Skip to content

Privacy and Reference

Logify Event Reference — Every Event It Records

Want to know exactly what Logify can record and how each entry is scored? This is the complete reference of every event Logify writes, grouped by area, with the event ID, action, and severity for each. Use it to work out what a log entry means, to build a filter or alert rule, or to pick a free ID when adding your own event. Events marked PRO require Logify PRO.

How severity works

Every event is scored on a fixed scale so you can filter, alert, and report by importance rather than by listing individual actions. The Activity Logs viewer shows a colour badge for each level, and PRO notifications can target a minimum severity.

Severity Level
100 Info
200 Notice
300 Warning
400 Alert
500 High
600 Critical
700 Emergency

Most everyday activity — logins, content edits, plugin and theme changes — is recorded at Info (100). Failed logins are High (500), and an aggregated brute-force burst is Emergency (700). Yoast SEO changes that affect how search engines treat a page are recorded above Info.

How event IDs are organised

Each area owns a block of IDs, which is what makes it possible to filter or alert on a whole category without naming every event. The blocks in use:

Range Area
1000–1999 Users and security
2000–2999 Media
3000–3999 Comments
4000–4999 Plugins and plugin file edits
5000–5999 Themes and theme file edits
6000–6999 Posts and pages
7000–7999 Taxonomy terms
8000–8999 Navigation menus
9000–9999 Widgets
10000–10999 WordPress settings
11000–11999 Advanced Custom Fields PRO
12000–12999 bbPress PRO
13000–13999 WooCommerce PRO
14000–14999 URL Shortify and MemberPress PRO
15000–15999 Gravity Forms PRO
16000–16999 Yoast SEO PRO
17000–17999 MemberPress subscriptions, transactions, and members PRO

To add your own event, pick an ID from an unused range — see hooks and filters.

Users and security

ID Event type Action What it means Severity
1000 user login A user signed in Info
1001 user logout A user signed out Info
1002 user registered A new user account was created Info
1003 user delete A user account was deleted Info
1004 security login_failed A sign-in attempt failed for an existing user High
1005 user updated A profile was updated Info
1006 user password_reset A password was reset Info
1007 security login_failed_nonexistent A sign-in attempt for a username that does not exist High
1008 user role_changed A user's role changed Info
1009 security brute_force_detected Repeated failed logins from one IP within the detection window Emergency
1010 user session_terminated An administrator forced a session to log out PRO Info

Logins also record the method used, so a sign-in through Magic Link or a Temporary Login link is labelled as such. See Magic Link tagging and Temporary Login tagging.

Media

ID Action What it means
2000 added A file was uploaded
2001 updated An attachment was edited
2002 deleted An attachment was deleted

Comments

ID Action
3000 created
3001 updated
3002 deleted
3003 spammed
3004 unspammed
3005 trashed
3006 untrashed
3007 status_changed

Plugins

ID Action What it means
4000 activated A plugin was activated
4001 deactivated A plugin was deactivated
4002 installed_updated A plugin was installed or updated through the updater
4003 deleted A plugin was deleted
4004 installed A plugin was installed
4005 file_edited A plugin file was edited in the built-in editor
4006 updated A plugin was updated

Themes

ID Action What it means
5000 activated A theme was activated
5001 installed_updated A theme was installed or updated through the updater
5002 deleted A theme was deleted
5003 switched The active theme changed
5004 customized A change was saved in the Customizer
5005 installed A theme was installed
5006 file_edited A theme file was edited in the built-in editor
5007 updated A theme was updated

Posts and pages

ID Action What it means
6000 deleted Permanently deleted
6001 status_changed Status changed
6002 created Created
6003 trashed Moved to trash
6004 restored Restored from trash
6005 published Published
6006 updated Updated

These apply to every public post type, not only posts and pages.

Taxonomy terms, menus, widgets and settings

ID Event type Action
7000 term created
7001 term updated
7002 term deleted
8000 menu created
8001 menu updated
8002 menu deleted
9000 widget updated
10000 option changed

Option changes cover key WordPress settings such as the site title, tagline, admin email, and default role. Add your own with the kc_lf_tracked_options filter — see hooks and filters.

Advanced Custom Fields PRO

PRO feature

ACF tracking requires Logify PRO.

ID Action What it means
11000 deleted A field group was deleted
11001 deleted A post field was deleted
11002 deleted A taxonomy field was deleted

See how to track ACF deletions.

bbPress PRO

PRO feature

bbPress tracking requires Logify PRO and covers the whole forum, using the 12000–12999 ID block.

  • Forums — created, updated, trashed, restored, deleted, and status changed.
  • Topics — created, updated, trashed, restored, deleted, opened, closed, stickied, unstickied, marked spam, unspammed, approved, unapproved, moved, merged, and tags changed.
  • Replies — created, updated, trashed, restored, deleted, and moved.

Forums, topics, and replies are recorded once as forum activity rather than appearing again as generic post entries. See how to track bbPress activity.

WooCommerce PRO

PRO feature

WooCommerce tracking requires Logify PRO.

ID Action What it means
13000 created Product created
13001 deleted Product deleted
13002 trashed Product trashed
13003 restored Product restored
13004 updated Product updated
13010 created Order created
13011 status_changed Order status changed
13012 item_added Item added to an order
13013 item_removed Item removed from an order
13014 item_quantity_changed Order item quantity changed
13015 refunded Order refunded
13016 refund_deleted A refund was deleted
13017 updated Order updated
13020 created Coupon created
13021 updated Coupon updated
13022 trashed Coupon trashed
13023 restored Coupon restored
13024 deleted Coupon deleted
13030 created Customer created
13031 updated Customer updated
13032 deleted Customer deleted
13040 created Product category created
13041 updated Product category updated
13042 deleted Product category deleted
13050 created Product tag created
13051 updated Product tag updated
13052 deleted Product tag deleted
13060 updated WooCommerce settings saved

See how to track WooCommerce store changes.

URL Shortify PRO

PRO feature

URL Shortify tracking requires Logify PRO.

ID Action What it means
14000 created A short link was created
14001 updated A short link was updated
14002 deleted A short link was deleted

See URL Shortify integration logs.

MemberPress PRO

PRO feature

MemberPress tracking requires Logify PRO. Membership, group, rule, and settings events use the 14000 block; subscriptions, transactions, and members use the 17000 block.

  • Memberships, groups, and access rules — created, updated, trashed, restored, and deleted (IDs 14010–14040).
  • Subscriptions — created, updated, expired, and deleted (IDs 17000–17003).
  • Transactions — created, updated, and deleted (IDs 17010–17012).
  • Members — added, signup completed, account updated, and deleted (IDs 17020–17023).
  • Settings — MemberPress settings changes (ID 14040).

Memberships, groups, and rules are recorded once as membership activity rather than again as generic post entries. See how to track MemberPress activity.

Gravity Forms PRO

PRO feature

Gravity Forms tracking requires Logify PRO.

ID Action What it means
15000 created A form was created or saved
15001 trashed A form was moved to trash
15002 deleted A form was deleted
15003 duplicated A form was duplicated
15004 imported Forms were imported
15005 activated A form was activated
15006 deactivated A form was deactivated

See how to track Gravity Forms changes.

Yoast SEO PRO

PRO feature

Yoast SEO tracking requires Logify PRO.

ID Action What it means
16000 updated A post's Yoast SEO fields changed

Each save produces a single entry listing every SEO field that changed — title, meta description, focus keyphrase, social and X titles and images, canonical URL, indexing and following, cornerstone content, schema types, and breadcrumb title — with its old and new value. Changes that affect how search engines treat the page are recorded above Info severity. The tracked fields can be adjusted with the kc_lf_yoast_tracked_fields filter. See Yoast SEO activity logs.

Conclusion

This reference maps every event Logify records to its ID, action, and severity, so you can read any log entry and build filters, alerts, and reports against the right values. To act on these events, see how to filter WordPress activity logs; to record your own events or change what is logged, see hooks and filters.

FAQs

What do the severity levels mean?

Logify scores every event from Info (100) up to Emergency (700): Info, Notice, Warning, Alert, High, Critical, and Emergency. Most routine activity is Info. Failed logins are High (500) and an aggregated brute-force burst is Emergency (700). The scale lets you filter the log and target PRO notifications by a minimum severity instead of naming individual events.

Which events are free and which need Logify PRO?

All WordPress core events — users, security, media, comments, plugins, themes, posts, taxonomy, menus, widgets, and settings (IDs 1000–10999) — are free. Integration events for ACF, bbPress, WooCommerce, URL Shortify, MemberPress, Gravity Forms, and Yoast SEO (IDs 11000 and up) require Logify PRO, along with forced session termination.

What is the difference between failed login and brute-force events?

A failed login (ID 1004, or 1007 for a non-existent username) records one unsuccessful sign-in at High severity. When failures from the same IP and username cross the threshold within the detection window, Logify stops recording each attempt and writes a single aggregated brute-force event (ID 1009) at Emergency severity for the rest of the window, keeping the log readable during an attack.

Can I add my own event types to Logify?

Yes. Create an activity class that extends BaseActivity, set its $event_id, $event_type, $action, and $severity, and pick an event ID from an unused range so it does not collide with the blocks listed above. Trackers are auto-discovered by file. See hooks and filters for the full procedure.

Do these events apply to custom post types?

Yes. The post events (IDs 6000–6006 — created, updated, published, trashed, restored, status changed, and deleted) apply to every public post type, not only posts and pages. You can narrow which post types are logged using the Excluded Post Types rule on the Exclusions settings tab.

Was this page helpful?