Event log and reports
The security event log stingsby keeps for each Discord server for 90 days, and the downloadable Markdown report for audits.
Event log
Each server has its own log, shown by /honeypot logs and included in reports. Events are kept for 90 days. The log is recorded even when no log channel is set; the log channel is a live feed of the same events.
| Kind | Recorded when | Contains |
|---|---|---|
| 🔨 Ban | The trap banned someone | User, ID, trigger message |
| ⚠️ Ban failed | The trap fired but the ban didn't go through | User, ID, reason, message |
| ⚙️ Config | Someone changed a setting | Who made the change and what changed |
| 🚨 Warning | The honeypot or log channel was deleted | Which channel, and what that switched off |
| 🧹 Clear | Someone deleted messages with /clear | Who ran it, how many messages, where, and whose |
| 📥 Joined | A member joined while the join log is on | Who joined, and who invited them with which invite |
| 📤 Left | A member left or was removed while the join log is on | Who left, and when they had joined |
| 🔓 Unban | Someone pressed Unban on a ban report | Who unbanned whom |
Reports
/security report days:7 replies with a summary (bans, failed bans, warnings, setting changes, the busiest day and the security score) and attaches a Markdown file, honeypot-report-<serverID>-<date>.md, with:
- the server, its ID and the exact time range (UTC)
- a summary table and the current configuration
- every scan finding, with explanations
- every banned account: time, result, username, ID and trigger message
- every setting change, clean-up, unban and warning, with who did it
Markdown opens in any text editor and looks tidy on GitHub, in Obsidian or in VS Code, so you can keep it as an audit record or share it with co-admins.