The Audit Log is the full record for the selected server: detections, connections, admin actions and system events, newest first.
This page covers the entry types, severity levels, and how to filter the log during an investigation.
Entry types
| Type | Records |
|---|---|
| Connection | Players joining |
| Disconnect | Players leaving, with reason and session length |
| Detection | A detection firing |
| Admin action | Something a staff member did, with their name |
| Config | Configuration changes and identifier changes |
| System | Startup, shutdown and internal events |
This is what makes misuse of the moderation tools visible after the fact.
Severity
| Level | Meaning |
|---|---|
| Info | Routine |
| Warning | Worth noticing |
| Critical | Needs attention — a ban, a failed integrity check, unusual admin activity |
Filtering to critical is a reasonable daily check.
Identifier changes
When a returning player’s identifiers do not match what was stored, the change is logged as a config warning showing exactly what differs.
This is usually innocent — a newly linked Steam account, or a changed IP. Repeated changes on one account are worth reviewing, since dropping an identifier is one way to avoid a ban.
Retention
Old entries are removed according to Log Retention on
Configuration. Setting it to 0 keeps everything
indefinitely, and the table grows without limit.
Filtering
Search matches type, severity, player name and message. Combine it with the type and severity filters to narrow an investigation — admin actions at critical severity, for example, is a short list.