Contents

Export - Plugixa Activity Log

The export answers “can I have this as a spreadsheet?”. It turns the events on screen into a CSV file: for an auditor, for a client, or for a question the log’s filters cannot answer on their own.

Pro feature. CSV export is part of Plugixa Activity Log Pro. See the Free vs Pro matrix.

It exports what the filters show

Export CSV sits in the toolbar of the Activity Log. There is no separate export screen and no second set of options, on purpose.

The file contains exactly what the current filters show. The export reads its filters with the same code as the list, so the two cannot disagree. Filter to failed sign-ins, last 7 days, from one IP address, press the button, and that is the file.

So the way to export less is to filter more. To export a saved view, open it first.

Two limits are worth knowing:

  • One download holds up to 50,000 events. A larger result is cut at 50,000. Narrow the dates and export in pieces.
  • The export reads the live log. Events already moved to the Archive are not in it.

The file is named activity-log- followed by the date and time of the download in UTC, for example activity-log-2026-10-08-141530.csv.

The columns

One row per event, with a header row first.

Column Contents
id The event’s number in the log
time_utc When it happened, in UTC, as YYYY-MM-DD HH:MM:SS
time_site The same moment in the site’s timezone
severity informational, low, medium, high or critical
event_code The stable code of the event, for example 1003
group The area the event belongs to, as named in the log
message The one-line description shown in the log
user_id The WordPress user ID of who did it
user Their username
role Their role at the time
ip The IP address the request came from
object_type What kind of thing the event is about: a post, a user, a plugin
object_id That thing’s ID, empty when it has none
object That thing’s name or title
site_id The site on a multisite network

Both times are there for a reason. time_utc is the one to sort and compare on, because it never shifts with daylight saving. time_site is the one to read, because it matches the clock on the wall when it happened.

The old and new values shown in the event inspector are not in the file. The CSV is one line per event; the detail stays in the log.

Made to open correctly in Excel

The file starts with a byte-order mark. Without it, Excel guesses a legacy character set and names like Zoë or Sørensen arrive as garbage. With it, Excel reads the file as UTF-8.

Protected against spreadsheet formulas

This is the real risk in any export of a log, and it is easy to miss.

Much of the log is text somebody else typed: the username of a failed sign-in, a post title, a comment author. A spreadsheet treats a cell that begins with =, +, - or @ as a formula. Somebody who types =HYPERLINK(...) as a username on your sign-in form has put a formula in your audit file, waiting for whoever opens it.

So every cell that begins with one of those characters, or with a tab or a carriage return, is prefixed with an apostrophe. Spreadsheets read that as “this is text” and show the value without running it.

If you feed the CSV to a script instead of a spreadsheet, expect that leading apostrophe on such values.

Who may export

An export is a copy of the log leaving the site, so it has its own permission, separate from viewing.

  • Administrators can always export.
  • Other roles can when they are listed under Settings -> Access, in Roles that can export the log.

Somebody who can view the log but not export it does not see the button at all. The permission is worked out when it is needed and is never written onto a role, so removing a role from the list takes effect at once and leaves nothing behind.

The same permission covers running Reports, for the same reason.

On a multisite network, a site administrator’s export holds only their own site’s events, whatever the request asks for.

An export is itself logged

Every download records The log was exported to a CSV file (N rows). as event 9003, at medium severity, with who did it, when and from which address.

Like all of the plugin’s own events (codes 9000 and above), it cannot be excluded and it never triggers a notification. Nobody can take a copy of the log without the log saying so.

Troubleshooting

Symptom Usual cause
There is no Export CSV button Pro feature, the CSV export module is switched off on the Monitors screen, or your role may not export.
The file has fewer rows than expected It exports the current filters. Clear them, or check the 50,000 limit.
Exactly 50,000 rows The limit. Split the export by date.
Accented names look wrong The file was opened as something other than UTF-8. Excel reads the byte-order mark; other tools may need telling.
A value starts with an apostrophe Formula protection. The value began with =, +, - or @.
Times look hours off time_utc is UTC. Use time_site for local time.
Old events are missing They were archived. The export reads the live log.
An editor cannot export Add the role under Settings -> Access.

What to do next

  • Get a summary instead of rows: Reports PRO.
  • Choose who may export: Access.
  • Read events from a script: REST API.
  • Copy every event off the site as it happens: Mirrors PRO.

Quick Links