# User lockout time after wrong password

**URL:** <https://community.graylog.org/t/user-lockout-time-after-wrong-password/27167>\
**Category:** Graylog Central (peer support)\
**Created:** [January 4, 2023, 6:48pm UTC](https://community.graylog.org/t/user-lockout-time-after-wrong-password/27167 "2023-01-04T18:48:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kavalaris](https://avatars.discourse-cdn.com/v4/letter/k/ee7513/32.png) [@kavalaris](https://community.graylog.org/u/kavalaris)\
**Post date:** [January 4, 2023, 6:48pm UTC](https://community.graylog.org/t/user-lockout-time-after-wrong-password/27167/1 "2023-01-04T18:48:32Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
I want to have an option to lockout a user that trie to put wrong password for 3 times for example

**2. Describe your environment:**

- OS Information:  
ubuntu server 20.04.5
- Package Version:

# v4.3.9

- Service logs, configurations, and environment variables:

**3. What steps have you already taken to try and solve the problem?**

**4. How can the community help?**

Hello and a Happy new year.  
I am new to graylog set up. until now with the post here I set up my log server with success.  
My issue now is that I should have a security option for my future employees and this is in the case of a user that trie to log in at the interface of graylog with 3 failed attempts his/her account should be deactivete for some time or until the admin unlock this user.  
I search but I dont find something simillar.

Thank you in advance

**Helpful Posting Tips:** [Tips for Posting Questions that Get Answers](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) [Hold down CTRL and link on link to open tips documents in a separate tab]

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 4, 2023, 11:02pm UTC](https://community.graylog.org/t/user-lockout-time-after-wrong-password/27167/2 "2023-01-04T23:02:39Z")

</div>

Hello && welcome @kavalaris

There isnt one I know of.

You do have a couple of choices thou. Connect the Graylog server to a Active Directory and adjust failed logon attempts there or Graylog Operation/Enterprise license you can use the SSo OIDC and adjust the failed logon attempts from there.

EDIT:  
you can ask for a feature request here

> **[Build software better, together](https://github.com/Graylog2/graylog2-server/issues/new/choose)**
>
> GitHub is where people build software. More than 94 million people use GitHub to discover, fork, and contribute to over 330 million projects.

---

<div class="post-metadata">

**Author:** ![patrickmann](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/patrickmann/32/9091_2.png) [@patrickmann](https://community.graylog.org/u/patrickmann)\
**Post date:** [January 5, 2023, 8:08am UTC](https://community.graylog.org/t/user-lockout-time-after-wrong-password/27167/3 "2023-01-05T08:08:04Z")

</div>

We already have a feature request for this:

> <https://github.com/Graylog2/graylog2-server/issues/13189>
>
> Graylog's implementation of users does not provide functionality to lock a user …account on a number of failed login attempts. While we rely on an external auth provider (LDAP, Okta, etc) to handle such an action, this may not be available in an organization that does not use SSO, or uses an auth provider that Graylog does not support. 
> 
> Source: HS-1032446263

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 19, 2023, 8:09am UTC](https://community.graylog.org/t/user-lockout-time-after-wrong-password/27167/4 "2023-01-19T08:09:04Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
