Hi,
in our company (about 1000 git users) we have the problem that some users forget where they set up their credentials. Some use Jenkins and configure credentials per job. Some have installed more than 3 GIT clients using different credential-stores... etc. mostly you can't imagine whar crude ideas they have.
The problem is: we have a policy to change the user password in a regularly basis. This leads these users into a problem: always having their account captcha-locked due to password change and not knowing which "client" is causing this.
For me, as admin the Problem is: How can I obtain the IP-address or Repository (for possible job search) a system is trying to access and causes the CAPTCHA lock?
What is the effecitve way to look into the atlassian-bitbucket.log or atlassian-bitbucket-access.log and find an answer to the question:
When and which IP-adress is causing a captcha lock for user <xyz>?
looking only for "captcha" in the access-log I only find:
"<IP> | https | o@PE2R7Xx957x831907x1 | - | 2018-10-12 15:57:50,515 | "GET /captcha HTTP/1.1" | "https://gitserveradress/login" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0" | 200 | 0 | 9220 | - | 275 | 120zft0 |"
this sadly does not answer WHOM account. It also seems it does not show up if a GIT-CLIENT is getting/requesting via pull and gets a captchalock response.
We only have https access enabled.
Any ideas? thank you so much.