1. login events
Anzenna Public API
  • How To Use the Anzenna Public API
  • data exfiltration
    • Query database exfiltration events
      POST
    • List file delete events
      POST
    • List file movement activities
      POST
    • Get file movement activity by id
      GET
    • List files used with data exfiltration.
      POST
    • Get a specific data exfiltration file
      GET
    • List git events
      POST
    • Get a specific git event by id
      GET
    • List git repositories
      POST
    • Get a specific git repository
      GET
  • api key
    • Get API key information
      GET
  • login events
    • List login events
      POST
    • Get a login event by ID
      GET
  • browser applications
    • Query all browser applications
      POST
    • Get a browser application by id
      GET
    • List browser application instances
      POST
  • browser history
    • List browser history entries
      POST
  • data sharing
    • List file sharing instances
      POST
    • Query database share grants
      POST
    • Query database share user additions
      POST
    • List documents
      POST
    • Get document by id
      GET
  • devices
    • List devices
    • Get a device
    • List USB device connection events
    • Get a USB connection event
  • device policies
    • List device policies
    • Get a device policy
  • device applications
    • List device applications
    • Get a device application
    • Query device application instances.
  • device infections
    • List device infections
    • Get a device infection
  • ide applications
    • List IDE applications
    • Get an IDE application
  • ide application instances
    • Query IDE application instances.
  • mcp servers
    • List MCP servers
    • Get an MCP server
    • Query MCP server installations
  • mfa
    • Query all mfa statuses
    • Get an MFA status by id
  • oauth applications
    • Query all OAuth applications
    • Get an OAuth application by id
    • Query all OAuth application instances
  • passwords
    • Query all password reuse instances
  • people
    • Query all people
    • Get departure analysis for a person
    • Get a person by id
    • Add a category to multiple people
    • Remove a category from multiple people
  • account
    • List accounts
    • Get an account by id
  • phishing interactions
    • Query all phishing interactions
  • email flows
    • Query all outbound email events
    • Get an outbound email event by id
  • company wide risk trends
    • Get company risk trends
  • high risk organizations
    • Get number of high risk organizations
  • detections
    • Get key finding detections
    • Get detection details
    • List users associated with a given detection
  • events
    • List security events
  • shadow it
    • Query all Shadow IT instances
  • web host
    • Query all web host resources
    • Get a web host resource by id
  • advanced query
    • Execute an advanced query
  • sources
    • Query raw events
  • allowlist
    • Query all allowlists
    • Create a new allowlist
    • Delete an allowlist
    • Update an allowlist
  • anomalies
    • Get an anomaly by ID
  • groups
    • List groups
  • investigations
    • Query all investigations
    • Get an investigation by id
    • Get detection investigation prompts
    • Get global investigation prompts
    • Get user investigation prompts
  • rdp connections
    • Query all remote machines
    • Get a remote machine by id
  • risk registers
    • Query all risk registers
    • Query all risk register catalog entries
  • shadow ai
    • Query all Shadow AI instances
    • Get a Shadow AI instance by id
  • training
    • List training campaigns
    • Create a training campaign
  • webhooks
    • Receive a webhook event
  • ai audits
    • Query all AI audit events
    • Get an AI audit event by id
  • dlp policies
    • List DLP policies
    • Get a DLP policy by id
    • List DLP policy detectors
  • remediations
    • Execute a remediation
  • dlp alerts
    • Query all DLP alerts
    • Get a DLP alert by id
  1. login events

Get a login event by ID

GET
/login-events/{id}
Retrieve a specific login audit event by its unique identifier

Request

Authorization
Path Params

Responses

🟢200OK
application/json
Successful operation
Bodyapplication/json

🟠400Bad Request
🟠401Unauthorized
🟠403Forbidden
🟠404Record Not Found
Request Request Example
Shell
JavaScript
Java
Swift
curl --location '/login-events/'
Response Response Example
{
    "allowlisted": true,
    "authentication_details": [
        {
            "authentication_method": "Password",
            "authentication_method_detail": "Password in the cloud",
            "authentication_step_result_detail": "MFA requirement satisfied by claim in the token",
            "succeeded": true
        }
    ],
    "challenge_method_kinds": [
        "security_key",
        "password"
    ],
    "client_app": "Browser",
    "conditional_access_status": "failure",
    "device": {
        "activation_lock": "unspecified",
        "active_usb_connections": {
            "composite_count": 0,
            "hid_count": 2,
            "kvm_count": 0,
            "max_usb_risk_level": 1,
            "network_adapter_count": 0,
            "storage_count": 1,
            "unknown_count": 0
        },
        "antivirus": "unspecified",
        "apps_installed": 47,
        "disk_encryption": "unspecified",
        "employee_email": "joe.smith@example.com",
        "employee_name": "Joe Smith",
        "id": "8CA67511-744C-4D74-B26E-7281CF88712F",
        "last_seen": "2021-01-01T00:00:00Z",
        "last_usb_usage": "2021-01-01T00:00:00Z",
        "local_user_accounts": [
            {
                "admin": true,
                "name": "John Doe",
                "user_id": "S-1-5-21-1234567890-1234567890-1234567890-1001",
                "username": "john.doe"
            }
        ],
        "mac_addresses": [
            "00:1B:44:11:3A:B7"
        ],
        "mdm": "unspecified",
        "model": "MacBook Pro",
        "name": "Joe's Mac",
        "platform": "windows",
        "risk_factors": [
            {
                "magnitude": 40,
                "type": "sensitive_file"
            }
        ],
        "risk_score": 9.2,
        "serial_number": "C02X1234DC79",
        "sources": [
            "unspecified"
        ]
    },
    "device_id": "device-123456",
    "employee": {
        "categories": [
            "automation"
        ],
        "departed_time": "2021-01-01T00:00:00Z",
        "department": "EPD",
        "email": "joe.smith@example.com",
        "id": "8CA67511-744C-4D74-B26E-7281CF88712F",
        "job_category": "engineer",
        "job_title": "Engineer",
        "last_login": "2021-01-01T00:00:00Z",
        "location_city": "San Francisco",
        "location_country": "USA",
        "location_state": "CA",
        "manager_email": "john.lopez@example.com",
        "manager_name": "John Lopez",
        "name": "Joe Smith",
        "password_changed": "2021-01-01T00:00:00Z",
        "risk_factors": [
            {
                "magnitude": 40,
                "type": "sensitive_file"
            }
        ],
        "risk_score": 9.2,
        "state": "unspecified"
    },
    "employee_email": "john.doe@example.com",
    "employee_name": "John Doe",
    "external_id": "login_success/user@example.com/2025-01-15T14:30:00Z",
    "high_prevalence": true,
    "id": "8CA67511-744C-4D74-B26E-7281CF88712F",
    "impossible_travel_detail": {
        "distance_miles": 5823.4,
        "from_city": "San Francisco",
        "from_country": "US",
        "speed_mph": 1250.7,
        "to_city": "Amsterdam",
        "to_country": "NL"
    },
    "ip_address": "192.168.1.100",
    "ip_chain": [
        {
            "city": "Amsterdam",
            "country": "NL",
            "ip": "203.0.113.45",
            "source": "proxy",
            "version": "V4"
        }
    ],
    "is_allowed_vpn": true,
    "is_foreign_country": false,
    "is_impossible_travel": false,
    "is_new_ip_network": false,
    "is_off_hours": false,
    "is_proxy_login": false,
    "is_service_account": false,
    "is_suspicious_client": false,
    "location_city": "San Francisco",
    "location_country": "USA",
    "location_state": "CA",
    "login_audit_kind": "failed_login",
    "login_time": "2025-01-15T14:30:00Z",
    "network_context": {
        "as_number": 14061,
        "as_org": "DigitalOcean, LLC",
        "domain": "digitalocean.com",
        "isp": "Comcast Cable"
    },
    "network_origin": {
        "geographic_location": {
            "city": "San Francisco",
            "country": "United States",
            "country_code": "US",
            "latitude": 0,
            "longitude": 0,
            "region": "California",
            "timezone": "America/Los_Angeles"
        },
        "ip": "203.0.113.45",
        "network": {
            "asn": "AS15169",
            "asn_name": "Google LLC",
            "host_type": [
                "HOSTING",
                "ANYCAST"
            ]
        },
        "privacy": {
            "privacy_mode": [
                "VPN"
            ],
            "service_name": "NordVPN"
        }
    },
    "proxy_detail": {
        "kind": "vpn",
        "source": "NordVPN"
    },
    "risk_factors": [
        {
            "magnitude": 40,
            "type": "sensitive_file"
        }
    ],
    "risk_level": "high",
    "risk_score": 25.5,
    "sign_on_mode": "auto_login",
    "source": "unspecified",
    "token_protection": "bound",
    "user_agent": {
        "browser": "Chrome",
        "os": "Mac OS X",
        "raw": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36"
    },
    "vpn_operators": [
        "GLOBAL_PROTECT_CLOUD_VPN"
    ]
}
Modified at 2026-07-24 15:31:52
Previous
List login events
Next
Query all browser applications
Built with