Contents
Events - Plugixa Activity Log
The Events screen is the catalogue: every kind of event the plugin can record, each with its code, its severity and a switch. It answers “what exactly does this log notice, and can I stop it noticing that one thing”.

The screen
| Column | What it shows |
|---|---|
| Event code | The stable number of this kind of event |
| Event | The sentence, as a template, with the section it belongs to beneath |
| Group | The area it belongs to: sign-ins, user accounts, posts and pages, and so on |
| Severity | Informational, low, medium, high or critical |
| Recorded | The switch. A Monitor off label beside it means the whole monitor is off; Always recorded means the event is part of the plugin’s own trail and its switch cannot be moved |
Above the table: a search box that matches the code or the wording, a Group menu, and All / Recorded / Not recorded. Tick several rows and a bar appears with Enable all and Disable all.
Everybody who may see the log may read the catalogue. Changing a switch needs permission to change settings.
Event codes
A code is what is stored with each event. It is never reused and never
renumbered, so a filter, an alert rule or a script that names 1103 means the
same thing after every update.
| Range | Area |
|---|---|
| 1000 | Sign-ins |
| 1100 | User accounts |
| 2000 | Posts and pages |
| 2100 | Media library |
| 2200 | Comments |
| 2300 | Menus, widgets and terms |
| 3000 | Plugins, themes and updates |
| 4000 | Site settings |
| 5000 to 6399 | Integration monitors PRO, one block per plugin |
| 7000 | PHP errors |
| 7100 | 404 errors |
| 7200 | File integrity PRO |
| 9000 and up | The plugin’s own trail |
The catalogue lists what can happen on this site. The events of an integration monitor PRO appear only while the plugin it watches is active, so there are no switches for things that cannot occur.
The sentence is a template
{user}, {object} and the other placeholders are filled in when the event
happens, and the finished sentence is stored with the event. Old entries
therefore never change when a later release improves the wording. The raw values
stay with the event and are shown when you open it.
Severity
| Severity | Meant for | Example |
|---|---|---|
| Informational | Routine activity | 1000, somebody signed in |
| Low | A change worth having on record | 2001, a post was published |
| Medium | A change somebody may ask about | 1102, a user was deleted |
| High | A change to who can do what, or to what runs | 1103, a role changed |
| Critical | Rare and dangerous | 3020, a plugin file was edited in the editor |
Severity is fixed per event code. It drives the chips on the log, the dashboard totals and the notification threshold.
Switching a single event off
Switching an event off stops recording it from now on. Existing entries are kept. Switching it back on resumes recording; nothing is filled in for the time between.
Only your deviations from the defaults are stored. An event you set back to its default is forgotten rather than pinned, so if a later release changes a default, it applies to every event you never touched.
One event starts off: 2012, a custom field changed. It is the most detailed event in the catalogue, so it is there for the sites that want it rather than on for everybody.
An event or a whole monitor? Use this screen for one noisy sentence in an area you still want. For an area you do not want at all, switch off the monitor: a monitor that is off attaches no WordPress hooks, whereas a single switched-off event still has to be detected before it is discarded.
Every change made here is a change to the plugin’s settings, and is recorded as event 9000.
The 9000 range: the plugin’s own trail
Codes 9000 and up record what was done to the log itself: settings changed, a monitor switched, old events removed by retention, a notification that could not be delivered, a person’s data erased.
This range is protected in three ways that no setting changes:
-
It cannot be switched off. Each of these rows shows Always recorded and a switch that does not move. The REST API and WP-CLI refuse the same request, and Disable all on a selection leaves these rows out. Otherwise the first two clicks of anybody covering their tracks would be to switch off “settings were changed” and “a monitor was switched off”.
-
Exclusions never apply to it. Excluding yourself from the log is a reasonable thing to want, and it must not also hide who changed the exclusions, the retention period or the monitors. An audit trail that can be told to stop auditing itself is not one.
-
It never triggers a notification. One of these events is “a notification could not be delivered”. Emailing about that would be a loop.
Together these are what lets you answer “who turned that off, and when”, whoever it was.
The catalogue
The tables below list every event the plugin defines outside the integration monitors, with the wording, severity and default the plugin’s event registry gives it. The events of each integration monitor PRO are listed in Integrations.
Sign-ins
| Code | Severity | Event | Default |
|---|---|---|---|
| 1000 | informational | {user} signed in. | on |
| 1001 | informational | {user} signed out. | on |
| 1002 | medium | Failed sign-in attempt for the unknown username “{attempted}”. | on |
| 1003 | medium | Failed sign-in attempt for “{attempted}”: the password was wrong. | on |
| 1004 | low | A password reset link was requested for “{target}”. | on |
| 1005 | medium | The password of “{target}” was reset with a reset link. | on |
| 1006 | high | More than {limit} failed sign-ins came from {ip}. Further attempts from it are not logged individually for {minutes} minutes. | on |
User accounts
| Code | Severity | Event | Default |
|---|---|---|---|
| 1100 | low | New user “{object}” registered with the role {role}. | on |
| 1101 | medium | User “{object}” was created with the role {role}. | on |
| 1102 | medium | User “{object}” ({email}) was deleted. | on |
| 1103 | high | The role of “{object}” changed from {old_role} to {new_role}. | on |
| 1104 | medium | The email address of “{object}” changed from {old_email} to {new_email}. | on |
| 1105 | medium | The password of “{object}” was changed. | on |
| 1106 | low | The profile of “{object}” was updated: {fields}. | on |
| 1107 | critical | “{object}” was made a network super admin. | on |
| 1108 | high | “{object}” is no longer a network super admin. | on |
| 1109 | high | Application password “{name}” was created for “{object}”. | on |
| 1110 | medium | Application password “{name}” of “{object}” was revoked. | on |
Posts and pages
| Code | Severity | Event | Default |
|---|---|---|---|
| 2000 | informational | {type} “{object}” was created as {new_status}. | on |
| 2001 | low | {type} “{object}” was published. | on |
| 2002 | low | The content of {type} “{object}” was modified. | on |
| 2003 | medium | {type} “{object}” was moved to the trash. | on |
| 2004 | low | {type} “{object}” was restored from the trash. | on |
| 2005 | medium | {type} “{object}” was permanently deleted. | on |
| 2006 | low | {type} “{object}” changed status from {old_status} to {new_status}. | on |
| 2007 | medium | The author of {type} “{object}” changed from {old_author} to {new_author}. | on |
| 2008 | low | The title of {type} “{old_title}” changed to “{new_title}”. | on |
| 2009 | medium | The URL slug of {type} “{object}” changed from {old_slug} to {new_slug}. | on |
| 2010 | low | The {taxonomy} of {type} “{object}” changed: added {added}; removed {removed}. | on |
| 2011 | low | {type} “{object}” was scheduled for {scheduled_for}. | on |
| 2012 | informational | Custom field “{field}” of {type} “{object}” was {meta_action}. | off |
| 2013 | medium | The visibility of {type} “{object}” changed from {old_visibility} to {new_visibility}. | on |
| 2014 | informational | {type} “{object}” was {sticky_state}. | on |
Media library
| Code | Severity | Event | Default |
|---|---|---|---|
| 2100 | informational | File “{object}” ({mime_type}) was uploaded. | on |
| 2101 | informational | File “{object}” was edited. | on |
| 2102 | medium | File “{object}” was permanently deleted. | on |
Comments
| Code | Severity | Event | Default |
|---|---|---|---|
| 2200 | informational | A comment by {author} was posted on “{post_title}” ({comment_status}). | on |
| 2201 | low | The comment by {author} on “{post_title}” was approved. | on |
| 2202 | low | The comment by {author} on “{post_title}” was set back to pending. | on |
| 2203 | low | The comment by {author} on “{post_title}” was marked as spam. | on |
| 2204 | low | The comment by {author} on “{post_title}” was marked as not spam. | on |
| 2205 | low | The comment by {author} on “{post_title}” was moved to the trash. | on |
| 2206 | low | The comment by {author} on “{post_title}” was restored from the trash. | on |
| 2207 | medium | The comment by {author} on “{post_title}” was permanently deleted. | on |
| 2208 | low | The comment by {author} on “{post_title}” was edited. | on |
Menus, widgets and terms
| Code | Severity | Event | Default |
|---|---|---|---|
| 2300 | low | Menu “{object}” was created. | on |
| 2301 | low | Items of menu “{object}” were changed. | on |
| 2302 | medium | Menu “{object}” was deleted. | on |
| 2310 | low | Widget “{object}” was added to {sidebar}. | on |
| 2311 | low | Widget “{object}” was removed from {sidebar}. | on |
| 2320 | low | {taxonomy} “{object}” was created. | on |
| 2321 | low | {taxonomy} “{object}” was edited: {fields}. | on |
| 2322 | medium | {taxonomy} “{object}” was deleted. | on |
| 2330 | low | Changes made in the Customizer were published. | on |
Plugins, themes and updates
| Code | Severity | Event | Default |
|---|---|---|---|
| 3000 | high | Plugin “{object}” {version} was installed. | on |
| 3001 | high | Plugin “{object}” was activated. | on |
| 3002 | medium | Plugin “{object}” was deactivated. | on |
| 3003 | low | Plugin “{object}” was updated to {version}. | on |
| 3004 | high | Plugin “{object}” was deleted. | on |
| 3010 | high | Theme “{object}” {version} was installed. | on |
| 3011 | high | The active theme changed from “{old_theme}” to “{object}”. | on |
| 3012 | low | Theme “{object}” was updated to {version}. | on |
| 3013 | medium | Theme “{object}” was deleted. | on |
| 3020 | critical | The file {file} of plugin “{object}” was edited in the plugin editor. | on |
| 3021 | critical | The file {file} of theme “{object}” was edited in the theme editor. | on |
| 3030 | high | WordPress was updated to version {version}. | on |
Site settings
| Code | Severity | Event | Default |
|---|---|---|---|
| 4000 | medium | The setting “{object}” changed from {old_value} to {new_value}. | on |
| 4001 | high | The security-relevant setting “{object}” changed from {old_value} to {new_value}. | on |
| 4010 | medium | Site “{object}” ({site_url}) was added to the network. | on |
| 4011 | medium | Site {object} was archived. | on |
| 4012 | low | Site {object} was unarchived. | on |
| 4013 | high | Site “{object}” ({site_url}) was deleted from the network. | on |
| 4014 | medium | User “{object}” was added to site {site} as {role}. | on |
| 4015 | medium | User “{object}” was removed from site {site}. | on |
PHP errors
Recorded only while the PHP errors monitor is on, which it is not by default. See PHP Errors and 404s.
| Code | Severity | Event | Default |
|---|---|---|---|
| 7000 | high | PHP fatal error in {component}: {error} ({object}:{line}) | on |
| 7001 | medium | PHP warning in {component}: {error} ({object}:{line}) | on |
| 7002 | low | PHP notice in {component}: {error} ({object}:{line}) | on |
| 7003 | informational | PHP deprecation in {component}: {error} ({object}:{line}) | on |
| 7004 | medium | PHP errors are being suppressed: more than {limit} in an hour. | on |
404 errors
Recorded only while the 404 errors monitor is on, which it is not by default.
| Code | Severity | Event | Default |
|---|---|---|---|
| 7100 | low | 404 Not Found: {object} | on |
| 7101 | medium | Many 404 errors from {ip}: possible scan. | on |
File integrity PRO
Recorded by the scheduled file scan. See File Integrity.
| Code | Severity | Event | Default |
|---|---|---|---|
| 7200 | high | A WordPress core file was modified: {path} | on |
| 7201 | high | A WordPress core file is missing: {path} | on |
| 7202 | high | An unexpected file was found in WordPress core folders: {path} | on |
| 7203 | medium | A file was changed in {component}: {path} | on |
| 7204 | medium | A file was added to {component}: {path} | on |
| 7205 | low | A file was deleted from {component}: {path} | on |
| 7206 | high | An executable file was found in uploads: {path} | on |
| 7207 | informational | File scan finished: {changed} changes in {files} files. | on |
| 7208 | medium | File scan failed: {reason} | on |
| 7209 | high | {changed} files changed in {component}; too many to list one by one. Review the folder. | on |
Activity Log
| Code | Severity | Event | Default |
|---|---|---|---|
| 9000 | medium | Activity Log settings were changed: {changed}. | on |
| 9001 | informational | {count} old events were removed by the retention policy. | on |
| 9002 | medium | The monitor “{object}” was switched {state}. | on |
| 9003 PRO | medium | The log was exported to a CSV file ({count} rows). | on |
| 9004 PRO | informational | The scheduled report “{object}” was sent to {recipients}. | on |
| 9005 PRO | medium | The scheduled report “{object}” could not be sent: {reason} | on |
| 9006 PRO | medium | The report “{object}” was downloaded as {format}. | on |
| 9011 | medium | A notification could not be delivered to {target} after {attempts} attempts. | on |
| 9030 | medium | Personal data of a person was erased from the activity log ({count} events). | on |
| 9040 | informational | History imported from WP Activity Log: {count} events. | on |
| 9041 | informational | Imported from WP Activity Log: event {wsal_code}{summary} | on |
| 9120 PRO | medium | Alert rule “{object}” was {rule_action}. | on |
| 9200 PRO | medium | The session of {object} from {ip} was ended by an administrator. | on |
| 9201 PRO | medium | All sessions of {object} were ended. | on |
| 9202 PRO | medium | A sign-in by {object} was refused: the limit of {limit} concurrent sessions was reached. | on |
| 9203 PRO | low | {object} was signed out after {minutes} minutes of inactivity. | on |
| 9204 PRO | low | Every other session of {object} was ended; the current one was kept. | on |
| 9300 PRO | informational | The IP location database was updated ({edition}, {date}). | on |
| 9301 PRO | medium | The IP location database could not be updated: {reason} | on |
| 9400 PRO | informational | {count} events were moved to the archive. | on |
| 9401 PRO | medium | Archiving failed: {reason} | on |
| 9402 PRO | medium | The archive database connection was changed. | on |
| 9500 PRO | medium | Mirror “{object}” could not deliver events after {attempts} attempts. | on |
| 9501 PRO | medium | Mirror “{object}” was {state}. | on |
Troubleshooting
| Symptom | Usual cause |
|---|---|
| A switch is greyed out | Changing it needs permission to change settings. A row marked Always recorded is greyed out for everybody. |
| An event is on but nothing is recorded | Monitor off is shown beside it. Switch the monitor on. |
| An event is on, the monitor is on, still nothing | The user, role, address or post type is excluded. |
| A plugin’s events are not in the catalogue | That plugin is not active on this site, or the Pro build is not installed. |
| Old entries disappeared after switching an event off | They did not. Check the filters on the log, and the retention period. |
| A 7003 deprecation never appears | The PHP errors monitor records warnings and worse unless you lower its level. |
What to do next
- Switch off a whole area: Monitors.
- Leave out people rather than events: Exclusions.
- Record events of your own: Hooks Reference.