Identify User Last Login Success and Failure Attempts
search cancel

Identify User Last Login Success and Failure Attempts

book

Article ID: 428032

calendar_today

Updated On:

Products

Network Observability Spectrum

Issue/Introduction

Need a method to identify the last successful or failed login attempts for all users within the DX NetOps environment.

Unable to view last login timestamps in the standard User List tab.

Requirement to track account activity for security auditing.

Missing visibility for failed authentication attempts across different integration types.

Administrators lack a centralized view of user activity, potentially delaying the identification of unauthorized access attempts.

We found these attributes for user models but none of them appear to be working or showing correct values.

  • Users previous login timestamp
    • Attribute Name: User_prev_login_time
    • Attribute ID: 0x133f7
  • Users current login timestamp
    • Attribute Name: User_curr_login_time
    • Attribute ID: 0x133f8
  • Users failed login attempts count
    • Attribute Name: User_failed_login_attempts
    • Attribute ID: 0x133f9

Environment

Network Observability DX NetOps Spectrum releases 25.4.4 and older

Cause

This is caused by a defect in the product code. It is resolved via engineering defect DE161723.

It will ensure login attributes are correctly updated in the database for various authentication methods.

Resolution

Upgrade to a 25.4.5 or newer release to resolve this issue.

See the Spectrum Resolved Issues documentation topic for the DE161723 reference to see it's inclusion in 25.4.5. It shows:

  • Symptom: The user login attributes do not display any data.
  • Solution: With this fix, Spectrum implements the required code changes to ensure that the user login attributes now display the data.
  • (DE161723, 36059527, 36634214, 25.4.5)

Additional Information

SAML Integration failed attempt counts are currently not applicable for SAML authentication.