How to run a Report showing Failed Authentication Attempts in RSA Identity Governance & Lifecycle
Originally Published: 2015-09-10
Article Number
Applies To
RSA Version/Condition: 6.9.1, 7.x
Issue
Resolution
To view failed authentication attempts and other audit events, there is an Out-of-the-box (OOTB) Tabular Report that reports audit events for the last 30 days. In the user interface go to Reports > Tabular > Audit Events for the Past 30 Days > Run Report button. Once the report results are available, peruse the results for the LOGIN audit event. The LOGIN audit event audits login-related changes including failed authentication attempts.
Below is a sample of report output with successful and failed login attempts. If you export the report results (bottom right corner) to a CSV file, you can then sort the report on any of the table columns. In this case you could sort on Event Name to see all the LoginFailureAttempt events grouped together.
Related Articles
RSA Via Lifecycle and Governance 7.0 installation looping when running Oracle Cluster Verification Utility (CVU) cluvfy/ru… 71Number of Views RSA Announces the Availability of RSA Identity Governance Lifecycle 7.0.2 Patch 11 1Number of Views RSA Identity G&L 7.1.0 installation intermittently fails on SLES 12 where 'Hardware Lock Elision' functionality of the CPU… 34Number of Views Quick Setup Guide - Connect Governance & Lifecycle to Cloud Access Service 35Number of Views RSA Governance & Lifecycle SaaS - Deploying the Remote Collection Agent 43Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third …
Don't see what you're looking for?