1. Overview
The Logsign SIEM Security settings page provides centralised control over three distinct policy areas: Password Policy, Session Policy, and Login Policy. Together, these controls define how users authenticate, how long their sessions remain active, and how the platform responds to repeated failed login attempts.
This guide covers all configurable fields visible on the Settings › System › Security screen:
- Password Policy: complexity requirements, expiry, and reuse prevention
- Session Policy: absolute session timeout and idle timeout
- Login Policy: account lockout on repeated failed attempts
- Api Key: platform API access credential management
The Password Policy, Session Policy, and Login Policy settings are stored as a single platform-wide policy. Password Policy rules are enforced for local user accounts; users that sign in through LDAP or Microsoft Entra ID are authenticated by that directory. A user that has Custom Expire Limits enabled on its user record (Settings › Accounts and Views › Users) uses its own Session Timeout and Idle Timeout values instead of the Session Policy on this page.
When you click Save, a confirmation dialog ("You are about to change your password policy!") opens. The new values are saved after you click Yes. If Enable Password Policies is On, the dialog reminds you that the SMTP mail settings must be configured so that users whose passwords do not meet the new policy can change them.
2. Navigation
Access all Security Policy settings via the top navigation bar:
Settings › System › Security
The Security menu item is visible only to super admin users.
3. Security Settings Screen
The screenshot below shows the complete Security settings page, including all three policy sections and the Api Key area.
Figure 1: Settings › System › Security, full policy configuration screen
4. Password Policy
The Password Policy section enforces authentication standards for local user accounts. The fields below Enable Password Policies are shown, and enforced, only when that switch is On.
4.1 Configuration Reference
| Setting | Default | Allowed Values | Description |
|---|---|---|---|
| Enable Password Policies | Off | Off / On | Master switch. When Off, the custom values below are not applied and the fields are hidden. |
| Minimum number of characters | 6 | 6 to 64 | Minimum total password length. |
| Minimum number of lowercase letters | 1 | 1 or more | Minimum number of lowercase characters (a to z) in the password. |
| Minimum number of uppercase letters | 1 | 1 or more | Minimum number of uppercase characters (A to Z) in the password. |
| Minimum number of digits or symbols | 1 | 1 or more | Minimum number of digits (0 to 9) or special characters (e.g. !@#$%) in the password. |
| Force change password | Off | Off / On | When On, the password entered at login is checked against the complexity rules above. A user whose current password does not meet them must change it before signing in. |
| Password must be changed | 0 Months | 0 or more, in Months or Days | Password rotation interval. A value of 0 means passwords never expire; the screen then shows "(Password never expires)". |
| Prevent Password Repetition | Off | Off / On | When On, users cannot reuse previously set passwords. The reuse history depth is controlled by Prevent Password Count. |
| Prevent Password Count | 3 | 0 to 24 | Number of previous passwords that cannot be reused. Shown only when Prevent Password Repetition is On. |
4.2 Setting Details
Enable Password Policies
This is the master switch for the entire Password Policy module. The custom complexity, expiry, and repetition rules are enforced only when it is On. When it is Off, new passwords are still checked against the built-in baseline (at least 6 characters, with at least one lowercase letter, one uppercase letter, and one digit or symbol).
Minimum Character Length
Defines the shortest acceptable password. The default is 6 and the field accepts values from 6 to 64. NIST SP 800-63B recommends a minimum of 8 characters; PCI-DSS v4.0 requires at least 12 for cardholder data environments.
Character Complexity Rules
Three independent thresholds work together to enforce password diversity:
- Minimum number of lowercase letters (default 1): requires at least that many a to z characters.
- Minimum number of uppercase letters (default 1): requires at least that many A to Z characters.
- Minimum number of digits or symbols (default 1): requires at least that many numeric digits or special characters.
Force Change Password
When set to On, the password a user enters at login is validated against the current complexity rules. If it does not meet them, the login is refused with a "Please change your password" message and the user must set a compliant password. Users whose passwords already meet the rules are not affected. Use this after tightening the complexity rules so that existing weak passwords are replaced.
Password Must Be Changed
Sets a mandatory rotation interval. Enter a number and select Months or Days next to it; one month is counted as 30 days. When the interval has passed since the user last changed the password, the login is refused with a "Password expired" message and the user must change the password. A value of 0 disables expiry entirely. For regulated environments (PCI-DSS, HIPAA, ISO 27001) a 90-day (3-month) or 180-day (6-month) cycle is standard.
Prevent Password Repetition
When enabled, the platform retains a history of previous passwords and rejects any new password that matches an entry in that history. The depth of the history is configured via the Prevent Password Count field (visible when enabled, 0 to 24, default 3).
4.3 Security Recommendations
| Setting | Default | Recommendation |
|---|---|---|
| Enable Password Policies | Off | Turn On so that the settings below are enforced. |
| Min. Characters | 6 | Increase to 10 to 12. Short passwords are vulnerable to brute-force and dictionary attacks. |
| Password Expiry | Never (0 Months) | Set to 90 days (3 months) or 180 days (6 months) to satisfy common compliance frameworks. |
| Force Change Password | Off | Turn On after raising the complexity rules, so that users with non-compliant passwords must update them at their next login. |
| Prevent Repetition | Off | Enable and set Prevent Password Count to 5 to 10 to block short-cycle reuse patterns. |
5. Session Policy
The Session Policy section controls how long a signed-in session stays valid. Both values are in minutes and are always visible, regardless of the Enable Password Policies switch.
| Setting | Default | Allowed Values | Description |
|---|---|---|---|
| Session Timeout (min) | 1440 | 5 or more | Absolute session lifetime. After this time the user must sign in again, even if the session is active. |
| Idle Timeout (min) | 15 | 2 to 60 | Inactive sessions are logged out after this period. |
To give a specific user different values, open the user under Settings › Accounts and Views › Users, turn on Custom Expire Limits, and set Session Timeout (min) and Idle Timeout (min) for that user.
6. Login Policy
The Login Policy section locks an account after repeated failed login attempts. The limit and timeout fields are shown only when Lock Account After Failed Attempts is On.
| Setting | Default | Allowed Values | Description |
|---|---|---|---|
| Lock Account After Failed Attempts | Off | Off / On | Enables account lockout. |
| Failed Attempts Limit | 5 | 2 to 10 | Number of failed logins that locks the account. |
| Failed Attempts Timeout (min) | 15 | 1 to 30 | Failed attempts are counted within this window, and a locked account stays locked for this many minutes. |
7. Api Key
The Api Key section shows the platform API key in the Key field, masked by default. Click Generate Api Key to create a new key. This button works independently of the Save button above it.