← All features
Activity & audit logs

See the story behind a sign-in.

Review successful, failed and blocked logins with the details you need to understand unusual activity.

Available in the current release. Plugin activity and recovery actions were added in 3.0.

See it in action

Your site’s activity, as it happens.

Watch sample sign-ins, plugin changes and file recovery actions arrive in the log. Select an event to see its details.

Activity log
Sample activity
3 events
Illustrative activity records. New events appear at the top.
EventStatusUserTimeIP addressBrowser
Successalex09:41:06192.0.2.24Safari · macOS
Successadmin09:41:04192.0.2.10Chrome · Windows
Successmorgan09:41:02192.0.2.36Safari · macOS
Latest sample events · newest firstShowing the latest 7 events
Why it matters

You cannot investigate an event you cannot see.

An unexpected administrator login or a member’s repeated failure is difficult to explain without context. Time, method and result help turn a vague concern into a focused review.

How it helps your site

Create a trail you can follow.

FluentAuth records supported authentication events with the details needed to investigate them. Since 3.0 that includes plugin activation, deactivation and updates. Logs help you detect and understand events; they do not block an attack by themselves.

What you gain

Answer support questions faster and connect unusual sign-ins with the events around them.

Get FluentAuth →
Inside FluentAuth

See the controls behind the experience.

Available in the current release. Plugin activity and recovery actions were added in 3.0.

Follow the setup guide →
FluentAuth activity & audit logs settings and results on a local development site.
FluentAuth activity & audit logs settings and results on a local development site. Select the image to view it full size.

How to use the activity log

  1. Open the log and narrow the view to the period or activity you are investigating.
  2. Review the user, result, method and address associated with an event.
  3. Compare related events before deciding whether to contact the user or take recovery action.

An unfamiliar IP address alone is not proof of a break-in. Mobile networks, VPNs and shared connections can change what appears in the log.

Useful during support and incident review

If a member says they cannot log in, check whether attempts are failing or being blocked. If an administrator receives an unexpected alert, review the surrounding events and any file changes before deciding what to do next.

How long are logs kept?

You control log retention in settings. Choose a period that supports your review needs and account for the personal data, such as addresses and user identifiers, stored in those records.

Keep the context behind your site’s activity.

Enable the events you need to review and choose a retention period that fits your site.