Short Answer: Find the event row in Access logs, note Date, User and Action, copy the IP address and investigate further external IP lookup or escalate to your security team.
PreRequisites
-
Open 'Settings' > 'Security' > 'Access logs'
-
Access to an external IP lookup tool or security contact
Steps
-
Open 'Access logs' and locate the row with the suspicious 'IP address'.
Row with the IP for example '192.108.1.1' is visible. -
Note the row’s Date, User and 'Action' e.g., 'New device' or 'Incorrect password'.
You have context for the suspicious access. -
Compare the 'Location' shown to the user's normal location or expected region.
A mismatch is flagged for follow-up. -
Copy the IP address and run an external IP lookup or share details with your security/admin team for further analysis.
You obtain additional geolocation/ASN information about the IP. -
If the IP is confirmed suspicious, follow your incident response steps for example, require password reset, revoke sessions, block IP.
Appropriate containment steps are initiated by your security team.
Troubleshooting
-
Location shown looks incorrect different country than expected.
LikelyCause: IP geolocation is approximate or user may be using VPN/proxy.
Action: Verify with the user whether they were using a VPN; perform an external IP lookup for more detail. -
IP in logs is internal or appears masked.
LikelyCause: Network NAT, proxy or private addressing may mask the true client IP.
Action: Coordinate with your network/security team to trace the source or request additional logs.
Note: Access logs give the evidence IP, timestamp, Action you need to escalate; additional investigation often happens outside this page.