Contents

Reports - Plugixa Activity Log

The log answers “what happened at 14:02?”. A report answers “what happened last week?” - how much, how serious, by whom and from where - in a file you can read, print or hand to somebody who has no account on the site.

The Reports screen, with the form to run a report now and the tab of scheduled reports

Pro feature. Reports are part of Plugixa Activity Log Pro. See the Free vs Pro matrix.

Run a report now

Open Reports. The Run a report tab builds one and downloads it.

Field What it does
Title The heading of the report. Left empty it is Activity report.
Period Today, Last 7 days, Last 30 days, Last 90 days or Custom range with a start and an end date.
Area Only one area of the log, or all of them.
At least Only events of this severity or higher.
Role Only events done by people with this role.
Include The sections, below. At least one.
Format HTML (printable) or CSV (spreadsheet).

Dates are read in the site’s timezone, not UTC, and both ends are included. A report for the 3rd covers the 3rd as the site’s clock sees it.

Press Download report. The filters are checked by the same code the log screen uses, so a report shows exactly what the log would for the same filters.

What each section contains

Section Contents
Summary Five totals: events, high or critical events, failed sign-ins, users and IP addresses.
By severity The number of events at each severity.
By area The number of events in each area: sign-ins, users, content and so on.
Most active users The 25 usernames with the most events.
Top IP addresses The 25 addresses with the most events.
Every event The events themselves: time, severity, code, area, user, role, IP address, object and message. Up to 50,000.

Every event is the heavy one. A month of a busy site is a large file. When the period holds more than 50,000 events the report lists the first 50,000 and says so. For a summary to email, leave it off.

CSV or HTML

HTML is a self-contained, printable document. It is downloaded as a file and never displayed on your site, and every value in it is escaped.

CSV opens in a spreadsheet. Any cell that a spreadsheet would run as a formula is neutralised first, the same protection as the CSV export.

Who may run one

Running a report needs the export permission: administrators, plus the roles chosen under Settings -> Access. A report is a copy of the log leaving the site, so it is held to the same rule as the export, and every download is recorded: The report “…” was downloaded as … (event 9006).

Scheduled reports

The Scheduled reports tab appears for people who may change the plugin’s settings. New scheduled report asks for a name, recipients, the same filters, sections and format, and when to send.

Frequency Covers Sent
Daily Yesterday Every day at the chosen hour
Weekly The seven full days before the day it is sent On the chosen weekday, at the chosen hour
Monthly The previous calendar month On the chosen day of the month, 1 to 28, at the chosen hour
  • The hour is site time. “Daily at 07:00” means seven in the morning where the site is.
  • Monthly stops at the 28th so there is never a 31st of February to decide about.
  • Recipients are email addresses separated by commas, up to 20.

The report arrives as an email attachment, with the headline totals in the body of the message.

How sending works

Schedules are checked once an hour by WP-Cron (plugixa_activity_log_run_reports), which sends whatever is due. On a quiet site WP-Cron only runs when somebody visits, so for punctual delivery give WordPress a real cron job.

A sent report records event 9004. A failed send is recorded once (event 9005, with the reason) and is not retried every hour. The next report goes out at its normal time. Retrying hourly would mail nobody and fill the log with the same failure.

Send now on a schedule’s row sends it immediately. The list shows when each schedule runs next and whether the last one was Sent or Failed.

On a network

A site administrator on a multisite network sees and runs only their own site’s schedules, and their reports contain only their own site’s events.

Troubleshooting

Symptom Usual cause
Reports is not in the menu Pro feature, or the module is switched off on the Monitors screen.
There is no Scheduled reports tab Managing schedules needs the settings permission.
The report is one day off Dates are in the site’s timezone. Check the timezone in WordPress’s general settings.
“Only the first 50,000 events are listed” The period holds more. Shorten it, or narrow the filters.
A scheduled report is late WP-Cron needs traffic, or a real cron job.
The last status is Failed WordPress could not send the email. Event 9005 has the reason.
A failed report was not sent again By design. It is tried at the next scheduled time.
Archived events are missing Reports read the live log. See Archive.

What to do next

  • Take the rows instead of a summary: Export PRO.
  • Choose who may run reports: Access.
  • Be told as it happens, not next week: Alert Rules PRO.

Quick Links