How to run a Report showing Failed Authentication Attempts in RSA Identity Governance & Lifecycle
Originally Published: 2015-09-10
Article Number
Applies To
RSA Version/Condition: 6.9.1, 7.x
Issue
Resolution
To view failed authentication attempts and other audit events, there is an Out-of-the-box (OOTB) Tabular Report that reports audit events for the last 30 days. In the user interface go to Reports > Tabular > Audit Events for the Past 30 Days > Run Report button. Once the report results are available, peruse the results for the LOGIN audit event. The LOGIN audit event audits login-related changes including failed authentication attempts.
Below is a sample of report output with successful and failed login attempts. If you export the report results (bottom right corner) to a CSV file, you can then sort the report on any of the table columns. In this case you could sort on Event Name to see all the LoginFailureAttempt events grouped together.
Related Articles
RSA Via Lifecycle and Governance 7.0 installation looping when running Oracle Cluster Verification Utility (CVU) cluvfy/ru… 71Number of Views RSA Announces the Availability of RSA Identity Governance Lifecycle 7.0.2 Patch 11 1Number of Views RSA Identity Governance and Lifecycle 7.5 AWS Installation and Clustering Guide 32Number of Views RSA Identity G&L 7.1.0 installation intermittently fails on SLES 12 where 'Hardware Lock Elision' functionality of the CPU… 40Number of Views RSA ID Plus Free Trial Playbook 304Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?