SiteFort documentation

Audit Log

Every login, setting change, and admin action in one place. Use it to reconstruct incidents, review suspicious activity, and export evidence.

Audit Log

The Audit Log records user activity and system events as they happen, not just that something changed, but who changed it, when a lockout occurred, whether a sensitive tool was used, and whether a plugin, theme, or core change lined up with the start of an incident.

If audit logging is disabled, the page shows Audit Logging is Disabled and provides Enable Audit Logging plus a link to Settings > Advanced. Enable it before you need evidence, not after, since it can't retroactively log anything that already happened while it was off.

AreaDetailsHow to use it
Summary cardsTotal events, Warnings, Critical, and Unique users.Use to estimate activity volume and urgency.
FiltersAll, Info, Warning, Critical, and search by event, user, or IP.Filter before exporting or clearing to avoid losing context.
Event tableEvent, User, Date & Time, Category, and IP Address.Use for incident reconstruction and compliance review.
Header actionsExport CSV, Clear All, and Refresh.Export before Clear All. CSV export protects fields from spreadsheet formula execution.
Event typesAuthentication, password, user management, plugin, theme, core, hardening, site setting, lockout, audit clear, and default event details.Correlate with Scanner findings and Traffic Log events.