Contents

Events - Plugixa Activity Log

The Events screen is the catalogue: every kind of event the plugin can record, each with its code, its severity and a switch. It answers “what exactly does this log notice, and can I stop it noticing that one thing”.

The event catalogue, listing event codes with their wording, group, severity and a Recorded switch on each row

The screen

Column What it shows
Event code The stable number of this kind of event
Event The sentence, as a template, with the section it belongs to beneath
Group The area it belongs to: sign-ins, user accounts, posts and pages, and so on
Severity Informational, low, medium, high or critical
Recorded The switch. A Monitor off label beside it means the whole monitor is off; Always recorded means the event is part of the plugin’s own trail and its switch cannot be moved

Above the table: a search box that matches the code or the wording, a Group menu, and All / Recorded / Not recorded. Tick several rows and a bar appears with Enable all and Disable all.

Everybody who may see the log may read the catalogue. Changing a switch needs permission to change settings.

Event codes

A code is what is stored with each event. It is never reused and never renumbered, so a filter, an alert rule or a script that names 1103 means the same thing after every update.

Range Area
1000 Sign-ins
1100 User accounts
2000 Posts and pages
2100 Media library
2200 Comments
2300 Menus, widgets and terms
3000 Plugins, themes and updates
4000 Site settings
5000 to 6399 Integration monitors PRO, one block per plugin
7000 PHP errors
7100 404 errors
7200 File integrity PRO
9000 and up The plugin’s own trail

The catalogue lists what can happen on this site. The events of an integration monitor PRO appear only while the plugin it watches is active, so there are no switches for things that cannot occur.

The sentence is a template

{user}, {object} and the other placeholders are filled in when the event happens, and the finished sentence is stored with the event. Old entries therefore never change when a later release improves the wording. The raw values stay with the event and are shown when you open it.

Severity

Severity Meant for Example
Informational Routine activity 1000, somebody signed in
Low A change worth having on record 2001, a post was published
Medium A change somebody may ask about 1102, a user was deleted
High A change to who can do what, or to what runs 1103, a role changed
Critical Rare and dangerous 3020, a plugin file was edited in the editor

Severity is fixed per event code. It drives the chips on the log, the dashboard totals and the notification threshold.

Switching a single event off

Switching an event off stops recording it from now on. Existing entries are kept. Switching it back on resumes recording; nothing is filled in for the time between.

Only your deviations from the defaults are stored. An event you set back to its default is forgotten rather than pinned, so if a later release changes a default, it applies to every event you never touched.

One event starts off: 2012, a custom field changed. It is the most detailed event in the catalogue, so it is there for the sites that want it rather than on for everybody.

An event or a whole monitor? Use this screen for one noisy sentence in an area you still want. For an area you do not want at all, switch off the monitor: a monitor that is off attaches no WordPress hooks, whereas a single switched-off event still has to be detected before it is discarded.

Every change made here is a change to the plugin’s settings, and is recorded as event 9000.

The 9000 range: the plugin’s own trail

Codes 9000 and up record what was done to the log itself: settings changed, a monitor switched, old events removed by retention, a notification that could not be delivered, a person’s data erased.

This range is protected in three ways that no setting changes:

  • It cannot be switched off. Each of these rows shows Always recorded and a switch that does not move. The REST API and WP-CLI refuse the same request, and Disable all on a selection leaves these rows out. Otherwise the first two clicks of anybody covering their tracks would be to switch off “settings were changed” and “a monitor was switched off”.

  • Exclusions never apply to it. Excluding yourself from the log is a reasonable thing to want, and it must not also hide who changed the exclusions, the retention period or the monitors. An audit trail that can be told to stop auditing itself is not one.

  • It never triggers a notification. One of these events is “a notification could not be delivered”. Emailing about that would be a loop.

Together these are what lets you answer “who turned that off, and when”, whoever it was.

The catalogue

The tables below list every event the plugin defines outside the integration monitors, with the wording, severity and default the plugin’s event registry gives it. The events of each integration monitor PRO are listed in Integrations.

Sign-ins

Code Severity Event Default
1000 informational {user} signed in. on
1001 informational {user} signed out. on
1002 medium Failed sign-in attempt for the unknown username “{attempted}”. on
1003 medium Failed sign-in attempt for “{attempted}”: the password was wrong. on
1004 low A password reset link was requested for “{target}”. on
1005 medium The password of “{target}” was reset with a reset link. on
1006 high More than {limit} failed sign-ins came from {ip}. Further attempts from it are not logged individually for {minutes} minutes. on

User accounts

Code Severity Event Default
1100 low New user “{object}” registered with the role {role}. on
1101 medium User “{object}” was created with the role {role}. on
1102 medium User “{object}” ({email}) was deleted. on
1103 high The role of “{object}” changed from {old_role} to {new_role}. on
1104 medium The email address of “{object}” changed from {old_email} to {new_email}. on
1105 medium The password of “{object}” was changed. on
1106 low The profile of “{object}” was updated: {fields}. on
1107 critical “{object}” was made a network super admin. on
1108 high “{object}” is no longer a network super admin. on
1109 high Application password “{name}” was created for “{object}”. on
1110 medium Application password “{name}” of “{object}” was revoked. on

Posts and pages

Code Severity Event Default
2000 informational {type} “{object}” was created as {new_status}. on
2001 low {type} “{object}” was published. on
2002 low The content of {type} “{object}” was modified. on
2003 medium {type} “{object}” was moved to the trash. on
2004 low {type} “{object}” was restored from the trash. on
2005 medium {type} “{object}” was permanently deleted. on
2006 low {type} “{object}” changed status from {old_status} to {new_status}. on
2007 medium The author of {type} “{object}” changed from {old_author} to {new_author}. on
2008 low The title of {type} “{old_title}” changed to “{new_title}”. on
2009 medium The URL slug of {type} “{object}” changed from {old_slug} to {new_slug}. on
2010 low The {taxonomy} of {type} “{object}” changed: added {added}; removed {removed}. on
2011 low {type} “{object}” was scheduled for {scheduled_for}. on
2012 informational Custom field “{field}” of {type} “{object}” was {meta_action}. off
2013 medium The visibility of {type} “{object}” changed from {old_visibility} to {new_visibility}. on
2014 informational {type} “{object}” was {sticky_state}. on

Media library

Code Severity Event Default
2100 informational File “{object}” ({mime_type}) was uploaded. on
2101 informational File “{object}” was edited. on
2102 medium File “{object}” was permanently deleted. on

Comments

Code Severity Event Default
2200 informational A comment by {author} was posted on “{post_title}” ({comment_status}). on
2201 low The comment by {author} on “{post_title}” was approved. on
2202 low The comment by {author} on “{post_title}” was set back to pending. on
2203 low The comment by {author} on “{post_title}” was marked as spam. on
2204 low The comment by {author} on “{post_title}” was marked as not spam. on
2205 low The comment by {author} on “{post_title}” was moved to the trash. on
2206 low The comment by {author} on “{post_title}” was restored from the trash. on
2207 medium The comment by {author} on “{post_title}” was permanently deleted. on
2208 low The comment by {author} on “{post_title}” was edited. on
Code Severity Event Default
2300 low Menu “{object}” was created. on
2301 low Items of menu “{object}” were changed. on
2302 medium Menu “{object}” was deleted. on
2310 low Widget “{object}” was added to {sidebar}. on
2311 low Widget “{object}” was removed from {sidebar}. on
2320 low {taxonomy} “{object}” was created. on
2321 low {taxonomy} “{object}” was edited: {fields}. on
2322 medium {taxonomy} “{object}” was deleted. on
2330 low Changes made in the Customizer were published. on

Plugins, themes and updates

Code Severity Event Default
3000 high Plugin “{object}” {version} was installed. on
3001 high Plugin “{object}” was activated. on
3002 medium Plugin “{object}” was deactivated. on
3003 low Plugin “{object}” was updated to {version}. on
3004 high Plugin “{object}” was deleted. on
3010 high Theme “{object}” {version} was installed. on
3011 high The active theme changed from “{old_theme}” to “{object}”. on
3012 low Theme “{object}” was updated to {version}. on
3013 medium Theme “{object}” was deleted. on
3020 critical The file {file} of plugin “{object}” was edited in the plugin editor. on
3021 critical The file {file} of theme “{object}” was edited in the theme editor. on
3030 high WordPress was updated to version {version}. on

Site settings

Code Severity Event Default
4000 medium The setting “{object}” changed from {old_value} to {new_value}. on
4001 high The security-relevant setting “{object}” changed from {old_value} to {new_value}. on
4010 medium Site “{object}” ({site_url}) was added to the network. on
4011 medium Site {object} was archived. on
4012 low Site {object} was unarchived. on
4013 high Site “{object}” ({site_url}) was deleted from the network. on
4014 medium User “{object}” was added to site {site} as {role}. on
4015 medium User “{object}” was removed from site {site}. on

PHP errors

Recorded only while the PHP errors monitor is on, which it is not by default. See PHP Errors and 404s.

Code Severity Event Default
7000 high PHP fatal error in {component}: {error} ({object}:{line}) on
7001 medium PHP warning in {component}: {error} ({object}:{line}) on
7002 low PHP notice in {component}: {error} ({object}:{line}) on
7003 informational PHP deprecation in {component}: {error} ({object}:{line}) on
7004 medium PHP errors are being suppressed: more than {limit} in an hour. on

404 errors

Recorded only while the 404 errors monitor is on, which it is not by default.

Code Severity Event Default
7100 low 404 Not Found: {object} on
7101 medium Many 404 errors from {ip}: possible scan. on

File integrity PRO

Recorded by the scheduled file scan. See File Integrity.

Code Severity Event Default
7200 high A WordPress core file was modified: {path} on
7201 high A WordPress core file is missing: {path} on
7202 high An unexpected file was found in WordPress core folders: {path} on
7203 medium A file was changed in {component}: {path} on
7204 medium A file was added to {component}: {path} on
7205 low A file was deleted from {component}: {path} on
7206 high An executable file was found in uploads: {path} on
7207 informational File scan finished: {changed} changes in {files} files. on
7208 medium File scan failed: {reason} on
7209 high {changed} files changed in {component}; too many to list one by one. Review the folder. on

Activity Log

Code Severity Event Default
9000 medium Activity Log settings were changed: {changed}. on
9001 informational {count} old events were removed by the retention policy. on
9002 medium The monitor “{object}” was switched {state}. on
9003 PRO medium The log was exported to a CSV file ({count} rows). on
9004 PRO informational The scheduled report “{object}” was sent to {recipients}. on
9005 PRO medium The scheduled report “{object}” could not be sent: {reason} on
9006 PRO medium The report “{object}” was downloaded as {format}. on
9011 medium A notification could not be delivered to {target} after {attempts} attempts. on
9030 medium Personal data of a person was erased from the activity log ({count} events). on
9040 informational History imported from WP Activity Log: {count} events. on
9041 informational Imported from WP Activity Log: event {wsal_code}{summary} on
9120 PRO medium Alert rule “{object}” was {rule_action}. on
9200 PRO medium The session of {object} from {ip} was ended by an administrator. on
9201 PRO medium All sessions of {object} were ended. on
9202 PRO medium A sign-in by {object} was refused: the limit of {limit} concurrent sessions was reached. on
9203 PRO low {object} was signed out after {minutes} minutes of inactivity. on
9204 PRO low Every other session of {object} was ended; the current one was kept. on
9300 PRO informational The IP location database was updated ({edition}, {date}). on
9301 PRO medium The IP location database could not be updated: {reason} on
9400 PRO informational {count} events were moved to the archive. on
9401 PRO medium Archiving failed: {reason} on
9402 PRO medium The archive database connection was changed. on
9500 PRO medium Mirror “{object}” could not deliver events after {attempts} attempts. on
9501 PRO medium Mirror “{object}” was {state}. on

Troubleshooting

Symptom Usual cause
A switch is greyed out Changing it needs permission to change settings. A row marked Always recorded is greyed out for everybody.
An event is on but nothing is recorded Monitor off is shown beside it. Switch the monitor on.
An event is on, the monitor is on, still nothing The user, role, address or post type is excluded.
A plugin’s events are not in the catalogue That plugin is not active on this site, or the Pro build is not installed.
Old entries disappeared after switching an event off They did not. Check the filters on the log, and the retention period.
A 7003 deprecation never appears The PHP errors monitor records warnings and worse unless you lower its level.

What to do next

Quick Links