• Features
  • Pricing
  • Help
  • My Account
  • Buy Now
WP Ghost
  • Features
  • Pricing
  • Help
  • My Account
  • Buy Now

Lesson 4 – How to Use the Website Events Log in WP Ghost

/Getting Started /Lesson 4 – How to Use the Website Events Log in WP Ghost
Table of Contents
  • What Is the Events Log?
  • How to Activate and Use the Events Log
    • Activate the Events Log
    • Check and Filter the Log
    • Set Up Email Alerts
  • Frequently Asked Questions
    • Is this available in the free version?
    • What’s the difference between local and cloud storage?
    • What’s the difference between Events Log and Security Threats Log?
    • Does the Events Log store personal data?
    • Does WP Ghost modify WordPress core files?
  • Related Tutorials

Track every user action on your WordPress site and get notified when critical events happen. The Events Log records logins, content changes, plugin activations, settings modifications, and other dashboard actions. Logs are stored locally in your WordPress database with configurable retention, and optionally synced to WP Ghost’s cloud for 30-day access from any device. If you manage a team or give clients backend access, you’ll know exactly what was changed, by whom, and when. Set up email alerts for critical actions like logins from new IPs or unauthorized settings changes. This is a Premium feature.

What Is the Events Log?

What is the WP Ghost Events Log for tracking user actions and preventing unauthorized changes

The Events Log monitors and records user actions in your WordPress dashboard. It tracks logins, logouts, content edits, plugin activations, settings modifications, and more. Logs are stored in your local database, so you always have a record of what happened on your site. You can optionally enable cloud storage to keep a copy on the WP Ghost Dashboard for 30 days, accessible from any device, even if someone deletes the plugin from your site. For the full feature reference, see the Events Log Report tutorial.

How to Activate and Use the Events Log

Activate the Events Log

  1. Go to WP Ghost > Logs > Settings.
  2. Switch on Log Users Events to start monitoring.
  3. Optionally, switch on Enable Cloud Storage for Events Log to keep a copy on the WP Ghost Dashboard for 30 days.
  4. Select the user roles you want to monitor from Log User Roles. Leave empty to monitor all roles.
  5. Click Save.
WP Ghost Events Log settings with Log Users Events toggle, cloud storage option, and user role selection

User role filtering: You can choose to log only specific roles. For example, monitor Subscribers and Contributors but skip Administrator activity. Select multiple roles or leave the dropdown empty (“Nothing Selected”) to track all user roles.

Cloud storage is tamper-proof. When enabled, cloud-stored logs remain accessible from the WP Ghost Dashboard even if a user deactivates and deletes the plugin from your site. Local logs stored in your database are removed if the plugin is uninstalled.

Check and Filter the Log

View the Events Log from your WordPress site (WP Ghost > Logs > Events Log) or from the WP Ghost Dashboard if cloud storage is enabled.

WP Ghost Events Log report showing user actions with timestamps and details in the WordPress dashboard
Events Log in your WordPress dashboard
WP Ghost Dashboard cloud Events Log accessible from any device with multi-site filtering
Events Log in the WP Ghost Dashboard (cloud)

If you manage multiple sites, click Filter and select the website from “Filter by URL.” You can also filter by user action type and time interval. Click Search to see details for every action: username, role, paths, post name, plugin name, attachment, and more.

Cloud-stored logs are retained for 30 days. Local logs are retained based on the retention period you set in Settings.

Timezone note: Event times are stored in UTC-0 on the WP Ghost Dashboard. Convert to your local timezone when reviewing cloud logs.

Set Up Email Alerts

Get notified instantly when critical actions happen on your site. Go to the WP Ghost Dashboard at Email Alerts > New Alert and select the events you want to be notified about.

WP Ghost Dashboard email alert creation with predefined security alert options

WP Ghost includes predefined alerts such as login from a new IP, unauthorized settings changes, plugin activations, and user role modifications. Alerts are sent immediately when the event triggers. You can manage all alerts from the Email Alerts section for every website connected to your account.

WP Ghost Dashboard email alerts list showing active security alerts for all connected sites

Email alerts require cloud storage. To receive email alerts, the Enable Cloud Storage for Events Log option must be switched on. Alerts are triggered from cloud-stored events.

Frequently Asked Questions

Is this available in the free version?

No. The Events Log and Email Alerts require WP Ghost Premium. The free version does not include user activity logging.

What’s the difference between local and cloud storage?

Local storage saves events in your WordPress database. Logs are accessible from your WordPress dashboard and retained based on the period you configure. If the plugin is uninstalled, local logs are removed. Cloud storage sends a copy to the WP Ghost Dashboard where logs are kept for 30 days. Cloud logs survive plugin deletion, are accessible from any device, and are required for email alerts.

What’s the difference between Events Log and Security Threats Log?

The Events Log tracks actions by logged-in users (edits, logins, settings changes). The Security Threats Log tracks malicious requests from external visitors (blocked attacks, firewall hits, brute force attempts). Together they give you full visibility into both internal activity and external threats.

Does the Events Log store personal data?

Yes. The log records usernames, IP addresses, and user actions. If you need to comply with GDPR or similar regulations, inform your users that their dashboard activity is logged. Cloud-stored data is kept for 30 days and then automatically deleted. Local retention is configurable. See the Events Log Report tutorial for GDPR details.

Does WP Ghost modify WordPress core files?

No. The Events Log operates through WordPress hooks that monitor actions. No core files are modified. Local logs are stored in a dedicated database table. Cloud logs are sent via API.

Related Tutorials

Monitoring and logging features:

  • Events Log Report – The full reference tutorial with all event types, filtering, GDPR details, and role-based configuration.
  • Security Threats Log – Monitor external threats and blocked attacks.
  • Security Monitor – Weekly cloud-based security scanning.
  • Hide from Theme Detectors – The previous step: verify your site is fully hidden.
  • Brute Force Protection – Protect the login page before monitoring login activity.
Tagged: events loguser action loglogin email alertsbrute force email alert

Related Articles

  • WP Ghost – Free vs Premium

  • WP Ghost Settings – Best Practice

  • Lesson 1 – Customize Paths and Hide Your WordPress Website

  • Lesson 2 – Activate Brute Force Protection on Your Login Page

  • Lesson 3 – Hide Your Site from WordPress Theme Detectors and Bots

WP Ghost

Stop WordPress hacks before they start

Path security, 8G firewall, brute force protection, and passkeys. 60-second setup.

Install Free → See Premium Plans
Last 30 days
100M+ threats blocked
Across 250,000+ protected sites.
Read the Impact Report →
Rated by real users
★ 4.5
WordPress.org
★ 4.8
G2
★ 4.8
Capterra
★ 4.8
AppSumo
Getting Started
  • What is WP Ghost?
  • Install WP Ghost (Free)
  • 3-Minute Safe Mode Setup
  • Best Practice Settings Guide
  • One-Click Security Presets
  • Website Security Check
Path Security
  • Hide wp-admin Path
  • Hide wp-login Path
  • Change wp-content Path
  • Change Plugins Path
  • Hide Author ID & Path
  • Change REST API Path
  • Change admin-ajax.php Path
Login & 2FA
  • Two-Factor Authentication (2FA)
  • Passkey 2FA (Face ID, Touch ID)
  • Magic Link Login
  • Temporary Logins
  • Brute Force Protection + reCAPTCHA
  • Login Page Designer
Firewall & Monitoring
  • 7G & 8G Firewall
  • Security Headers (HSTS, CSP)
  • Security Threats Log
  • User Events Log
  • Country Blocking (Geo)
  • Disable XML-RPC Access
Hardening
  • Hide Your WordPress Website
  • Hide from Theme Detectors
  • Hide Common WordPress Files
  • Prevent Hack Attacks on WordPress
  • Hacker Bot Attack Types
Compatibility
  • Plugin Compatibility List
  • Theme Compatibility List
  • WooCommerce Setup
  • Nginx Server Setup
  • Hosting Setup Guides
  • Emergency: Disable WP Ghost
Help & Resources
  • Full Knowledge Base
  • Frequently Asked Questions
  • Changelog
  • Developer Hooks Reference
  • Contact Support
Free vs Premium?

Lite Mode (Free) covers core path security. Safe Mode and Ghost Mode (Premium) add advanced features.

Compare Plans →

Product

  • What is WP Ghost?
  • Free vs Premium
  • Pricing
  • Changelog
  • Why WP Ghost
  • Knowledge Base

Features

  • Path Security
  • Firewall Security
  • Brute Force Protection
  • Two-Factor Authentication
  • User Events Log
  • Security Threats Log

Resources

  • Getting Started Guide
  • Plugin Compatibility
  • Theme Compatibility
  • Hosting Setup Guides
  • Developer Hooks
  • Impact Report

Company

  • Affiliate
  • Media Kit
  • Terms Of Use
  • Privacy Policy
  • GDPR Compliance
  • Contact
  • Facebook
  • YouTube
  • X
© WP Ghost 2016-2026 | Powered by AISQ | Squirrly