Skip to content

Security Logs Module Documentation

10 min readUpdated: Sep 26, 2026
View as Markdown
  1. Navigation & Access
  2. Screenshots & Visual Interface
  3. Module Overview (Technical)
  4. Module Overview (Commercial/Business)
  5. Module Overview (End User/Administrator)
  6. Security Event Reference
  7. Common Scenarios & Examples
  8. Limitations & Important Notes
  9. Troubleshooting Tips
  10. Glossary
  11. Model Context Protocol (MCP) AI Integration

To access the Security Logs surveillance ledger:

  1. Log in to the Ring2All Web Portal (https://<domain-or-ip>/login).
  2. In the left navigation sidebar, expand Reports.
  3. Under System Reports, click Security Logs (/reports/system/security).
  4. Review authentication trials, failed login alerts, password alterations, and access violations.

Focused security event stream tracking login triumphs, authentication rejections, MFA challenges, credential refreshes, source IP locations, and security alert severity levels. Security Logs Table


Security Logs is a security monitoring module that tracks authentication and access control events. Unlike general Audit Logs, Security Logs focuses specifically on security-relevant events: logins, logout, failed login attempts, password changes, MFA configuration, and permission modifications.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Security Logs Architecture β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ β”‚
β”‚ Security Events β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ Authentication System β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”œβ”€ User logs in β†’ LOGIN β”‚ β”‚
β”‚ β”‚ β”œβ”€ Wrong password β†’ LOGIN_FAILED β”‚ β”‚
β”‚ β”‚ β”œβ”€ User logs out β†’ LOGOUT β”‚ β”‚
β”‚ β”‚ β”œβ”€ Password changed β†’ PASSWORD_CHANGE β”‚ β”‚
β”‚ β”‚ β”œβ”€ Password reset β†’ PASSWORD_RESET β”‚ β”‚
β”‚ β”‚ β”œβ”€ MFA enabled β†’ MFA_ENABLED β”‚ β”‚
β”‚ β”‚ β”œβ”€ MFA disabled β†’ MFA_DISABLED β”‚ β”‚
β”‚ β”‚ └─ Role/permission change β†’ PERMISSION_CHANGE β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚ β”‚
β”‚ β–Ό Logged with context β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ public.security_logs β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ | event | user | ip_address | user_agent | timestamp | β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚ β”‚
β”‚ β–Ό Displayed in Viewer β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ Security Logs Page β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚
β”‚ β”‚ β”‚Time β”‚Event β”‚User β”‚IP Address β”‚Details β”‚ β”‚ β”‚
β”‚ β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ β”‚
β”‚ β”‚ β”‚10:30 β”‚Login β”‚admin β”‚192.168.1.1β”‚ [πŸ‘οΈ] β”‚ β”‚ β”‚
β”‚ β”‚ β”‚10:28 β”‚Login Failedβ”‚john β”‚10.0.0.5 β”‚ [πŸ‘οΈ] β”‚ β”‚ β”‚
β”‚ β”‚ β”‚10:25 β”‚MFA Enabled β”‚admin β”‚192.168.1.1β”‚ [πŸ‘οΈ] β”‚ β”‚ β”‚
β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Security Logs provides security visibility:

Without Security Logs With Security Logs
Unknown access Login tracking
Hidden attacks Failed login alerts
No MFA tracking MFA event history
Permission blind Permission change log
  1. Intrusion Detection

    • Track failed logins
    • Identify brute force attacks
  2. Access Auditing

    • View login history
    • Track session patterns
  3. Compliance

    • SOC 2 requirements
    • Security audit trail
  4. Incident Response

    • Investigate breaches
    • Forensic analysis
Feature Benefit
Login Tracking Who accessed system
Failed Logins Attack detection
Password Events Credential changes
MFA Events 2FA configuration
Permission Changes Access control audit
IP Tracking Location awareness

  • View all security events
  • Track login/logout activity
  • Monitor failed login attempts
  • Review password changes
  • Track MFA configuration
  • Monitor permission changes
  • Filter by event type and user
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Security Logs β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ β”‚
β”‚ Filters: β”‚
β”‚ β”œβ”€ Range: [7 Days β–Ό] β”‚
β”‚ β”œβ”€ Event Type: [All Events β–Ό] β”‚
β”‚ β”œβ”€ User: [All Users β–Ό] β”‚
β”‚ └─ [πŸ”„ Refresh] [Clear Filters] β”‚
β”‚ β”‚
β”‚ πŸ” [Search by action, user, or IP address... ] β”‚
β”‚ β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ Timestamp β”‚ Event β”‚ User β”‚ IP Address β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€ β”‚
β”‚ β”‚ 01/16 10:30 β”‚ 🟒 Login β”‚ admin β”‚ 192.168.1.1 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”‚ 01/16 10:28 β”‚ πŸ”΄ Login Failedβ”‚ john β”‚ 10.0.0.5 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”‚ 01/16 10:27 β”‚ πŸ”΄ Login Failedβ”‚ john β”‚ 10.0.0.5 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”‚ 01/16 10:26 β”‚ πŸ”΄ Login Failedβ”‚ john β”‚ 10.0.0.5 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”‚ 01/16 10:00 β”‚ πŸ”’ MFA Enabled β”‚ admin β”‚ 192.168.1.1 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”‚ 01/15 18:30 β”‚ πŸšͺ Logout β”‚ admin β”‚ 192.168.1.1 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β”‚ 01/15 17:00 β”‚ πŸ”‘ Pass Change β”‚ jane β”‚ 192.168.1.2 β”‚πŸ‘οΈβ”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚
β”‚ ⚠️ Alert: 3 failed login attempts for 'john' in last hour β”‚
β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

[!TIP] Failed Logins: Multiple failed attempts may indicate an attack.

[!TIP] Unusual IPs: Watch for logins from unexpected locations.

[!CAUTION] MFA Disabled: Review any MFA disable events immediately.


Event Icon Description
Login 🟒 Successful authentication
Logout πŸšͺ User session ended
Login Failed πŸ”΄ Failed authentication attempt
Password Change πŸ”‘ User changed password
Password Reset πŸ”„ Password was reset
MFA Enabled πŸ”’ Two-factor authentication enabled
MFA Disabled πŸ”“ Two-factor authentication disabled
Permission Change πŸ‘₯ User role/permissions modified
Field Description
Timestamp When event occurred
User Affected user account
IP Address Source IP address
User Agent Browser/client info
Resource Related resource type
Metadata Additional context
Event Severity Action Needed
Login Info Normal activity
Logout Info Normal activity
Login Failed Warning Monitor for patterns
Password Change Info Expected activity
Password Reset Medium Verify authorization
MFA Enabled Info Security improvement
MFA Disabled High Investigate immediately
Permission Change Medium Verify authorization

  1. Filter by β€œLogin Failed”
  2. Look for same user/IP with multiple failures
  3. Check timestamp clustering
  4. Block IP if attack confirmed
  1. Set date range for period
  2. Filter by specific user
  3. Review all login events
  4. Check for unusual IPs
  1. Filter by β€œMFA Disabled”
  2. Identify who disabled MFA
  3. Check if authorized
  4. Re-enable if needed
  1. Filter by β€œPermission Change”
  2. Review who made changes
  3. Verify proper authorization
  4. Document for compliance

[!NOTE] Security Focus: Only security events, not data changes.

[!NOTE] Real-time: Events logged immediately.

[!WARNING] Failed Logins: May contain attempted usernames (could be typos).

  1. Daily Review: Check failed logins daily
  2. Alert Setup: Configure alerts for patterns
  3. IP Monitoring: Watch for unusual locations
  4. MFA Enforcement: Monitor MFA disable events
  5. Permission Reviews: Audit permission changes regularly
Pattern Indicator Response
Brute Force Many failures, same user Lock account, block IP
Credential Stuffing Many users, same IP Block IP range
Insider Threat Off-hours access Investigate user
Account Takeover Password changed + MFA disabled Lock account immediately

Symptom Possible Cause Solution
No records Too restrictive filter Clear filters
Missing logins Events not logged Check logging configuration
Unknown IP VPN or proxy Check user’s network
Many failures Attack or typos Investigate pattern
Slow loading Large date range Reduce date range

Recent security events:

SELECT
timestamp,
event,
user_email,
ip_address,
user_agent
FROM public.security_logs
ORDER BY timestamp DESC
LIMIT 50;

Failed login summary:

SELECT
user_email,
ip_address,
COUNT(*) as failed_attempts
FROM public.security_logs
WHERE event = 'LOGIN_FAILED'
AND timestamp >= NOW() - INTERVAL '24 hours'
GROUP BY user_email, ip_address
ORDER BY failed_attempts DESC;

Login locations:

SELECT
user_email,
ip_address,
COUNT(*) as logins,
MAX(timestamp) as last_login
FROM public.security_logs
WHERE event = 'LOGIN'
GROUP BY user_email, ip_address
ORDER BY last_login DESC;

Term Definition
MFA Multi-Factor Authentication
Brute Force Repeated login attempts
Credential Stuffing Testing stolen credentials
Session Authenticated user period
User Agent Browser/client identification
Failed Login Incorrect credentials

The Ring2All Platform Copilot connects directly with authentication event records and security incident logs in ss_logs.audit_logs via the Model Context Protocol (MCP). Information security officers, system operators, and fraud analysts can audit authentication attempts, track brute-force attacks, and identify unauthorized access attempts conversationally.

Tool Name Operation Primary Parameters Description
get_security_logs Security Event Ledger action (β€œLOGIN”, β€œLOGIN_FAILED”, β€œPASSWORD_CHANGE”, β€œACCESS_DENIED”), ipAddress (string, optional), limit (number, default: 25) Retrieves security events, failed authentication challenges, password modifications, and blocked IP alerts.
query_audit_logs General Audit Search search (string, optional), resource (string, optional), limit (number) Searches system-wide audit records to correlate security alerts against administrative resource operations.
  • Tenant Isolation: Security logs queries enforce strict tenant_id partitioning (WHERE tenant_id = :tenant_id). Tenant administrators cannot inspect login patterns or user accounts of other tenants.
  • Credential Protection: Passwords (plain or hashed) are never stored in log metadata or returned across MCP payloads. Authentication payloads only record success/failure statuses and client metadata.
  • SOC Integration: High-frequency failure events can be queried by SIEM/SOAR platforms leveraging the Ring2All MCP server endpoint.
{
"action": "LOGIN_FAILED",
"limit": 10
}

Response:

{
"success": true,
"data": {
"total": 2,
"securityEvents": [
{
"id": "fe183921-9922-4e01-9a1b-123456789abc",
"action": "LOGIN_FAILED",
"resource": "auth",
"resourceId": "admin",
"user": "admin",
"ipAddress": "198.51.100.44",
"details": { "reason": "invalid_credentials", "attempt": 3 },
"timestamp": "2026-09-08T06:14:22.000Z"
},
{
"id": "ae112233-4455-6677-8899-aabbccddeeff",
"action": "LOGIN_FAILED",
"resource": "auth",
"resourceId": "admin",
"user": "admin",
"ipAddress": "198.51.100.44",
"details": { "reason": "invalid_credentials", "attempt": 2 },
"timestamp": "2026-09-08T06:14:10.000Z"
}
]
}
}

2. Investigating Security Activity for a Remote IP Address (get_security_logs)

Section titled β€œ2. Investigating Security Activity for a Remote IP Address (get_security_logs)”
{
"ipAddress": "198.51.100.44"
}
  • β€œShow me all failed login attempts recorded in the last 24 hours.”
  • β€œAre there any suspicious IP addresses with multiple authentication failures today?”
  • β€œWhen was the last password change performed on the admin account?”
  • β€œWere there any access denied or permission rejection events logged this week?”

Documentation last updated: January 2026