Understanding Sonicwall Credential Auditor Event Logs

Description

The Credential Auditor feature in SonicOS enhances security by detecting user credentials that may have been exposed in known data breaches. It compares login attempts against a database of compromised credentials and generates event logs accordingly.

Starting with, SonicOS 7.3.3 and SonicOS 8.2.2, the Credential Auditor is enabled by default.

For a full overview of the feature, refer to:
https://www.sonicwall.com/support/knowledge-base/understanding-and-using-credential-auditor-on-sonicwall-firewalls/kA1VN00000088Bh0AI

 

Event Message

"Allowed a login attempt by a user whose password was found to have possibly been compromised."

 
What This Event Means

This event indicates that:

  • A user successfully authenticated to the firewall or an associated service.
  • The password used in the login attempt matches an entry in the Credential Auditor database.
  • The system has identified the password as potentially compromised (e.g., exposed in previous data breaches).
  • Despite the risk, the login was allowed, depending on current policy settings.
  • This event is generated for users authenticated through external authentication mechanisms (e.g. LDAP) when the supplied password is identified as compromised by the Credential Auditor database.

Note: This event does not indicate an active breach, but rather a high-risk condition.

To block the login of externally authenticated users with a potentially compromised password, please navigate to DEVICE | Users | Settings - Credential Auditor. Under DURING LOGIN, Enable "Block login of externally authenticated users with a compromised password"

 

Event Message

"Credential Auditor file download failed."

What This Event Means
This event indicates that:
  • The firewall failed to download the Credential Auditor database required for identifying compromised credentials.
  • The Credential Auditor feature relies on a periodically updated database. If the firewall cannot retrieve this file, the feature will not function as intended.
  • The firewall is not registered on mysonicwall.com or is not In-Sync with mysonicwall.com license manager

For registering the SonicWall firewalls, refer to: Register firewall

For  syncing licenses on the SonicWall firewall, refer to: Synchronize Licenses

Issue ID

GEN8-16608

Related Articles

  • SonicWall NetExtender 10.3.4 – “SonicWall NetExtender service does not respond!” Error
    Read More
  • SSLVPN user sessions timeout after upgrading to NetExtender version 10.3.5
    Read More
  • GEN8 Firewalls show Down status in On-Prem Syslog Analytics
    Read More
not finding your answers?