Contents
Developer reference - Plugixa Activity Log
The other pages describe the plugin by what you see. This one lists the names code and scripts use: setting keys for WP-CLI and the REST API, the tables for a backup plan, the scheduled jobs for a server cron check, and the constants and capabilities.
Where settings are stored
Every setting lives in one option, plugixa_activity_log_settings. It is a
site option, so on a multisite network there is one copy for the whole
network.
Read and change settings through the plugin rather than the option, so a value passes the same checks as the Settings screen:
wp activity-log settings get
wp activity-log settings set retention_days 30
POST /wp-json/plugixa-activity-log/v1/settings
{ "retention_days": 30 }
A key the plugin does not recognise is discarded, and a value outside its range is brought back inside it. See WP-CLI and the REST API.
A key exists only while the feature that owns it is installed and switched
on. wp activity-log settings get prints the complete list for your site.
Setting keys
General, access and uninstall
| Key | Default | Values |
|---|---|---|
user_display |
display_name |
display_name, login, first_last |
records_per_page |
50 |
10 to 200 |
trusted_proxy_header |
empty | Empty, HTTP_X_FORWARDED_FOR, HTTP_CF_CONNECTING_IP, HTTP_X_REAL_IP, HTTP_TRUE_CLIENT_IP |
view_roles |
[] |
Role slugs that may read the log |
export_roles PRO |
[] |
Role slugs that may download the log |
event_overrides |
[] |
Event code to true or false, holding only the events moved away from their default |
delete_data_on_uninstall |
false |
true or false |
Retention and exclusions
| Key | Default | Values |
|---|---|---|
retention_days |
90 |
0 to 3650. Zero means no age limit |
retention_max_rows |
0 |
0 to 100,000,000. Zero means no count limit |
excluded_user_ids |
[] |
User IDs |
excluded_roles |
[] |
Role slugs |
excluded_ips |
[] |
Single addresses or CIDR ranges |
excluded_post_types |
[] |
Post type slugs |
Privacy and notifications
| Key | Default | Values |
|---|---|---|
privacy_ip_mode |
full |
full, truncate, none |
privacy_store_user_agent |
true |
true or false |
notify_enabled |
false |
true or false |
notify_emails |
[] |
Up to 20 email addresses. Empty uses the site’s administration email |
notify_min_severity |
high |
medium, high, critical |
notify_digest_minutes |
0 |
0, 5, 15 or 60: the minutes events are collected for before one email is sent |
notify_hourly_cap |
20 |
1 to 500 |
PHP errors and 404s
Present while the PHP errors monitor or the 404 errors monitor is on.
| Key | Default | Values |
|---|---|---|
php_errors_min_level |
warning |
error, warning, notice, deprecated |
php_errors_ignore_paths |
[] |
Up to 50 pieces of text |
not_found_ignore |
["*/favicon.ico","*/apple-touch-icon*","*/robots.txt","*.map"] |
Up to 50 patterns |
Sessions PRO
| Key | Default | Values |
|---|---|---|
sessions_max_per_user |
0 |
0 to 100. Zero means no limit |
sessions_limit_action |
block_new |
block_new, end_oldest |
sessions_idle_minutes |
0 |
15 to 43,200, or zero for no idle sign-out |
sessions_policy_roles |
[] |
Role slugs the policy applies to |
sessions_exempt_admins |
true |
true or false |
IP location PRO
| Key | Default | Values |
|---|---|---|
geo_account_id |
empty | The MaxMind account ID |
geo_license_key |
empty | The MaxMind licence key |
geo_edition |
GeoLite2-City |
GeoLite2-City, GeoLite2-Country |
File integrity PRO
| Key | Default | Values |
|---|---|---|
files_schedule |
daily |
daily, weekly, off |
files_scope_core |
true |
true or false |
files_scope_plugins |
true |
true or false |
files_scope_themes |
true |
true or false |
files_scope_uploads |
true |
true or false |
files_ignore |
["*.log","*/cache/*","*/node_modules/*","*/.git/*"] |
Patterns |
files_max_size_kb |
2048 |
64 to 51,200 |
Archive and mirrors PRO
| Key | Default | Values |
|---|---|---|
archive_after_days |
0 |
0 to 3650. Zero switches archiving off |
archive_target |
local |
local, external |
archive_retention_days |
0 |
0 to 36,500 |
archive_db_host |
empty | External database host |
archive_db_name |
empty | External database name |
archive_db_user |
empty | External database user |
archive_db_password |
empty | External database password |
archive_db_prefix |
wp_ |
Table prefix on the external database |
archive_db_ssl |
false |
true or false |
mirrors_allow_private |
false |
true or false |
Alert rules, mirrors, report schedules and saved views are not settings. Each has its own table and its own REST routes.
Database tables
Every table name starts with the WordPress base prefix followed by
plugixaactivitylog_. With the usual wp_ prefix the events table is
wp_plugixaactivitylog_events. On a multisite network the base prefix is the
network’s, so there is one set of tables for every site.
| Table | Holds |
|---|---|
events |
The log itself, one row per event |
views |
Saved views |
notification_queue |
Alerts waiting to be sent |
notification_rules PRO |
Alert rules |
report_schedules PRO |
Scheduled reports |
file_hashes PRO |
The file scan’s record of each file |
mirrors PRO |
Mirrors |
mirror_queue PRO |
Events waiting to be sent to a mirror |
events_archive PRO |
Archived events, when the archive is kept on this database |
An archive kept on another database server is one table there, named with the
prefix you set in archive_db_prefix.
Back up the events table with the rest of the database. Nothing else holds
the log.
Scheduled jobs
The plugin does its background work through WP-Cron. The hook names are what a
cron manager plugin or wp cron event list shows.
| Hook | Runs | Does |
|---|---|---|
plugixa_activity_log_prune |
Daily | Removes events past the retention limits |
plugixa_activity_log_send_notifications |
When the queue has work | Sends waiting alerts |
plugixa_activity_log_import_wsal |
While an import is running | Imports the next batch of WP Activity Log history |
plugixa_activity_log_run_reports PRO |
Hourly | Sends the scheduled reports that are due |
plugixa_activity_log_archive PRO |
Daily | Moves old events to the archive |
plugixa_activity_log_file_scan PRO |
Daily or weekly, as set | Starts a file scan |
plugixa_activity_log_file_scan_continue PRO |
While a scan is running | Carries a long scan on |
plugixa_activity_log_update_geo_db PRO |
Every 30 days | Downloads the IP location database |
plugixa_activity_log_mirror_send PRO |
When the queue has work | Sends waiting events to mirrors |
A job that runs “when the queue has work” is not booked the rest of the time, which the Health screen shows as Not booked. The Health screen is also where an overdue or stalled job shows up.
Constants
| Constant | Set by | Use |
|---|---|---|
PLUGIXA_ACTIVITY_LOG_MIRROR_DIR PRO |
You, in wp-config.php |
The folder file mirrors write to. Point it outside the web root. See Mirrors |
PLUGIXA_ACTIVITY_LOG_VERSION |
The plugin | The installed version |
PLUGIXA_ACTIVITY_LOG_PATH |
The plugin | The plugin’s folder on disk |
PLUGIXA_ACTIVITY_LOG_URL |
The plugin | The plugin’s folder as a URL |
PLUGIXA_ACTIVITY_LOG_BASENAME |
The plugin | The plugin’s file, as WordPress names it |
define( 'PLUGIXA_ACTIVITY_LOG_MIRROR_DIR', '/var/log/my-site/activity' );
The plugixa_activity_log_mirror_directory filter runs after the constant. See
the Hooks Reference.
Capabilities
| Capability | Held by |
|---|---|
plugixa_activity_log_view |
Administrators, plus the roles in view_roles |
plugixa_activity_log_manage_settings |
Administrators. On a network, network administrators |
plugixa_activity_log_export PRO |
Administrators, plus the roles in export_roles |
plugixa_activity_log_manage |
Anybody holding one of the above. It only means “may open the app” |
All four are worked out when they are checked and are never stored on a role, so
add_cap() has no effect. Check them with current_user_can(). See
Access.
What to do next
- Change a setting from a terminal: WP-CLI.
- Read the log from a script: REST API.
- Extend the plugin: Hooks Reference.