Skip to Main Content
Customer Feedback

We love feedback from you on our products and the problems in your daily work that you would like us to solve. Please describe the challenge you're encountering and your desired outcome. Be as detailed as possible.

For technical issues or bugs please head to Support or our Developer Community. You can assign up to 20 votes in total. Thank you for your feedback.

Status explanation: 'Future Consideration' = Continuing to collect further feedback, not planned at this time. 'Investigating' = Prioritized for deeper customer and feasibility investigations ahead of planning development.

Status Gathering interest
Created by Guest
Created on Aug 8, 2024

Add Audit Logs for incorrect password login attempt logs and user locked out logs

In Audit logs, we are getting admin user logins and password change related logs. But we are not getting incorrect password login attempt logs and user locked out logs.

  • How do we know if someone's account was locked due to incorrect password login attempts ?

  • How do we know if someone trying to login with brute force attack ?

  • Optimizely
    Sara Winter
    Reply
    |
    Aug 22, 2024

    There is currently not a way to see if an admin user is locked out due to incorrect password/login attempts and the user must wait until the configured lockout time expires in order to be unlocked. Adding any attempted login attempt may be quite significant, would having the ability to see just lockouts be sufficient as it would also capture too many login attempts by such users without flooding the app log? (Understanding the goal is to have better visibility to locked users)

    Can you please confirm that this request is asking for the ability to audit the admin console attempted user logins only and not including Storefront website logins?

    1 reply
  • Optimizely
    Sara Winter
    Reply
    |
    Aug 22, 2024

    Thank you for submitting this request! Our team is currently reviewing this request, particularly with consideration of our wide client base. We will update this ticket once we have completed this investigation.