Viewing user activity

You can view the user's activity in Verify for the past 90 days.

Before you begin

  • You must have administrative permission to complete this task.
  • Log in to the IBM® Verify administration console as an Administrator.

About this task

Note: The activities that are listed are for the past 90 days only. Use the filtering options to modify your reports.
The reports provide the following individual user activity information:
Table 1. Individual activity information
Information Attributes Descriptions
Time Stamp time When the authentication request was made.
Event type event_type Indicates the type of event. For example, whether the event was a single sign-on, an authentication, or a management event.
Event type detail data.subtype Displays information about the event such as
  • Username and password
  • MFA
  • federation
  • social
Result data.result
  • Success
  • Failure
Performed by
Username
data.username
Realm
data.realm
Includes the
Username
The Unique identifier for logging in to Verify. It can be the same as the email address of the user.
Realm
The identity source attribute that helps distinguish users from multiple identity sources that have the same username.

This information is displayed in the Directory > Users & Groups > Users tab, and in the Edit User dialog box.

For the following identity sources,
  • Cloud Directory, the realm value is cloudIdentityRealm.
  • IBMid, the realm value is www.ibm.com.
  • SAML Enterprise, the realm value can be any unique name that you assigned when you created the identity source.
  • OnPrem LDAP, the realm value can be any unique name that you assigned when you created the identity source.
AccountExpiration The system disables the account based on the timestamp set in the user profile.
Client IP data.origin The IP address of the device that made the authentication request. The details contain an X-Force IP report link to evaluate the threat value of the address.
Location
  • geoip.region_name
  • geoip.country_name
The geographical location, region, and country, where the authentication request was made.
Note: The region might not display accurately because of the way your network is configured. This condition is a known limitation.

Procedure

  1. Select Directory > User & groups.
    Ensure that the Users tab is the active tab.
  2. If the user is not displayed on the page, use the search function to find the user.
  3. Hover over the user and select the User details icon when it appears.
  4. On the user's page, select the Activity tab.
    The page displays a table with the following activity information for each event.
    • Time stamp
    • Event type
    • Event type detail
    • Result
    • Performed by
    • Client IP
    • Location
    You can sort the table by any of the column headings except for the Event type detail and Location.
  5. Required: Select Filters to filter the results.
    You can search by,
    Identity
    Filter selection is performed by.
    Source
    Filter selections are client IP and location.
    Event details
    Filter selections are event type and results.
    You can use any combination of filters to refine your results. Select Apply filters to modify the report. The selected filters are displayed above the table. You can clear the filters by selecting the Reset link.
  6. Select and change the date range for the report. Select the From and To dates to display the calendar and select the dates for the report.
    Note: The To date cannot exceed the current date.
  7. Select Run Report.
    The information is displayed when refreshed.
  8. Select an event to see the event details.
    See User activity event types for a description of various event details.
  9. Export a CSV report.
    1. Select a user.
    2. Select Export CSV.
    3. Open and save the file.
    Note: For double-byte characters to display correctly in Microsoft Excel®, the CSV file must be imported as UTF-8.