Suspicious logins
Open Journal -> Advanced Analytics -> Security. This report identifies accounts with repeated rejected attempts, attempts from multiple countries or signs of automation.
These are reasons to review activity, not proof of abuse. Travel, VPNs and device characteristics can explain unusual activity. The report does not block accounts.
Period and scope
The default is all projects and the last seven days. Select a project to choose a game server. All servers includes attempts without a server; selecting one server includes only attempts associated with it.
Choose a preset, a year or custom dates. Both dates are included in UTC. New events can take a short time to appear.
Selection criteria
| Field | Meaning |
|---|---|
| Minimum countries | Number of different known countries during the period. Defaults to 3; accepts values from 2. Leave blank to disable this criterion. |
| Minimum rejected attempts | Number of rejected sign-in attempts. Defaults to 10; accepts values from 1. Leave blank to disable this criterion. |
| Include signs of automation | Includes accounts with at least one attempt whose client identifies itself as automated. This is not verified bot identity. |
| Rows per page | 10, 25, 50 or 100 accounts. Defaults to 25. |
Keep at least one criterion enabled. An account needs to match any one of them. Refresh after changing filters; reset restores the defaults.
For example, to review only multiple-country activity on one server, choose its project and server, clear the rejection minimum and disable automation. Rejected-attempt counts remain visible in the rows but no longer affect selection.
Reading the results
The cards count matching accounts and matches for each enabled criterion across the entire result, not just the current page. An account can match several criteria, so adding the three counts does not give the overall total.
Each row represents an account in a particular project. Accounts from different projects are not merged by a shared ID or email.
| Column | Meaning |
|---|---|
| Account / project | Current email, project name and ID. A profile link is available with the corresponding permission. If the account is no longer available, its historical row remains with its ID. |
| Matched criteria | Enabled criteria responsible for including this account. |
| Countries | Different known countries. Unknown locations do not increase the count. |
| Unique IPs | Different addresses in the selected period. Alternate representations of the same IPv6 address are counted once. |
| Rejected / Successful | Counts of rejected and successful sign-in attempts. |
| Automated | Attempts showing an automated client signature, whether successful or rejected. |
| Last attempt | Latest attempt in the period, including rejected attempts. |
Accounts with more rejections come first, followed by more recent attempts. Next and Previous preserve the order. Changing filters or manually refreshing starts again from the first page. The table scrolls horizontally on narrow screens.
Attempts without an identified account are excluded here. Review those in the login journal.
Empty results and errors
No matches means the available history contains no matching accounts for the chosen dates. It does not establish the absence of risk outside that period.
Refresh if the page expires or the history changes. Select a project or shorten the period if the result is too large. When data is temporarily unavailable, a warning appears and previous rows are hidden until a successful refresh.