The User Event Monitor lists the most recent user events for the Cloud Authentication Service. Use this information to monitor user behavior patterns and troubleshoot unsuccessful authentication attempts.
The User Event Monitor can list up to 100 events that occurred over the past seven days. You can filter the results according to User ID, date range, and authentication methods. The User Event Monitor displays the following information related to the event:
- Event Code
- Authentication Details
- Assurance Level
Events are color-coded for quick identification.
The assurance levels displayed depend on the following:
- For RSA SecurID Token, FIDO Token, SMS Tokencode, and Voice Tokencode, the User Event Monitor displays the assurance level assigned to the access policy for the protected resource. If the policy contains multiple conditions and assurance levels, the User Event Monitor displays the assurance level for the condition applied to the user.
- For Approve and Device Biometrics, the User Event Monitor displays the assurance level configured for those methods on the Assurance Level page in the Cloud Administration Console.
- In the Cloud Administration Console, click Users > User Event Monitor.
- (Optional) In the Filter field, type the User ID for which you want to display events. By default, all events within the specified time period are displayed.
- (Optional) Specify the time period to include in the report in hours (1 to 24) or days (1 to 7). The default is four hours.
- (Optional) Specify if you want to display only Success Events, Error Events, or Critical Events.
- Click Go to begin the search. By default, events appear in descending order by timestamp, with the most recent entry first. To sort a column, click its arrow.