Understanding detected events
How Syspeace Service turns Windows sign-in activity into a detected event.
Syspeace Service follows the Windows Security event log for sign-in activity on the server it’s installed on. This requires Windows to actually be logging that activity — see Enable Windows audit logging for sign-in attempts if events aren’t appearing.
What counts as an event
Both failed and successful sign-in attempts are recorded. A single failed sign-in is not, by itself, treated as an attack — Syspeace evaluates the pattern of activity from a given source against your configured rules and thresholds before deciding to block it. A person mistyping their own password once is a normal, expected event, not a block trigger.
Where to see events
- Current blocks shows which addresses are presently blocked.
- Access Log is a searchable history of successful and failed sign-in attempts.
- IP activity shows the individual sign-in attempts behind a specific address, and which rule (if any) acted on them.
All of these are reviewed from Syspeace Console. See Understanding blocking behavior for what happens once a rule is triggered.