Contents

Developer reference - Plugixa Activity Log

The other pages describe the plugin by what you see. This one lists the names code and scripts use: setting keys for WP-CLI and the REST API, the tables for a backup plan, the scheduled jobs for a server cron check, and the constants and capabilities.

Where settings are stored

Every setting lives in one option, plugixa_activity_log_settings. It is a site option, so on a multisite network there is one copy for the whole network.

Read and change settings through the plugin rather than the option, so a value passes the same checks as the Settings screen:

wp activity-log settings get
wp activity-log settings set retention_days 30
POST /wp-json/plugixa-activity-log/v1/settings
{ "retention_days": 30 }

A key the plugin does not recognise is discarded, and a value outside its range is brought back inside it. See WP-CLI and the REST API.

A key exists only while the feature that owns it is installed and switched on. wp activity-log settings get prints the complete list for your site.

Setting keys

General, access and uninstall

Key Default Values
user_display display_name display_name, login, first_last
records_per_page 50 10 to 200
trusted_proxy_header empty Empty, HTTP_X_FORWARDED_FOR, HTTP_CF_CONNECTING_IP, HTTP_X_REAL_IP, HTTP_TRUE_CLIENT_IP
view_roles [] Role slugs that may read the log
export_roles PRO [] Role slugs that may download the log
event_overrides [] Event code to true or false, holding only the events moved away from their default
delete_data_on_uninstall false true or false

Retention and exclusions

Key Default Values
retention_days 90 0 to 3650. Zero means no age limit
retention_max_rows 0 0 to 100,000,000. Zero means no count limit
excluded_user_ids [] User IDs
excluded_roles [] Role slugs
excluded_ips [] Single addresses or CIDR ranges
excluded_post_types [] Post type slugs

Privacy and notifications

Key Default Values
privacy_ip_mode full full, truncate, none
privacy_store_user_agent true true or false
notify_enabled false true or false
notify_emails [] Up to 20 email addresses. Empty uses the site’s administration email
notify_min_severity high medium, high, critical
notify_digest_minutes 0 0, 5, 15 or 60: the minutes events are collected for before one email is sent
notify_hourly_cap 20 1 to 500

PHP errors and 404s

Present while the PHP errors monitor or the 404 errors monitor is on.

Key Default Values
php_errors_min_level warning error, warning, notice, deprecated
php_errors_ignore_paths [] Up to 50 pieces of text
not_found_ignore ["*/favicon.ico","*/apple-touch-icon*","*/robots.txt","*.map"] Up to 50 patterns

Sessions PRO

Key Default Values
sessions_max_per_user 0 0 to 100. Zero means no limit
sessions_limit_action block_new block_new, end_oldest
sessions_idle_minutes 0 15 to 43,200, or zero for no idle sign-out
sessions_policy_roles [] Role slugs the policy applies to
sessions_exempt_admins true true or false

IP location PRO

Key Default Values
geo_account_id empty The MaxMind account ID
geo_license_key empty The MaxMind licence key
geo_edition GeoLite2-City GeoLite2-City, GeoLite2-Country

File integrity PRO

Key Default Values
files_schedule daily daily, weekly, off
files_scope_core true true or false
files_scope_plugins true true or false
files_scope_themes true true or false
files_scope_uploads true true or false
files_ignore ["*.log","*/cache/*","*/node_modules/*","*/.git/*"] Patterns
files_max_size_kb 2048 64 to 51,200

Archive and mirrors PRO

Key Default Values
archive_after_days 0 0 to 3650. Zero switches archiving off
archive_target local local, external
archive_retention_days 0 0 to 36,500
archive_db_host empty External database host
archive_db_name empty External database name
archive_db_user empty External database user
archive_db_password empty External database password
archive_db_prefix wp_ Table prefix on the external database
archive_db_ssl false true or false
mirrors_allow_private false true or false

Alert rules, mirrors, report schedules and saved views are not settings. Each has its own table and its own REST routes.

Database tables

Every table name starts with the WordPress base prefix followed by plugixaactivitylog_. With the usual wp_ prefix the events table is wp_plugixaactivitylog_events. On a multisite network the base prefix is the network’s, so there is one set of tables for every site.

Table Holds
events The log itself, one row per event
views Saved views
notification_queue Alerts waiting to be sent
notification_rules PRO Alert rules
report_schedules PRO Scheduled reports
file_hashes PRO The file scan’s record of each file
mirrors PRO Mirrors
mirror_queue PRO Events waiting to be sent to a mirror
events_archive PRO Archived events, when the archive is kept on this database

An archive kept on another database server is one table there, named with the prefix you set in archive_db_prefix.

Back up the events table with the rest of the database. Nothing else holds the log.

Scheduled jobs

The plugin does its background work through WP-Cron. The hook names are what a cron manager plugin or wp cron event list shows.

Hook Runs Does
plugixa_activity_log_prune Daily Removes events past the retention limits
plugixa_activity_log_send_notifications When the queue has work Sends waiting alerts
plugixa_activity_log_import_wsal While an import is running Imports the next batch of WP Activity Log history
plugixa_activity_log_run_reports PRO Hourly Sends the scheduled reports that are due
plugixa_activity_log_archive PRO Daily Moves old events to the archive
plugixa_activity_log_file_scan PRO Daily or weekly, as set Starts a file scan
plugixa_activity_log_file_scan_continue PRO While a scan is running Carries a long scan on
plugixa_activity_log_update_geo_db PRO Every 30 days Downloads the IP location database
plugixa_activity_log_mirror_send PRO When the queue has work Sends waiting events to mirrors

A job that runs “when the queue has work” is not booked the rest of the time, which the Health screen shows as Not booked. The Health screen is also where an overdue or stalled job shows up.

Constants

Constant Set by Use
PLUGIXA_ACTIVITY_LOG_MIRROR_DIR PRO You, in wp-config.php The folder file mirrors write to. Point it outside the web root. See Mirrors
PLUGIXA_ACTIVITY_LOG_VERSION The plugin The installed version
PLUGIXA_ACTIVITY_LOG_PATH The plugin The plugin’s folder on disk
PLUGIXA_ACTIVITY_LOG_URL The plugin The plugin’s folder as a URL
PLUGIXA_ACTIVITY_LOG_BASENAME The plugin The plugin’s file, as WordPress names it
define( 'PLUGIXA_ACTIVITY_LOG_MIRROR_DIR', '/var/log/my-site/activity' );

The plugixa_activity_log_mirror_directory filter runs after the constant. See the Hooks Reference.

Capabilities

Capability Held by
plugixa_activity_log_view Administrators, plus the roles in view_roles
plugixa_activity_log_manage_settings Administrators. On a network, network administrators
plugixa_activity_log_export PRO Administrators, plus the roles in export_roles
plugixa_activity_log_manage Anybody holding one of the above. It only means “may open the app”

All four are worked out when they are checked and are never stored on a role, so add_cap() has no effect. Check them with current_user_can(). See Access.

What to do next

Quick Links