Aller au contenu principal

5.2 Two limits to know before you rely on the log

The Type filter does not cover every activity type in the log - The filter offers seven values, but the Activity Type column contains more than seven distinct values. Types that appear in the data and cannot be selected in the filter include New Utilisateur Registration, Login Attempt, Data Export and Mot de passe Reset. An empty result from the Type filter therefore does not mean the events did not happen.

Failed sign-ins are not all classified as Failed Login - A failed sign-in can be recorded with Activity Type Utilisateur Login, with the failure stated in the Description, for example a description reading that a login attempt failed on invalid credentials. The filter offers a separate Failed Login value, so filtering on Failed Login can return nothing even when failed sign-ins have occurred.

To investigate sign-in activity reliably:

  • Effacer the Type filter so no type is excluded.
  • Set the start and end dates to the period you are investigating.
  • Use Rechercher against the Description text, for example searching for failed, rather than relying on the Type filter.
  • Read the Utilisateur and IP Address columns together. Repeated failures against one account from one unfamiliar address is the pattern worth escalating.
  • If an account shows repeated failures, disable it while you investigate (see 2.7) and reset its password before re-enabling (see 2.8).

Rapport both limits to support@ncsapp.com when you raise a security query, so the platform team knows the filter result you are quoting is incomplete.

Figure key, Journal d'activité​

  • Fil d'Ariane.
  • Left navigation, with Journal d'activité selected.
  • Rechercher field.
  • Contrôle de date de début.
  • Contrôle de date de fin.
  • Type filter, with its seven values.
  • Timestamp column.
  • Utilisateur column.
  • **Activity Colonne Type.
  • **Colonne Description.
  • IP Address column.
  • Rows per page selector and page controls.