Back to How-To Guides
Security & Monitoring Security Event Monitoring

Security Event Monitoring

Monitor security events, track failed login attempts, and protect your network infrastructure

Intermediate 10 minutes

Step 1: Access Security Events Dashboard

Navigate to Security → Security Events in the left sidebar to access the comprehensive security monitoring dashboard.

The Security Events page provides real-time visibility into security-related activities across your network infrastructure. Key features include:

  • Security Event Statistics: Overview cards showing total events, critical alerts, and security trends
  • Event Timeline: Visual timeline displaying security events over time
  • Event Categories: Organized view of different security event types
  • Real-Time Updates: Automatic refresh to show the latest security events

Security Event Types You'll Monitor (Examples):

  • Authentication Failures: Failed login attempts and unauthorized access attempts
  • Configuration Changes: Unauthorized or suspicious configuration modifications
  • Security Violations: MAC address violations, port security breaches
  • Access Control Events: 802.1X authentication failures, MAB violations
  • Network Intrusions: Suspicious network activity and potential attacks

Note: These are just examples - the system monitors many more security event types based on your network infrastructure and device configurations.

The dashboard automatically categorizes and prioritizes events by severity, helping you focus on the most critical security issues first.

Step 2: Analyze Security Events and Filter Results

The Security Events table displays detailed information about each security event, allowing you to investigate and respond to threats effectively.

Event Information Displayed:

  • Timestamp: Exact date and time when the security event occurred
  • Device: Source device name or IP address where the event originated
  • Severity: Color-coded severity levels (CRITICAL, ERROR, WARNING, INFO)
  • Event Type: Category of security event (Authentication, Configuration, Violation, etc.)
  • Description: Detailed description of the security event
  • Source IP: IP address associated with the security event

Powerful Filtering Options:

  • Severity Filter: Filter by CRITICAL, ERROR, WARNING, or INFO to focus on specific threat levels
  • Device Filter: View security events from specific network devices
  • Time Range: Select from Last Hour, 6 Hours, 24 Hours, 7 Days, 30 Days, or Custom range
  • Event Type Filter: Filter by specific security event categories
  • Search: Full-text search across all event fields for quick investigation

Using Filters Effectively:

  • Focus on Critical Issues: Select CRITICAL severity to see only the most urgent security threats
  • Investigate Specific Devices: Use device filter when investigating security issues on a particular device
  • Time-Based Analysis: Set custom time ranges to investigate security incidents that occurred at specific times
  • Pattern Detection: Review events over longer periods (7-30 days) to identify recurring security patterns

Best Practice: Regularly review CRITICAL and ERROR severity events to ensure immediate threats are addressed promptly.

Step 3: Monitor Failed Login Attempts

Navigate to Security → Failed Logins to access detailed tracking of authentication failures and potential brute force attacks.

The Failed Logins page provides specialized monitoring for authentication-related security events, helping you detect and prevent unauthorized access attempts.

Key Metrics Displayed:

  • Total Failed Logins: Total number of failed authentication attempts in the selected time period
  • Unique Devices: Number of different devices experiencing login failures
  • Unique IPs: Number of different source IP addresses attempting failed logins
  • Most Active IPs: IP addresses with the highest number of failed login attempts

Failed Login Details:

  • Timestamp: When the failed login attempt occurred
  • Device: Target device where the login attempt failed
  • Source IP: IP address of the system attempting to log in
  • Username: Username used in the failed login attempt
  • Failure Reason: Why the login attempt failed (wrong password, user not found, etc.)
  • Attempt Count: Number of failed attempts from the same source

Identifying Security Threats:

  • Brute Force Attacks: Multiple failed login attempts from the same IP address indicate potential brute force attacks
  • Unauthorized Access Attempts: Failed logins with unknown usernames may indicate reconnaissance activities
  • Account Compromise: Multiple failures for a known username may indicate password guessing attempts
  • Distributed Attacks: Failed logins from multiple IPs targeting the same device suggest coordinated attacks

Response Actions:

  • Block Suspicious IPs: Use firewall rules to block IP addresses with excessive failed login attempts
  • Review Account Security: Check if legitimate accounts are being targeted and consider password changes
  • Investigate Patterns: Analyze time patterns to identify automated attack schedules
  • Enable Additional Security: Consider implementing account lockout policies or two-factor authentication

Security Monitoring Configured!

You now have comprehensive security event monitoring in place. Backup Manager & Network Operations Suite helps you detect threats, track unauthorized access attempts, and maintain a secure network infrastructure with real-time security event analysis.