Test search and privacy together

An incident responder should be able to find all resets for one account and all failed sign-ins from one device reference. That calls for stable IDs and event names. It does not call for raw passwords, OTPs, or full IP history in every log. Test with fake secret values and search every log sink. Restrict access to events that show customer behavior and set a retention period approved by the data owner.

Search with fake secrets

Create unique fake password and OTP values. Trigger failed sign-in, successful sign-in, code resend, support reset, and session revocation. Search device logs, central logs, alerts, and support views for those exact values. They should not appear. Then try to reconstruct the event order using actor, account reference, action, time, outcome, and correlation ID. If staff cannot trace the flow without raw secrets, improve event structure rather than logging full requests.

Test cases and proof

Use test accounts and test data
CaseExpected resultProof to keep
Failed loginRecord result and safe contextAudit event
OTP submittedNever log code valueLog sample
Support resetRecord actor and approvalLinked audit events

Log the decision without logging the secret

Run four synthetic events: login success, login failure, step-up denial, and session revocation. Each event needs time, stable event ID, actor or anonymous identifier, action, outcome, and request link. Check that raw passwords, OTPs, access tokens, and full bank details are absent from both app logs and error traces. Change the log pipeline to fail in staging and confirm the product handles it under a written rule. Save a redacted sample and retention settings. An event that only says “login failed” cannot support an account review. (OWASP logging guidance).

Check delivery gaps and denied access

Use synthetic reset S-01 with event IDs for requested, approved, and completed. Drop the completed event at the collector, then search S-01 as an incident reader. The missing event must remain a visible gap; an approval alone cannot prove completion. Retry delivery of the approved event with the same event ID and confirm the search view does not count two approvals. Next, sign in as ordinary support and attempt to export the account history. Deny access unless the role rule grants it. For a log outage, state which actions stop, which use a durable buffer, and how the team gets an alert. Test that stated rule without filling the disk.

Keep account lookup safe

A failed sign-in can name an address that belongs to no account. Do not invent a customer ID for that event or make the logging query reveal whether the address exists. Use an anonymous attempt ID and the allowed masked lookup value. In the synthetic test, send three failures for known account A and three for an unknown address. The public responses must follow the same account-enumeration rule. An authorized responder can join the known failures by internal reference while ordinary support cannot list unknown submitted addresses. Store server event time and collector receipt time separately; delayed delivery must not make a support reset appear to happen before its request.

Related reading

Source