Open Security Ninja → Events → Settings to control what is logged and how long it is kept.
Enable events logging
When this is off, event hooks and database writes are skipped. Use that on sites where you only want other Security Ninja features, or while debugging.
Admin-creation emails (Pro) still work if you have them enabled. See Monitoring administrator accounts.
Log REST API errors
Off by default. Turn it on only when you need diagnostics: REST authentication failures and HTTP 400+ responses are then written to the Events log. Leave it off on API-heavy sites (WooCommerce, headless, mobile apps) or the log fills with noise.
This setting is included in Tools import/export and MainWP copy on Security Ninja 5.303 or newer. Older exports without the key import as off.
Email reports (Pro)
Receive email reports after a chosen number of events. Only enable this if you are ready for the volume of mail on a busy site. Set the recipient address carefully.
Modules (Pro)
Choose which groups to log:
- Comments
- File editor
- Installer
- Media
- Menus
- Posts
- Settings
- Taxonomies
- Users
- Widgets
- WooCommerce
- Security Ninja
Log retention
Default: keep logs for 7 days.
You can keep logs by days (1, 7, 30, 60, 90, 180, or 365) or by record count (last 100 up to last 10,000). Longer retention uses more database space.
Selected firewall and block events can be kept longer for investigations (up to about 2 years). Use Delete all log entries only when you intentionally want an empty log. That action cannot be undone. Export first if you need a copy (Pro CSV download on the Event Log tab).
Webhooks (Pro)
Configure webhook events and optionally Zapier under the Webhooks subtab.
