Audit Log event types
The types of events that are recorded in Audit Logs for an organization or an application.
| Feature | Event key | Recorded event type |
|---|---|---|
| Application lifecycle | app:create | Created an application |
site-retire | Retired an application | |
| Backup Shipping | sites:backup-shipping:deleted | Deleted a Backup Shipping configuration |
sites:backup-shipping:disabled | Disabled Backup Shipping | |
sites:backup-shipping:enabled | Enabled Backup Shipping | |
sites:backup-shipping:updated | Updated a Backup Shipping configuration | |
| Basic Authentication | basic-auth:add-user | Added a Basic Authentication username/password combination |
basic-auth:create | Enabled Basic Authentication | |
basic-auth:delete | Disabled Basic Authentication | |
basic-auth:delete-user | Removed a Basic Authentication username/password combination | |
basic-auth:update | Updated the Basic Authentication configuration | |
basic-auth:update-user | Updated a Basic Authentication username/password combination | |
| Code Deployment | change-repo | Updated the repository/branch that deploys to an environment |
client-site:custom-deploy:disable | Enabled Default Deployment | |
client-site:custom-deploy:enable | Enabled Custom Deployment | |
environment:rollback:started | Started a rollback to a previous commit | |
sites:commits:deploy | A commit was deployed to an environment | |
sites:deploy:failure | A deployment failed | |
sites:deploy:success | A deployment finished | |
| Codebase: Plugins | client-site:plugins:update-pr-created | A user initiated a pull request to update a plugin |
| Custom Deployments | sites:custom-deploy:deactivate-access-token | Deactivated a Custom Deployment access token |
sites:custom-deploy:generate-access | Generated a Custom Deployment access token | |
| Custom error pages | custom-error-page:config:update | The source for a custom error page was updated |
custom-error-page:repository-content:delete | The file for a custom error page was deleted from the repository | |
custom-error-page:repository-content:update | The content of a custom error page was updated | |
| Custom metric anomalies | custom:anomalies:app-cpu-usage:end | An app CPU usage anomaly ended (custom metric-threshold detection) |
custom:anomalies:app-cpu-usage:start | An app CPU usage anomaly started (custom metric-threshold detection) | |
custom:anomalies:app-memory-usage:end | An app memory usage anomaly ended (custom metric-threshold detection) | |
custom:anomalies:app-memory-usage:start | An app memory usage anomaly started (custom metric-threshold detection) | |
custom:anomalies:db-data-size:end | A DB data size anomaly ended (custom metric-threshold detection) | |
custom:anomalies:db-data-size:start | A DB data size anomaly started (custom metric-threshold detection) | |
custom:anomalies:edge-cache-hit-rate:end | An edge cache hit rate anomaly ended (custom metric-threshold detection) | |
custom:anomalies:edge-cache-hit-rate:start | An edge cache hit rate anomaly started (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-2xx:end | An edge HTTP response count 2xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-2xx:start | An edge HTTP response count 2xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-3xx:end | An edge HTTP response count 3xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-3xx:start | An edge HTTP response count 3xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-4xx:end | An edge HTTP response count 4xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-4xx:start | An edge HTTP response count 4xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-5xx:end | An edge HTTP response count 5xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:edge-http-response-count-5xx:start | An edge HTTP response count 5xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-delete:end | A Memcached command count delete anomaly ended (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-delete:start | A Memcached command count delete anomaly started (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-get:end | A Memcached command count get anomaly ended (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-get:start | A Memcached command count get anomaly started (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-set:end | A Memcached command count set anomaly ended (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-set:start | A Memcached command count set anomaly started (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-total:end | A Memcached command count total anomaly ended (custom metric-threshold detection) | |
custom:anomalies:memcached-command-count-total:start | A Memcached command count total anomaly started (custom metric-threshold detection) | |
custom:anomalies:memcached-hit-rate:end | A Memcached hit rate anomaly ended (custom metric-threshold detection) | |
custom:anomalies:memcached-hit-rate:start | A Memcached hit rate anomaly started (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-delete:end | A MySQL command count delete anomaly ended (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-delete:start | A MySQL command count delete anomaly started (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-insert:end | A MySQL command count insert anomaly ended (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-insert:start | A MySQL command count insert anomaly started (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-kill:end | A MySQL command count kill anomaly ended (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-kill:start | A MySQL command count kill anomaly started (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-select:end | A MySQL command count select anomaly ended (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-select:start | A MySQL command count select anomaly started (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-update:end | A MySQL command count update anomaly ended (custom metric-threshold detection) | |
custom:anomalies:mysql-command-count-update:start | A MySQL command count update anomaly started (custom metric-threshold detection) | |
custom:anomalies:mysql-slow-query-count:end | A MySQL slow query count anomaly ended (custom metric-threshold detection) | |
custom:anomalies:mysql-slow-query-count:start | A MySQL slow query count anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-2xx:end | An origin HTTP response count 2xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-2xx:start | An origin HTTP response count 2xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-3xx:end | An origin HTTP response count 3xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-3xx:start | An origin HTTP response count 3xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-4xx:end | An origin HTTP response count 4xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-4xx:start | An origin HTTP response count 4xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-5xx:end | An origin HTTP response count 5xx anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-count-5xx:start | An origin HTTP response count 5xx anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p50:end | An origin HTTP response time p50 anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p50:start | An origin HTTP response time p50 anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p75:end | An origin HTTP response time p75 anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p75:start | An origin HTTP response time p75 anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p95:end | An origin HTTP response time p95 anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p95:start | An origin HTTP response time p95 anomaly started (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p99:end | An origin HTTP response time p99 anomaly ended (custom metric-threshold detection) | |
custom:anomalies:origin-http-response-time-p99:start | An origin HTTP response time p99 anomaly started (custom metric-threshold detection) | |
| Custom Metric Thresholds | custom-metric-thresholds-config:create | Created a custom metric threshold configuration |
custom-metric-thresholds-config:delete | Deleted a custom metric threshold configuration | |
| Data sync | data-sync:started | Queued a data sync |
| Database Backups | backup-download:generate-url | Generated a database backup download URL |
backup:restore:started | Started a database backup restore | |
backup:started | Requested a database backup | |
db-backup-download:started | Started a database backup download | |
| Defensive Mode | defensive-mode:disabled | Disabled Defensive Mode |
defensive-mode:enabled | Enabled Defensive Mode | |
defensive-mode:update | Updated the Defensive Mode configuration | |
| Domains | domains:added | Added a domain |
domains:created | Added a domain | |
domains:deleted | Deleted a domain | |
domains:inherited-verification-status | A domain inherited its verification status from another domain | |
domains:updated | Updated a domain | |
domains:verify-txt | Verified a domain | |
| Elasticsearch | elasticsearch:upgrade:completed | An Elasticsearch upgrade completed |
| Environment Management | app:environments:create | Created an environment |
| Environment security | environment:code:vulnerability-found | A code vulnerability was found in the environment |
| Environment variables | envvar:created | Added an environment variable |
envvar:deleted | Deleted an environment variable | |
envvar:updated | Updated an environment variable | |
| GitHub repository | client-site:deploy-key:added | Added a GitHub deploy key |
client-site:deploy-key:deleted | Deleted a GitHub deploy key | |
client-site:deploy-key:updated | Updated a GitHub deploy key | |
site-setup:webhook:configured | Configured a GitHub webhook | |
| HSTS | hsts-header:update | Updated HSTS settings |
| Imports | import:start | Requested a SQL import |
media-import:abort | Aborted a media import | |
media-import:start | Requested a media import | |
| Integrations | client-site:integration:disable | Disabled an integration (integration status changed to disabled) |
client-site:integration:enable | Enabled an integration (integration status changed to enabled) | |
client-site:integration:manage | Updated an integration’s configuration | |
client-site:integration:status-change | Changed an integration’s status | |
client-site:vip-integration:added-or-updated | Updated a configuration for an Integration | |
client-site:vip-integration:deleted | Removed an integration (legacy) | |
client:integration:disable | Integration disabled | |
client:integration:enable | Integration enabled | |
client:integration:manage | Updated an integration’s configuration | |
client:integration:status-change | Integration status updated | |
client:vip-integration:added-or-updated | Updated a configuration for an Integration | |
client:vip-integration:deleted | Removed an integration (legacy) | |
network-site:integration:disable | Disabled an integration (integration status changed to disabled) | |
network-site:integration:enable | Enabled an integration (integration status changed to enabled) | |
network-site:integration:manage | Updated an integration’s configuration | |
network-site:integration:status-change | Changed an integration’s status | |
network-site:vip-integration:added-or-updated | Added or updated an integration configuration (legacy) | |
network-site:vip-integration:deleted | Removed an integration (legacy) | |
| IP Restrictions | ip-allow-list:create | Enabled an IP Allow List |
ip-allow-list:delete | Deleted an IP Allow List | |
ip-allow-list:update | Updated an IP Allow List | |
ip-deny-list:create | Enabled an IP Deny List | |
ip-deny-list:delete | Deleted an IP Deny List | |
ip-deny-list:update | Updated an IP Deny List | |
| Launch | client-site:launched | Updated the site launch status (site metadata) |
| Launch a network site | domains:update-subsite:end | Completed updating the domain of a network site on a WordPress multisite environment |
domains:update-subsite:start | Started updating the domain of a network site on a WordPress multisite environment | |
network-site:update-status:launched | Changed network site launch status | |
network-site:update-status:not-launched | Changed network site launch status | |
| Launch a single site | client-site:update-status:launched | Changed site launch status |
client-site:update-status:not-launched | Changed site launch status | |
domains:set-primary | Switched primary domain | |
| Log Shipping | log-shipping:create | Enabled a Log Shipping configuration |
log-shipping:delete | Deleted a Log Shipping configuration | |
log-shipping:disable | Disabled Log Shipping | |
log-shipping:enable | Enabled a Log Shipping configuration | |
log-shipping:update | Updated a Log Shipping configuration | |
sites:log-shipping:auto-disabled | Log Shipping automatically disabled due to persistent errors | |
sites:log-shipping:deleted | Deleted a (cloud) Log Shipping configuration | |
sites:log-shipping:disabled | Disabled (cloud) Log Shipping | |
sites:log-shipping:enabled | Enabled (cloud) Log Shipping | |
sites:log-shipping:updated | Updated a (cloud) Log Shipping configuration | |
| MCP | mcp:vip:execute | Executed a VIP MCP tool |
mcp:wordpress:execute | Executed a WordPress MCP tool | |
| Media Backups | media-export:generate-signed-url | Downloaded a media backup |
media-export:start | Started a media backup | |
| Metrics anomalies | anomalies:edge-http-response-429-rate:end | An edge HTTP response 429 rate anomaly ended (automated detection) |
anomalies:edge-http-response-429-rate:start | An edge HTTP response 429 rate anomaly started (automated detection) | |
anomalies:memcached-hit-rate:end | A Memcached hit rate anomaly ended (automated detection) | |
anomalies:memcached-hit-rate:start | A Memcached hit rate anomaly started (automated detection) | |
anomalies:mysql-slow-query-count:end | A MySQL slow query count anomaly ended (automated detection) | |
anomalies:mysql-slow-query-count:start | A MySQL slow query count anomaly started (automated detection) | |
anomalies:origin-http-response-count-5xx:end | An origin HTTP response count 5xx anomaly ended (automated detection) | |
anomalies:origin-http-response-count-5xx:start | An origin HTTP response count 5xx anomaly started (automated detection) | |
| New Relic | client-site:new-relic-license:added | Enabled New Relic |
client-site:new-relic-license:deleted | Disabled New Relic | |
client-site:new-relic-license:updated | Access to New Relic given/removed | |
| Notifications | notifications:recipients:create | Created a Notifications recipient |
notifications:recipients:delete | Deleted a Notifications Recipient | |
notifications:recipients:update | Updated a Notifications Recipient | |
notifications:subscriptions:create | Created a notification subscription | |
notifications:subscriptions:delete | Deleted a notification subscription | |
notifications:subscriptions:disable | Disabled a notification subscription | |
notifications:subscriptions:enable | Enabled a notification subscription | |
notifications:subscriptions:update | Updated a notification subscription | |
| phpMyAdmin | phpmyadmin:generate-access | Started a phpMyAdmin session |
| Purge the page cache | page-cache:purged | Purged one or more URLs from the page cache |
| Single Sign-On for the VIP Dashboard | auth-domain:save | Updated the organization’s SSO registered domains |
enforce-sso-access:disabled | Disabled Enforce SSO Access | |
enforce-sso-access:enabled | Enabled Enforce SSO Access | |
identity-providers:create | Created the SSO configuration | |
identity-providers:delete | Deleted the SSO configuration | |
identity-providers:disabled-encryption | Disabled SSO Assertion Encryption | |
identity-providers:enabled-encryption | Enabled SSO Assertion Encryption | |
identity-providers:login-failure | Failed logging in via SSO | |
identity-providers:login-success | Logged in via SSO | |
identity-providers:update | Updated the SSO configuration | |
identity-providers:user-first-login | Logged in via SSO for the first time | |
| Site management | client-site:updated | Updated one or more environment/site properties |
lock-upgrade | Locked the site for an upgrade | |
migrations:mysql | Ran a MySQL migration | |
| Software Versions | client-site:software:changed | Changed the site software version |
sites:php:upgrade:started | Started a software update | |
sites:wp:upgrade:started | Started a software update | |
| TLS/SSL certificates | certificates:activated | Activated a custom TLS certificate for a domain |
certificates:create | Added a custom TLS certificate | |
certificates:deactivated | Deactivated a custom TLS certificate for a domain | |
certificates:update | Updated a custom TLS certificate | |
client-site:certificate:added | Added a custom TLS certificate (site metadata) | |
client-site:certificate:deleted | Deleted a custom TLS certificate | |
client-site:certificate:updated | Updated a custom TLS certificate (site metadata) | |
lets-encrypt:disable | Disabled a Let’s Encrypt certificate for a domain | |
lets-encrypt:enable | Enabled a Let’s Encrypt certificate for a domain | |
lets-encrypt:option:update | Changed Let’s Encrypt configuration | |
| User Agent Restrictions | user-agent-deny-list:create | Enabled User Agent Deny List |
user-agent-deny-list:delete | Deleted User Agent Deny List | |
user-agent-deny-list:update | Updated User agent Deny List | |
| User management | user-vip-role:update | Updated the internal VIP (isVIP) flag for a user |
| VIP Dashboard access | user-organization-role:add | Added a user’s role |
user-organization-role:remove | Removed a user’s role | |
user-organization-role:update | Updated a user’s role | |
users:invitation:accepted | Accepted an invitation | |
users:invitation:canceled | Canceled an invitation | |
users:invitation:created | Created an invitation | |
users:invitation:resend | Resent an invitation | |
| VIP Support user | client-site:support-user:added | Created a VIP Support user on the WordPress environment |
| WP-CLI commands | wp-cli:command | Ran a WP-CLI command using VIP-CLI |
Last updated: August 04, 2026