Skip to content

Admin List User Auth Events

cognitoidentityprovider_admin_list_user_auth_events R Documentation

Requests a history of user activity and any risks detected as part of Amazon Cognito threat protection

Description

Requests a history of user activity and any risks detected as part of Amazon Cognito threat protection. For more information, see Viewing user event history.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

Usage

cognitoidentityprovider_admin_list_user_auth_events(UserPoolId,
  Username, MaxResults, NextToken)

Arguments

UserPoolId

[required] The Id of the user pool that contains the user profile with the logged events.

Username

[required] The username of the user that you want to query or modify. The value of this parameter is typically your user's username, but it can be any of their alias attributes. If username isn't an alias attribute in your user pool, this value must be the sub of a local user or the username of a user from a third-party IdP.

MaxResults

The maximum number of authentication events to return. Returns 60 events if you set MaxResults to 0, or if you don't include a MaxResults parameter.

NextToken

This API operation returns a limited number of results. The pagination token is an identifier that you can present in an additional API request with the same parameters. When you include the pagination token, Amazon Cognito returns the next set of items after the current list. Subsequent requests return a new pagination token. By use of this token, you can paginate through the full list of items.

Value

A list with the following syntax:

list(
  AuthEvents = list(
    list(
      EventId = "string",
      EventType = "SignIn"|"SignUp"|"ForgotPassword"|"PasswordChange"|"ResendCode",
      CreationDate = as.POSIXct(
        "2015-01-01"
      ),
      EventResponse = "Pass"|"Fail"|"InProgress",
      EventRisk = list(
        RiskDecision = "NoRisk"|"AccountTakeover"|"Block",
        RiskLevel = "Low"|"Medium"|"High",
        CompromisedCredentialsDetected = TRUE|FALSE
      ),
      ChallengeResponses = list(
        list(
          ChallengeName = "Password"|"Mfa",
          ChallengeResponse = "Success"|"Failure"
        )
      ),
      EventContextData = list(
        IpAddress = "string",
        DeviceName = "string",
        Timezone = "string",
        City = "string",
        Country = "string"
      ),
      EventFeedback = list(
        FeedbackValue = "Valid"|"Invalid",
        Provider = "string",
        FeedbackDate = as.POSIXct(
          "2015-01-01"
        )
      )
    )
  ),
  NextToken = "string"
)

Request syntax

svc$admin_list_user_auth_events(
  UserPoolId = "string",
  Username = "string",
  MaxResults = 123,
  NextToken = "string"
)