CORE MODULE

Auditing Login Activity

What you'll learn in this guide

A quick look at how login activity is tracked in CX Platform, what's captured in the audit log, and how to request a copy when you need one for security checks, compliance, or just peace of mind.

Overview

Knowing who's logging into your platform — and when, and from where — is one of those things that matters more than you'd think. Whether you're investigating a security concern, preparing for an audit, or simply keeping an eye on user activity, the login audit log gives you a clear, time-stamped record of what's been happening behind the scenes.

CX Platform keeps a detailed log of every login event across your environment. That includes who signed in, which module they accessed, the IP address they came from, and any additional context tied to the session.

Audit logs aren't surfaced directly in the interface. Instead, they're available on request, so you get exactly the slice of data you need without sifting through everything.

‍

How to access the audit log

To request an audit log, reach out to your Platform Administrator or raise a support request. The more specific you can be about what you're after, the faster you'll get something useful back.

Helpful things to include in your request:

  1. The date range you want covered.
  2. Any specific users or usernames you'd like activity for.
  3. The modules involved (for example, Send, Receive, Generate).

The type of event you're interested in, such as successful logins, failed attempts, or activity from a particular IP address.
‍

Quick tip
‍
If you're not sure exactly what you need, a short description of why you're asking ("looking into a possible unauthorised access attempt last Tuesday") usually gives the team enough to pull the right report on the first go.

‍

What's in the audit log

Here's a rundown of the information captured in each log, so you know what's available to ask for.

Feature What it captures
Event tracking Every login event is recorded with the details you need to piece together what happened. Each entry includes:
  • Event date and time — when the event took place.
  • Logged in user — the person whose account was used.
  • User IP address — where the login came from, handy for spotting unfamiliar locations.
  • Event description — a short summary of what happened.
  • Username — the account name tied to the event.
  • Message — any extra context or metadata about the session.
Search and filter Login logs can run to thousands of entries, so sorting and filtering options are available to help narrow things down. You can ask for the data ordered by date, user, IP address, or event type, so the report you get back is genuinely useful rather than a wall of rows to wade through.
Event details Each log entry shows you the wider picture of a session, not just that someone signed in. You'll see:
  • Application accessed — which part of CX Platform the user opened (for example, CX Platform - Generate or CX Platform - Receive).
  • Login event type — whether it was a successful sign-in, a failed attempt, or another kind of authentication event.
  • IP address — useful for security monitoring and spotting logins from unexpected places.
  • Session message data — additional context or metadata tied to the login, like browser or device information where available.

‍

When to request a log

There's no wrong reason to ask for one, but the most common scenarios are security investigations, periodic compliance checks, troubleshooting access issues for a specific user, or providing evidence for an audit. If something feels off — or you just want to confirm everything's behaving as expected — a quick request is the way to go.

That's it. Once you've sent your request through to your Platform Administrator or the support team, you'll get a copy of the log covering the activity you've asked about, ready to review.