पाठ 23 / 25
Auditing and Monitoring Auth Events
Know when something is wrong.
What to log and alert on
Record structured audit events for logins (success and failure), logouts, MFA enrolment and removal, password changes and resets, email changes, role and permission changes, token issuance and refresh-token reuse, and admin impersonation. Include timestamp, user or client ID, source IP, user agent, outcome and a correlation ID. Never log passwords, full tokens, session IDs, reset links or MFA secrets. Alert on patterns: spikes in failed logins (stuffing), many accounts failing from one source (spraying), impossible travel, MFA push floods, logins from new devices on sensitive accounts. Notify users of security-relevant changes by email so they can react. Make audit logs append-only and retained according to your compliance needs.
A structured audit event
JSON log line; note what is deliberately absent.
{
"ts": "2026-10-02T09:14:07.512Z",
"event": "auth.login.failed",
"reason": "bad_credentials",
"userId": null,
"emailHash": "sha256:7c4a8d09ca37...",
"ip": "203.0.113.24",
"userAgent": "Mozilla/5.0 ...",
"requestId": "req_01J9ZK3X2",
"riskSignals": ["new_ip", "high_velocity_source"]
}
// no password, no session id, no token, no reset linkLog failures with care
Users sometimes type their password into the username field. Hash or truncate identifiers on failed logins so logs do not accidentally collect credentials.
त्वरित जाँच: Which item should never appear in authentication logs?
- The full session ID or access token
- The event type and outcome
- The source IP address
- A request correlation ID
Answer
The full session ID or access token — Logged tokens can be replayed by anyone with log access.