Update: The Security Audit Log has been completely revamped and rewritten with ShieldPRO 12.
With the Shield, we’ve created a toolkit that lets you lock down your site from intruders and prevent unauthorized access to core components of your site.
We took it one step further – we let you look back and see what you, and any other users on your system, has done on your site.
With the Shield Security, we give you a WordPress Audit Trail – full insight into all significant actions taken on your websites.
How The WordPress Audit Trail Works
The Audit Trail is designed to be your note-taker. It will watch your WordPress site and for certain specific actions that take place, it will record it in the database for your review, if necessary.
Information that it currently records include:
- The time of the request to the site
- The currently logged-in user if applicable
- The originating IP address of the request
- The event
- An optional message for the event.
With all this information it’s easy review the activity on your website.
You may want to review the information for any number of reasons, but for whatever that reason happens to be, the Audit Trail will keep you fully informed.
Organizing Events With Audit Trail Contexts
The Audit Trail monitors key activity on your site and records events as they happen.
Since many things can happen on a site we need a way to group these activities, and to achieve this we created “Contexts”.
Contexts, in relation to the Audit Trail, are large areas of the WordPress system within which certain groups of actions may fall. There are 7 main contexts as follows:
- Users / Logins
- WordPress Core and Settings
- Posts and Pages
Each of these contexts have 1 or more associated events. For example, “Plugins” has:
- plugin activated
- plugin deactivated
As the Audit Trail feature develops, more events will be added, as well as more Contexts as appropriate.
The Shield context is a special context where the plugin logs and tracks itself. Included in this context are events such as:
- Firewall blocks
- Firewall skipping
- White list notifications
- Two Factor Login Authentication
- etc. and with more to come.
One important point to note here is that the Contexts settings are not available in Shield 10.1 and onward. Audit Trail logs everything instead.
Why do you need an Audit Trail?
Often, when a website breaks, it’s helpful to know what immediately preceded it. Problems typically occur after a change and being able to see events leading up to a break can really help to pinpoint the cause of it.
The Audit Trail will let you see exactly what has been happening on your site. It gives you a view on the activity of your users and when this activity happens.
Sure, it can be used to identify and record malicious activity, but the most useful application of an Audit Trail is identifying the cause of sudden problems that can affect a site.
How to enable the Shield Audit Trail
The Audit Trail feature is accessible from within it’s own module and is enabled by default.
Here you can also configure it to
- automatically purge Audit log entries older than the set number of days; and
- set maximum Audit Trail length to keep.
As information comes into the Audit Trail, you can view it by navigating to the “Audit Trail Viewer” page.
Suggestion, Comments, Feedback?
We hope you like the Audit Trail feature. We’d like to hear what you think, and any suggestions as to what extra features you’d like to see here.
Please feel free to email us in our support centre, or leave a comment below!
<3 Addon – it's a must have addon for clients.
All of my clients have this plugin installed at their site. It’s not an option to opt-out. The very few times I have had to connect with them via support has been above expectations in helping me with my dumb-dom. For folks who are having a hard time with support…
Great – But One Visual Flaw
The logs, if we had these within their own sectional tabs, that’ll be amazing. Still deserves a 5-star for such an amazing product as it blows WordFence out of the water. Would like to see a few more features developed. But first we would love to donate for your hard…
Endlich mal ein Plugin das ohne Probleme perfekt funktioniert. Klasse, einfach wirklich sauber, schnell und gut gemacht 🙂
Thank you for this great security application. I am using a cheap shared hosting (128 MB ram limit). I’ve tested all popular security plugins for wordpress. This is easy to use and fast. But, It could be better if there was a DOS/Flood protection…