Skip to main content

Security Log

Review staff sign-ins, failed logins, logouts, and blocked IP addresses under Settings → Security → Security Log.

Written by Jonathan Marbutt

The Security Log is where administrators review staff sign-in activity for your organization — successful logins, failed logins, logouts, and blocked IP addresses.


Where to find it

Open Settings, then go to Security and choose Security Log.


What you'll see

Each row includes:

  • Time — when the event happened

  • Event — the kind of event (Login success, Login failure, IP denied, or Logout)

  • User — the person involved, when known

  • IP Address — the network address used for the attempt

  • Source — where CoolFocus recorded the event from

  • Details — extra context, such as an invalid password or an address that is not on the approved list

You cannot add or edit log entries here. The log is a read-only history.


Event types

  • Login success — the person signed in and was allowed into CoolFocus

  • Login failure — sign-in did not complete (for example, wrong password)

  • IP denied — the person was blocked because their IP address is not on your approved list

  • Logout — the person signed out

When a sign-in counts as Login success

A Login success is only recorded after the sign-in has passed your organization's IP address checks.

If IP Address Access blocks someone, you will see an IP denied event instead of Login success — even if they entered the correct password with your identity provider. That keeps the log from showing a successful sign-in for someone who was not actually allowed in.


Filter and search

  • Use the Event type filter to show one kind of event, or all events

  • Use the from and to date fields to limit the list to a date range

  • Use the search box to find matching text in the log

Changing a filter refreshes the list to match.


Choose Export CSV to download the log as a CSV file. The export covers whatever the Event type filter, date range, and search box are currently set to, not just the rows shown on the page.

Only administrators can export the log, and a single export is limited to 50,000 rows. If your filtered results exceed that, narrow the date range or event type and try again.


Approve a blocked IP

When someone is blocked by IP restrictions, an IP denied row can show an Approve IP button.

  • Choose Approve IP to add that address to your approved IP list so they can try again

  • Approval from this page is only available for a short time after the blocked attempt (about 30 minutes)

  • If the button is unavailable, ask the person to try signing in again so a fresh row appears, or add the address yourself under Settings → Security → IP Addresses

For more on approved locations, see IP Address Access.


When this helps

Use the Security Log when you are:

  • Investigating a reported sign-in problem

  • Confirming that IP restrictions are blocking or allowing access as expected

  • Reviewing recent sign-in activity for your organization


Security Log vs User Logs

The Security Log covers sign-in, logout, and IP denial history only.

If you need one timeline that also includes clinical record access and field-level record changes for a person, use User Logs instead.


Related

Did this answer your question?