What does a failed login or login attempt actually prove?¶
A failed login shows that an authentication process started but did not complete successfully.
The useful next step is to find the failure reason and look at the surrounding pattern.
Why did it fail?¶
The record may show:
- an incorrect password;
- an unknown username or account;
- a missing or failed second factor;
- an expired password, token or session;
- a locked or disabled account;
- a security or location policy block; or
- a technical error.
Keep the result code and its description. If the wording is unclear, ask the service or system administrator what that code means.
What may have caused it?¶
A failed attempt could come from:
- a user mistyping their password;
- a device trying old saved credentials;
- an application reconnecting in the background;
- someone trying possible passwords; or
- an automated tool testing one or many accounts.
The pattern helps distinguish these possibilities.
Look around the event¶
Check for:
- repeated attempts against the same account;
- attempts against many accounts;
- changes in source IP address or device details;
- a successful login before or after the failures;
- password resets or multi-factor prompts; and
- account activity following any successful access.
One failed attempt may be routine. A burst across many accounts, or repeated failures followed by success, can be much more useful.
Keep the fields that connect the pattern¶
Retain the timestamp and time zone, source IP address, account identifier, failure code, device or browser details, and any event or session identifier.
Does the same IP across several events mean the events are connected? explains how to use a repeated address as part of that comparison.
Operational takeaway
A failed login records an unsuccessful authentication event. Find the reason, preserve the surrounding attempts and look for the pattern before and after it.