Understanding IP, Device, and Country
Overview
IP, device, and country information gives additional context about where an activity may have originated.
What this feature does
It helps administrators review access patterns, detect unusual locations, and support security investigations.
Why it is useful
- It helps identify suspicious access.
- It supports login and activity investigations.
- It provides context when the same user account appears to perform unusual actions.
Who should read this?
RISE Admin, Security Officer, System Owner.
Where to find it
Activity Log, Auth Log, Security Dashboard, and related detail views where location or device data is available.
How to use it
- Open Activity Log or Auth Log.
- Review IP address and country fields.
- Compare activity with normal user behavior.
- Use Security Dashboard or Auth Log for deeper login context.
Example workflow
A staff member usually logs in from one country, but a sensitive invoice change appears from a new country. The admin reviews Auth Log and Security Dashboard before deciding whether the account is compromised.
Screenshot
Screenshot required
Capture from: Rise Audit Pro → Activity Log → IP / Country columns
Capture from: Rise Audit Pro → Activity Log → IP / Country columns
Common mistakes
- Treating IP location as perfect evidence. VPNs, proxies, and mobile networks can affect accuracy.
- Ignoring device and timestamp context.
- Sharing exported IP data without considering privacy policies.
Related articles
- IP and Country Lookup
- New Country Login Detection
- Security Dashboard Overview

