Home Setting How can I check a suspicious IP address or Location shown in Access logs?

How can I check a suspicious IP address or Location shown in Access logs?

Last updated on Aug 27, 2026

Short Answer: Find the event row in Access logs, note Date, User and Action, copy the IP address and investigate further external IP lookup or escalate to your security team.

PreRequisites

  1. Open 'Settings' > 'Security' > 'Access logs'

  2. Access to an external IP lookup tool or security contact

Steps

  1. Open 'Access logs' and locate the row with the suspicious 'IP address'.
    Row with the IP for example '192.108.1.1' is visible.

  2. Note the row’s Date, User and 'Action' e.g., 'New device' or 'Incorrect password'.
    You have context for the suspicious access.

  3. Compare the 'Location' shown to the user's normal location or expected region.
    A mismatch is flagged for follow-up.

  4. Copy the IP address and run an external IP lookup or share details with your security/admin team for further analysis.
    You obtain additional geolocation/ASN information about the IP.

  5. If the IP is confirmed suspicious, follow your incident response steps for example, require password reset, revoke sessions, block IP.
    Appropriate containment steps are initiated by your security team.

Troubleshooting

  1. Location shown looks incorrect different country than expected.
    LikelyCause: IP geolocation is approximate or user may be using VPN/proxy.
    Action: Verify with the user whether they were using a VPN; perform an external IP lookup for more detail.

  2. IP in logs is internal or appears masked.
    LikelyCause: Network NAT, proxy or private addressing may mask the true client IP.
    Action: Coordinate with your network/security team to trace the source or request additional logs.

Note: Access logs give the evidence IP, timestamp, Action you need to escalate; additional investigation often happens outside this page.