Application access request denied log
# support
r
Hi Medplum team - To pass a security test, we need to provide a recent access denied request (failed authentication, authorization, or failed resource access) to our EHR by a user. Does Medplum log such events? If so where can we find them? Thank you!
@rahul1 @reshma Would appreciate your comments on this
r
Yes, we do , via the
Login
resource
Every Login attempt creates a
Login
resource. HOwever, these are only accessible by Super Admins
r
Thank you @rahul1 . When I enter "Login" in the Resource Type search bar, I got a "Forbidden" error. I'm already an admin. Do I need to be a super admin to access it? If so, where can I grant my account this permission?
Any idea on why my admin account cannot access "Login" resources? @rahul1 @reshma
r
Hi @rayliao_93919 , this resource is only accessible to Super Admin users. I was under the impression that you were self-hosting
If you're not self-hosting, you won't be able to access those resources from within your project. However, we do offer "Log Streaming" as part of our paid tiers. We could then stream features for your specific project back to your log collector of choice (e.g. DataDog, Sumo Logic, Splunk) https://www.medplum.com/pricing
r
Thanks @rahul1. We are considering getting on a paid tier. Sounds like we'll then be able to access logs with every login attempt.