Skip to content

Feature Guide Audit Log

fuomag9 edited this page Sep 26, 2026 · 4 revisions

Feature Guide: Audit Log

Track configuration changes and user activity in Caddy Proxy Manager.

Table of Contents

  1. What the Audit Log Captures
  2. Search and Pagination
  3. How to Use It
  4. Troubleshooting

What the Audit Log Captures

Audit entries include:

  • Timestamp
  • User (or System)
  • Event summary

Typical events:

  • Proxy host create/update/delete
  • Access list changes
  • Certificate changes
  • Sign-in username changes by an administrator (since v1.13.1): Changed user <id> sign-in username to <username>, with the previous username in the entry's data (see Feature Guide User Management#sign-in-usernames)
  • Instance sync key pins (since v1.13.1): a slave's key pinned on first use, re-pinned after a rotation proof, pinned or reset by an admin, or removed when the instance is deleted or its base URL changes. Search for instance_sync_key to list them (see Feature Guide Instance Sync)
  • Other administrative operations

Use the audit log to answer: who changed what and when.


Search and Pagination

The audit log now supports server-side filtering and paging.

  • Search box filters by event summary, action, and entity type
  • Results are paginated on the server
  • Default page size: 50
  • URL params are used for state:
    • search: current search text
    • page: current page number

Search resets to page 1 automatically when the query changes.


How to Use It

  1. Open Audit Log.
  2. Enter text in Search audit log... to narrow results.
  3. Use pagination controls to browse older/newer pages.
  4. Share a filtered view by copying the URL.

Example URL:

/audit-log?search=proxy&page=2

Troubleshooting

No results found

Checks:

  1. Clear search text and retry
  2. Ensure there is recent activity in the system
  3. Verify you are on page 1 after changing search terms

Unexpected user shown as System

Some operations are intentionally system-generated and are not linked to a human user ID.

Entries made by a user who has since been deleted are also shown as System. Since v1.13.1, deleting a user keeps their audit entries but removes the link to the user, so a new account that later gets the same user ID is not credited with them. On the first start after upgrading, entries still linked to users that an older release deleted are cleared the same way, unless another account already has that ID (logged as Cleared rows left by deleted user id(s) <ids>).


Related Documentation


Need help? Open an issue with the query used and expected event details.

Clone this wiki locally