---
title: "Return login security brute force attacks by user"
method: GET
path: "/get_cphulk_user_brutes"
tags: ["cPHulk", "Reporting"]
---

# Return login security brute force attacks by user

`GET /get_cphulk_user_brutes`

This function lists brute force attack entries from the cPHulk database, ordered by user accounts.

## Response `200`

HTTP Request was successful.

- object
  - `data` object
    - `user_brutes` object[] — Information about each brute force attempt.
      - `authservice` string — The authentication service on which the login attempt occurred.
      - `exptime` string, ISO-8601 Date Time (Space Separated) — When the login request will time out.
      - `ip` union — The IP address of the login attempt.
        - string, ipv4
        - string, ipv6
      - `logintime` string, ISO-8601 Date Time (Space Separated) — When the login attempt occurred.
      - `service` string — The name of the service on which the login attempt occurred.
      - `timeleft` integer — The number of minutes that remain before cPHulk removes the block.
      - `user` string — The username for which login attempt occurred.
  - `metadata` object
    - `command` string — The method name called.
    - `reason` string — The reason the API function failed when the `metadata.result` field is 0. This field may display a success message when a function succeeds.
    - `result` 0 | 1 — * `1` - Success * `0` - Failed: Check the reason field for more details.
    - `version` integer — The version of the API function.

---

[API](https://skmtc.net/cpanel/apis/whm-api.md) · [All operations](https://skmtc.net/cpanel/apis/whm-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/cpanel/whm-api/revisions/3da41671c02c/schema)
