This article presents how to obtain a list of failed login attempts or other potentially malicious sign-on attempts.
- Reporting
- Suspicious Activity
- Okta Classic Engine
Watch the video or follow the steps below to obtain a list of failed login attempts or other potentially malicious sign-on attempts.
- In the Okta Admin Console, navigate to Reports > Reports.
- The Suspicious Activity section will provide a brief summary of failed logins and locked-out users over the past 30 days.
- For greater detail and a report that can be exported, click the Suspicious Activity header in the section.
- To export the report to a file, click the Download CSV link in the upper-right corner of the results table.
