Overview (Technical)
Section titled β1. Module Overview (Technical)βWhat Are Security Logs?
Section titled βWhat Are Security Logs?βSecurity Logs is a security monitoring module that tracks authentication and access control events. Unlike general Audit Logs, Security Logs focuses specifically on security-relevant events: logins, logout, failed login attempts, password changes, MFA configuration, and permission modifications.
Architecture
Section titled βArchitectureβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ Security Logs Architecture ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€β ββ Security Events ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ β Authentication System β ββ β β ββ β ββ User logs in β LOGIN β ββ β ββ Wrong password β LOGIN_FAILED β ββ β ββ User logs out β LOGOUT β ββ β ββ Password changed β PASSWORD_CHANGE β ββ β ββ Password reset β PASSWORD_RESET β ββ β ββ MFA enabled β MFA_ENABLED β ββ β ββ MFA disabled β MFA_DISABLED β ββ β ββ Role/permission change β PERMISSION_CHANGE β ββ β β ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ β ββ βΌ Logged with context ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ β public.security_logs β ββ β β ββ β | event | user | ip_address | user_agent | timestamp | β ββ β β ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ β ββ βΌ Displayed in Viewer ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ β Security Logs Page β ββ β β ββ β βββββββββββββββββββββββββββββββββββββββββββββββββββββββ β ββ β βTime βEvent βUser βIP Address βDetails β β ββ β βββββββββΌβββββββββββββΌβββββββΌββββββββββββΌββββββββββββ€ β ββ β β10:30 βLogin βadmin β192.168.1.1β [ποΈ] β β ββ β β10:28 βLogin Failedβjohn β10.0.0.5 β [ποΈ] β β ββ β β10:25 βMFA Enabled βadmin β192.168.1.1β [ποΈ] β β ββ β βββββββββββββββββββββββββββββββββββββββββββββββββββββββ β ββ β β ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ2. Module Overview (Commercial/Business)
Section titled β2. Module Overview (Commercial/Business)βBusiness Value
Section titled βBusiness ValueβSecurity Logs provides security visibility:
| Without Security Logs | With Security Logs |
|---|---|
| Unknown access | Login tracking |
| Hidden attacks | Failed login alerts |
| No MFA tracking | MFA event history |
| Permission blind | Permission change log |
Use Cases
Section titled βUse Casesβ-
Intrusion Detection
- Track failed logins
- Identify brute force attacks
-
Access Auditing
- View login history
- Track session patterns
-
Compliance
- SOC 2 requirements
- Security audit trail
-
Incident Response
- Investigate breaches
- Forensic analysis
Feature Highlights
Section titled βFeature Highlightsβ| Feature | Benefit |
|---|---|
| Login Tracking | Who accessed system |
| Failed Logins | Attack detection |
| Password Events | Credential changes |
| MFA Events | 2FA configuration |
| Permission Changes | Access control audit |
| IP Tracking | Location awareness |
3. Module Overview (End User/Administrator)
Section titled β3. Module Overview (End User/Administrator)βWhat Can You Do?
Section titled βWhat Can You Do?β- View all security events
- Track login/logout activity
- Monitor failed login attempts
- Review password changes
- Track MFA configuration
- Monitor permission changes
- Filter by event type and user
Security Logs Interface
Section titled βSecurity Logs Interfaceβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ Security Logs ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€β ββ Filters: ββ ββ Range: [7 Days βΌ] ββ ββ Event Type: [All Events βΌ] ββ ββ User: [All Users βΌ] ββ ββ [π Refresh] [Clear Filters] ββ ββ π [Search by action, user, or IP address... ] ββ ββ βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ β Timestamp β Event β User β IP Address βποΈβ ββ ββββββββββββββββΌβββββββββββββββββΌβββββββββΌββββββββββββββΌβββ€ ββ β 01/16 10:30 β π’ Login β admin β 192.168.1.1 βποΈβ ββ β 01/16 10:28 β π΄ Login Failedβ john β 10.0.0.5 βποΈβ ββ β 01/16 10:27 β π΄ Login Failedβ john β 10.0.0.5 βποΈβ ββ β 01/16 10:26 β π΄ Login Failedβ john β 10.0.0.5 βποΈβ ββ β 01/16 10:00 β π MFA Enabled β admin β 192.168.1.1 βποΈβ ββ β 01/15 18:30 β πͺ Logout β admin β 192.168.1.1 βποΈβ ββ β 01/15 17:00 β π Pass Change β jane β 192.168.1.2 βποΈβ ββ βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ββ ββ β οΈ Alert: 3 failed login attempts for 'john' in last hour ββ ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββQuick Tips
Section titled βQuick Tipsβ[!TIP] Failed Logins: Multiple failed attempts may indicate an attack.
[!TIP] Unusual IPs: Watch for logins from unexpected locations.
[!CAUTION] MFA Disabled: Review any MFA disable events immediately.
4. Security Event Reference
Section titled β4. Security Event ReferenceβEvent Types
Section titled βEvent Typesβ| Event | Icon | Description |
|---|---|---|
| Login | π’ | Successful authentication |
| Logout | πͺ | User session ended |
| Login Failed | π΄ | Failed authentication attempt |
| Password Change | π | User changed password |
| Password Reset | π | Password was reset |
| MFA Enabled | π | Two-factor authentication enabled |
| MFA Disabled | π | Two-factor authentication disabled |
| Permission Change | π₯ | User role/permissions modified |
Event Details
Section titled βEvent Detailsβ| Field | Description |
|---|---|
| Timestamp | When event occurred |
| User | Affected user account |
| IP Address | Source IP address |
| User Agent | Browser/client info |
| Resource | Related resource type |
| Metadata | Additional context |
Severity Levels
Section titled βSeverity Levelsβ| Event | Severity | Action Needed |
|---|---|---|
| Login | Info | Normal activity |
| Logout | Info | Normal activity |
| Login Failed | Warning | Monitor for patterns |
| Password Change | Info | Expected activity |
| Password Reset | Medium | Verify authorization |
| MFA Enabled | Info | Security improvement |
| MFA Disabled | High | Investigate immediately |
| Permission Change | Medium | Verify authorization |
5. Common Scenarios & Examples
Section titled β5. Common Scenarios & ExamplesβScenario 1: Detect Brute Force Attack
Section titled βScenario 1: Detect Brute Force Attackβ- Filter by βLogin Failedβ
- Look for same user/IP with multiple failures
- Check timestamp clustering
- Block IP if attack confirmed
Scenario 2: Audit Login History
Section titled βScenario 2: Audit Login Historyβ- Set date range for period
- Filter by specific user
- Review all login events
- Check for unusual IPs
Scenario 3: Investigate MFA Change
Section titled βScenario 3: Investigate MFA Changeβ- Filter by βMFA Disabledβ
- Identify who disabled MFA
- Check if authorized
- Re-enable if needed
Scenario 4: Permission Audit
Section titled βScenario 4: Permission Auditβ- Filter by βPermission Changeβ
- Review who made changes
- Verify proper authorization
- Document for compliance
6. Limitations & Important Notes
Section titled β6. Limitations & Important NotesβTechnical Notes
Section titled βTechnical Notesβ[!NOTE] Security Focus: Only security events, not data changes.
[!NOTE] Real-time: Events logged immediately.
[!WARNING] Failed Logins: May contain attempted usernames (could be typos).
Best Practices
Section titled βBest Practicesβ- Daily Review: Check failed logins daily
- Alert Setup: Configure alerts for patterns
- IP Monitoring: Watch for unusual locations
- MFA Enforcement: Monitor MFA disable events
- Permission Reviews: Audit permission changes regularly
Common Attack Patterns
Section titled βCommon Attack Patternsβ| Pattern | Indicator | Response |
|---|---|---|
| Brute Force | Many failures, same user | Lock account, block IP |
| Credential Stuffing | Many users, same IP | Block IP range |
| Insider Threat | Off-hours access | Investigate user |
| Account Takeover | Password changed + MFA disabled | Lock account immediately |
7. Troubleshooting Tips
Section titled β7. Troubleshooting TipsβCommon Issues
Section titled βCommon Issuesβ| Symptom | Possible Cause | Solution |
|---|---|---|
| No records | Too restrictive filter | Clear filters |
| Missing logins | Events not logged | Check logging configuration |
| Unknown IP | VPN or proxy | Check userβs network |
| Many failures | Attack or typos | Investigate pattern |
| Slow loading | Large date range | Reduce date range |
Diagnostic SQL
Section titled βDiagnostic SQLβRecent security events:
SELECT timestamp, event, user_email, ip_address, user_agentFROM public.security_logsORDER BY timestamp DESCLIMIT 50;Failed login summary:
SELECT user_email, ip_address, COUNT(*) as failed_attemptsFROM public.security_logsWHERE event = 'LOGIN_FAILED' AND timestamp >= NOW() - INTERVAL '24 hours'GROUP BY user_email, ip_addressORDER BY failed_attempts DESC;Login locations:
SELECT user_email, ip_address, COUNT(*) as logins, MAX(timestamp) as last_loginFROM public.security_logsWHERE event = 'LOGIN'GROUP BY user_email, ip_addressORDER BY last_login DESC;8. Glossary
Section titled β8. Glossaryβ| Term | Definition |
|---|---|
| MFA | Multi-Factor Authentication |
| Brute Force | Repeated login attempts |
| Credential Stuffing | Testing stolen credentials |
| Session | Authenticated user period |
| User Agent | Browser/client identification |
| Failed Login | Incorrect credentials |
9. Model Context Protocol (MCP) AI Integration
Section titled β9. Model Context Protocol (MCP) AI IntegrationβThe Ring2All Platform Copilot connects directly with authentication event records and security incident logs in ss_logs.audit_logs via the Model Context Protocol (MCP). Information security officers, system operators, and fraud analysts can audit authentication attempts, track brute-force attacks, and identify unauthorized access attempts conversationally.
Exposed MCP Tools
Section titled βExposed MCP Toolsβ| Tool Name | Operation | Primary Parameters | Description |
|---|---|---|---|
get_security_logs |
Security Event Ledger | action (βLOGINβ, βLOGIN_FAILEDβ, βPASSWORD_CHANGEβ, βACCESS_DENIEDβ), ipAddress (string, optional), limit (number, default: 25) |
Retrieves security events, failed authentication challenges, password modifications, and blocked IP alerts. |
query_audit_logs |
General Audit Search | search (string, optional), resource (string, optional), limit (number) |
Searches system-wide audit records to correlate security alerts against administrative resource operations. |
Operational Safeguards & Access Security
Section titled βOperational Safeguards & Access Securityβ- Tenant Isolation: Security logs queries enforce strict
tenant_idpartitioning (WHERE tenant_id = :tenant_id). Tenant administrators cannot inspect login patterns or user accounts of other tenants. - Credential Protection: Passwords (plain or hashed) are never stored in log metadata or returned across MCP payloads. Authentication payloads only record success/failure statuses and client metadata.
- SOC Integration: High-frequency failure events can be queried by SIEM/SOAR platforms leveraging the Ring2All MCP server endpoint.
Example MCP Payloads
Section titled βExample MCP Payloadsβ1. Checking Failed Login Attempts (get_security_logs)
Section titled β1. Checking Failed Login Attempts (get_security_logs)β{ "action": "LOGIN_FAILED", "limit": 10}Response:
{ "success": true, "data": { "total": 2, "securityEvents": [ { "id": "fe183921-9922-4e01-9a1b-123456789abc", "action": "LOGIN_FAILED", "resource": "auth", "resourceId": "admin", "user": "admin", "ipAddress": "198.51.100.44", "details": { "reason": "invalid_credentials", "attempt": 3 }, "timestamp": "2026-09-08T06:14:22.000Z" }, { "id": "ae112233-4455-6677-8899-aabbccddeeff", "action": "LOGIN_FAILED", "resource": "auth", "resourceId": "admin", "user": "admin", "ipAddress": "198.51.100.44", "details": { "reason": "invalid_credentials", "attempt": 2 }, "timestamp": "2026-09-08T06:14:10.000Z" } ] }}2. Investigating Security Activity for a Remote IP Address (get_security_logs)
Section titled β2. Investigating Security Activity for a Remote IP Address (get_security_logs)β{ "ipAddress": "198.51.100.44"}Copilot Natural Language Prompts
Section titled βCopilot Natural Language Promptsβ- βShow me all failed login attempts recorded in the last 24 hours.β
- βAre there any suspicious IP addresses with multiple authentication failures today?β
- βWhen was the last password change performed on the admin account?β
- βWere there any access denied or permission rejection events logged this week?β
Documentation last updated: January 2026

