get_login_failures_by_ip
Retrieve login failure counts grouped by source IP to identify brute-force attacks and suspicious login patterns within a specified date range.
Instructions
Get login failure statistics broken down by source IP.
Time-bounded: this call stops after KEYCLOAK_DEADLINE seconds (default 45) and returns what it has; the counts are then a lower bound. The result then starts with a "PARTIAL RESULT" warning. Call again with a narrower window instead of retrying the same call. A wide window on a busy day is what triggers it.
Args: date_from: Start date (YYYY-MM-DD). Defaults to last 24h when omitted (KEYCLOAK_DEFAULT_DATE_FROM_HOURS). date_to: End date (YYYY-MM-DD). Empty for all. top: Number of top IPs to show (default 20).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | ||
| date_to | No | ||
| date_from | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |