Skip to main content

Audit Insights

Audit Insights

Last verified: 2026-07-08

Audit insights summarize audit activity so administrators can spot patterns without reading every event row. Use them for triage, review meetings, and support handoff; use the raw audit log when you need event-level evidence.

Summary types

Awthy can summarize:

  • severity counts,
  • outcome counts,
  • top event types,
  • daily activity,
  • recent critical events,
  • actor/source/reason patterns,
  • WooCommerce and WordPress mutation summaries where those signals are enabled.

Time windows

Choose a window that matches the question. Short windows help with active incidents. Longer windows help with support trends, rollout effects, and compliance reviews.

If a summary looks suspicious, drill into the audit log with matching filters before taking destructive action.

Summary versus raw events

Use summaries to answer "what changed?" or "where is the risk concentrated?" Use raw audit events to answer "which exact action happened?" or "what evidence should be retained?"

Summaries should never expose secrets, raw customer data, raw order data, full IP addresses in exported support notes, full user agents, or absolute server paths.