Help Center> Host Security Service (New)> FAQs> Abnormal Logins> How Do I Check the User IP address of a Remote Login?
Updated on 2024-03-25 GMT+08:00

How Do I Check the User IP address of a Remote Login?

Alarm Policies

The remote login detection function checks for remote logins into your servers in real time. HSS generates an alarm if it detects logins from locations other than the common login locations you set.

Viewing Remote Login Records on the Console

  1. Log in to the management console.
  2. In the upper left corner of the page, select a region, click , and choose Security & Compliance > HSS.
  3. As shown in Figure 1, check the Abnormal logins. Click Remote Login and click the alarm name to view details.

    Figure 1 Abnormal logins

Locally Viewing Remote Login Records

  • Linux

    For Linux servers, you can view logs in /var/log/secure and /var/log/message directories, or run the last command to check whether there are abnormal login records.

  • Windows
    To view server login logs, perform the following steps:
    1. Open Control Panel.
    2. Choose Administrative Tools > Event Viewer. The Event Viewer page is displayed.
    3. In the navigation tree on the left, choose Windows Logs > Security. The Security page is displayed.
    4. In the navigation tree on the right, choose Security > Filter Current Log. The Filter Current Log dialog box is displayed.
    5. On the Filter tab, locate the <All Event IDs>.
    6. Enter the login event ID and click OK to filter the target login events.
      • 4624: ID of successful login events
      • 4625: ID of failed login events

Abnormal Logins FAQs

more