Skip to main content

5.2 Two limits to know before you rely on the log

The Type filter does not cover every activity type in the log - The filter offers seven values, but the Activity Type column contains more than seven distinct values. Types that appear in the data and cannot be selected in the filter include New User Registration, Login Attempt, Data Export and Password Reset. An empty result from the Type filter therefore does not mean the events did not happen.

Failed sign-ins are not all classified as Failed Login - A failed sign-in can be recorded with Activity Type User Login, with the failure stated in the Description, for example a description reading that a login attempt failed on invalid credentials. The filter offers a separate Failed Login value, so filtering on Failed Login can return nothing even when failed sign-ins have occurred.

To investigate sign-in activity reliably:

  • Clear the Type filter so no type is excluded.
  • Set the start and end dates to the period you are investigating.
  • Use Search against the Description text, for example searching for failed, rather than relying on the Type filter.
  • Read the User and IP Address columns together. Repeated failures against one account from one unfamiliar address is the pattern worth escalating.
  • If an account shows repeated failures, disable it while you investigate (see 2.7) and reset its password before re-enabling (see 2.8).

Report both limits to support@ncsapp.com when you raise a security query, so the platform team knows the filter result you are quoting is incomplete.

Figure key, Activity Log​

  • Breadcrumb.
  • Left navigation, with Activity Log selected.
  • Search field.
  • Start date control.
  • End date control.
  • Type filter, with its seven values.
  • Timestamp column.
  • User column.
  • Activity Type column.
  • Description column.
  • IP Address column.
  • Rows per page selector and page controls.