Device Fingerprint
Using the dashboardRisk Signals

Investigate risk signals

Risk Signals: Investigate risk signals

Enter the event from the signal card

Click View Log on the signal card, and the system will enter the event page and bring in the current investigation conditions:

  • Current application.
  • Current time frame.
  • Current Signal Code.

You can continue to add Request ID, Device ID or IP address filters to view specific events.

Illustration: Signal entry event

View the associated Request ID and Device ID

After entering the event list:

  1. View the events that hit the signal.
  2. Record or copy the Request ID and compare it with the server log.
  3. Check the Device ID to determine whether there are duplicate device activities.
  4. Open the event details and confirm the device, network, and other signals at the time.
  5. If you need to know the device history, enter the visitor details.

Combine multiple signals to judge

A single signal may have multiple interpretations. A more reliable way to investigate is to combine:

  • Other signals hit by the same event.
  • Historical events for the same Device ID.
  • Account, order, registration, and login behavior.
  • IP, device type and client platform.
  • level together with confidence.

For example, "VPN" appearing alone may be a normal privacy use; if there are abnormal device environments, a large number of requests in a short period of time, and multiple account associations at the same time, the risk judgment will be more complete.

Graphic: Multiple risk signals in event details