Contents

Alert Rules - Plugixa Activity Log

An alert rule says when this happens, tell them, there. Where free notifications decide by severity alone, a rule lets Priya hear about refunds in Slack while Daniel gets failed administrator sign-ins by email.

The Alert rules list, showing each rule’s name, the conditions it matches, its channels, an on/off switch and the test, edit and delete actions

Pro feature. Alert rules are part of Plugixa Activity Log Pro. See the Free vs Pro matrix.

A rule is conditions plus channels

Open Alert rules and choose New rule. A rule needs a name and at least one channel. Everything else narrows it.

The rule editor, with the name, the conditions an event must match, the channels to send to and the quiet period

Conditions

Condition Matches when
Areas The event belongs to one of these areas (sign-ins, users, content…).
Specific events The event has one of these codes.
At least this severe The event’s severity is this or higher.
Done by these roles The person who did it has one of these roles.
About these kinds of object The event is about one of these object types.
Message contains The text appears in the message, the object’s name or the username. Not case sensitive, up to 100 characters.
From these IP addresses The event came from one of these. One per line, single addresses or CIDR ranges.

Every condition you fill in must hold. An empty one does not narrow. Within one condition, any of the listed values is enough. So Areas: Sign-ins plus Done by these roles: Administrator means administrator sign-in events only.

A rule with no conditions matches every event. That is allowed, and it is occasionally what somebody wants, but it is rarely what somebody meant.

Two more conditions exist only through the REST API, not in the editor: an exact list of severities (severities) and a list of user IDs (user_ids).

Channels

A rule can send to up to 10 places, in any mix.

Channel You give it
Email An email address
Slack A Slack incoming webhook URL
Discord A Discord webhook URL
Microsoft Teams A Teams incoming webhook URL
Webhook (signed JSON) Any https:// URL of your own, and optionally a signing secret

Chat messages list the first 10 events of a batch and summarise the rest as “and N more”. Text is sent as plain text with markup neutralised, so a username like @everyone typed into a failed sign-in cannot ping a whole channel.

Email sent by rules counts against the same hourly email cap as Notifications.

URLs must be public and https

A webhook URL is a request your server makes to an address somebody typed. Without a guard, that is a way to probe the private network behind the site. So a URL is refused when:

  • it is not https://;
  • it points at localhost, or a name ending in .localhost, .local or .internal;
  • it is an IP address in a private, loopback, link-local or reserved range.

The check runs when you save and again when sending, where the host name is resolved and refused if it now points into one of those ranges. Redirects are not followed.

Signed webhooks

Give a webhook channel a Signing secret and every request carries:

X-Plugixa-Signature: sha256=<hex HMAC-SHA256 of the raw request body, keyed with the secret>

Compute the same value on your side and compare before trusting the payload. The body is JSON with source, site, rule (id and name) and events.

The secret is never shown again. After saving it appears as •••• followed by its last four characters. Leave that as it is to keep the secret, or type a new one to replace it. Clearing the field removes it, and so does switching the channel to another type.

Changing the URL keeps the secret. Edit the address, leave the masked secret alone, and the alerts sent to the new address are signed with the same secret. That is safe because the secret never travels: it only keys the signature, so the new address learns nothing from it.

Quiet period

Quiet period after firing (minutes) is the throttle. 0 sends every match. Otherwise, after the rule fires it stays silent for that long, up to 1440 minutes (a day).

Events that match during the quiet period are not sent later. They are in the log; the rule simply does not announce them. Use it for noisy rules where one message means “go and look”, not for rules where every event matters.

Delivery and retries

Rules deliver through the same background queue as free notifications. Nothing is sent on the request that recorded the event; WP-Cron sends a moment later.

  • Any 2xx answer is success. The plugin waits up to 5 seconds for a receiver.
  • A failure is retried after 1, 2, 4 and 8 minutes.
  • After the fifth failure the delivery is dropped and event 9011 is recorded, naming the channel and the receiving host.

Because rules use that queue, they need the Notifications module to be on. The free email switch in Settings can stay off; the module itself cannot.

The Test button

Send a test on a rule’s row delivers a sample alert to every channel of that rule, now, and reports how each one went: Delivered, or the reason it was not. The test ignores the conditions and the quiet period, so it tells you about the channels and nothing else.

What never triggers a rule

The plugin’s own events, codes 9000 and above, never trigger alerts. They cannot be chosen under Specific events, and a rule with no conditions still skips them. Changing a rule is itself recorded (event 9120), so the trail of who edited the alerting is in the log.

Managing rules needs the permission to change the plugin’s settings.

Troubleshooting

Symptom Usual cause
“Alert URLs must use https://” The URL is http://. Only https is accepted.
“Alerts cannot be sent to this machine or the private network” The URL points at localhost or a private address.
The rule fired once and went quiet The quiet period. Set it to 0 to send every match.
A rule matches nothing Every filled condition must hold. Empty one and try again.
The test works but real events do not arrive The conditions do not match, or WP-Cron is not running.
The receiver rejects the signature Sign the raw body, not re-encoded JSON, and check both ends hold the same secret.
A settings change did not alert Codes 9000 and above never alert.
“Add at least one place to send the alert” A rule needs a channel with an address or URL.

What to do next

Quick Links