Skip to content

Advanced Features (PRO)

How To Read Logify PRO Email Digest Insights

A plain activity count in your digest tells you how busy the site was, but not whether anything was wrong. Logify PRO enriches the standard Email Digest with security-focused insights — a severity breakdown, brute-force burst count, file-edit count, most active user, top IP address, and top event type — so a two-minute read tells you whether the period was routine or worth investigating. These insights appear automatically inside the digest email when Logify PRO is active.

PRO feature

The Email Digest itself is free. The extra insights described here — severity breakdown, brute-force count, file edits, top user, top IP, and top event type — are added only when Logify PRO is active. Upgrade at kaizencoders.com/logify.

What are Logify PRO digest insights?

Logify PRO digest insights are additional summary blocks Logify adds to the scheduled Email Digest email so the report highlights security and activity patterns, not just totals. The free digest already reports counts such as total events, logins, new users, and posts changed; the PRO insights layer the following on top:

Insight What it tells you
Severity breakdown How many Critical, High, and Warning events occurred in the period
Brute-force burst count How many aggregated brute-force login events were recorded
File edits How many plugin or theme files were edited from the WordPress editor
Most active user The user with the most logged activity, and how much
Top IP address The IP that appeared most in the logs, and its count
Top event type The category of event that occurred most often

Where the insights appear

The insights are part of the digest email itself, not a screen in wp-admin. To receive it, enable and schedule the digest under Logify → Settings → Email Digest, then read the PRO insight blocks in the email Logify sends. To check the layout without waiting for the schedule, use Send Test on that same settings tab.

How Do I Read Logify Pro Email Digest Insights?

Read the severity breakdown

The severity breakdown counts the period's Critical (600+), High (500+), and Warning (300+) events. A period made up of Warnings is usually routine; a jump in Critical or High counts is your signal that something needs a closer look. Use it as the first thing you scan.

Check the brute-force burst count

This counts aggregated brute-force login events. Logify raises one of these when repeated failed logins from the same source cross its threshold, so any non-zero count points to a login attack worth reviewing in the log.

Note the file edits count

This counts plugin and theme files edited directly through the WordPress file editor during the period. Unexpected file edits are a common sign of compromise or of a change made outside your normal deployment process, so a non-zero count on a site you thought was static deserves attention.

Identify the most active user and top IP

The Most active user block names who generated the most logged activity and how many events; the Top IP address block names the IP that appeared most and its count. Together they answer "who and where" — a familiar admin at the top is normal, while an unknown user or an unexpected IP is a lead to follow in the activity log filters.

Read the top event type

The Top event type block shows which category of activity — such as user, post, or plugin events — dominated the period. It frames the main story of the digest: a period led by post events is content work, while one led by security or user events may mean account activity worth checking.

Conclusion

Logify PRO digest insights turn a routine summary email into a quick security read: scan the severity breakdown and brute-force count first, then use the top user, top IP, and top event type to decide whether to dig in. When something looks off, open the activity log and filter it to the matching time range, or watch patterns build up over time in the PRO analytics dashboard.

FAQs

Is the Logify Email Digest free or PRO?

The Email Digest is free — the free plugin sends the scheduled daily, weekly, or monthly summary with counts of logins, users, posts, and other activity. Logify PRO does not add the digest; it enriches it with extra insight blocks: a severity breakdown, brute-force burst count, file-edit count, most active user, top IP address, and top event type.

How do I preview the digest without waiting for the schedule?

Go to Logify → Settings → Email Digest and use Send Test to email yourself the current digest, or Preview Email to view it. With Logify PRO active, the test email includes the same PRO insight blocks you will receive on the schedule, so you can confirm the layout and recipients before relying on it.

What does a high brute-force burst count mean?

It means Logify recorded one or more aggregated brute-force login events during the period. Logify collapses repeated failed logins from the same source into a single brute-force event once they cross its threshold, so even a small count reflects a sustained attempt rather than one typo. Open the activity log, filter to security events, and review the source IPs.

Which insight should I check first?

Start with the severity breakdown. If Critical and High counts are low and the brute-force count is zero, the period was routine and you can stop there. If either is elevated, move to the top IP and most active user to see who and where, then open the activity log for the matching time range to investigate the specific events.

Why don't I see the PRO insights in my digest?

The insight blocks only render when Logify PRO is active. If your digest shows totals but no severity breakdown, brute-force count, or top-IP blocks, you are on the free plugin, which sends the base digest only. Confirm your PRO license is active, then send a test digest from Logify → Settings → Email Digest to verify the enriched email.

Was this page helpful?