# Auditing and Monitoring Auth Events — Authentication & Authorization

Source: https://www.skillbyai.com/en/authentication/x-audit

> Know when something is wrong.

## What to log and alert on

Record structured **audit events** for logins (success and failure), logouts, MFA enrolment and removal, password changes and resets, email changes, role and permission changes, token issuance and refresh-token reuse, and admin impersonation. Include timestamp, user or client ID, source IP, user agent, outcome and a correlation ID. **Never log** passwords, full tokens, session IDs, reset links or MFA secrets. Alert on patterns: spikes in failed logins (stuffing), many accounts failing from one source (spraying), impossible travel, MFA push floods, logins from new devices on sensitive accounts. Notify users of security-relevant changes by email so they can react. Make audit logs append-only and retained according to your compliance needs.

## A structured audit event

JSON log line; note what is deliberately absent.

```json
{
  "ts": "2026-10-02T09:14:07.512Z",
  "event": "auth.login.failed",
  "reason": "bad_credentials",
  "userId": null,
  "emailHash": "sha256:7c4a8d09ca37...",
  "ip": "203.0.113.24",
  "userAgent": "Mozilla/5.0 ...",
  "requestId": "req_01J9ZK3X2",
  "riskSignals": ["new_ip", "high_velocity_source"]
}
// no password, no session id, no token, no reset link
```

## Log failures with care

Users sometimes type their password into the username field. Hash or truncate identifiers on failed logins so logs do not accidentally collect credentials.

**Quiz:** Which item should never appear in authentication logs?

- [x] The full session ID or access token
- [ ] The event type and outcome
- [ ] The source IP address
- [ ] A request correlation ID

*Answer:* The full session ID or access token. Logged tokens can be replayed by anyone with log access.
