Hosmel Quintana
Laravel Audit Logs
Introduction
Installation
Configuration
Basic usage
Recording Audit Logs
Actors and Targets
Recording Attribute Changes
Querying Audit Logs
Testing Audit Logs
Advanced usage
Configuring Audit Context
Redacting Sensitive Data
Batching and Correlating Logs
Customizing the Audit Log Model
View on GitHub

Configuration

Configure default attributes, request metadata, redaction, retention, and storage.

The published config/audit-log.php file contains five groups of options. Most options can be set through environment variables; see the table at the end of this page.

Default attributes

OptionDefaultDescription
defaults.bucketapplicationBucket used when a log does not set one.
defaults.sourceplatformSource used when a log does not set one.

The builder applies these defaults when it prepares a log. Values passed to bucket() and source() take precedence. AuditLogData objects you create yourself must set both values.

Request metadata

OptionDefaultDescription
request.capture_remote_iptrueFill a missing remote IP from the current request.
request.capture_user_agenttrueFill a missing user agent from the current request.
request.capture_in_consolefalseAllow capture while the application runs in the console.

Console capture is disabled because Laravel binds a synthetic request when running Artisan commands. Queue workers also run in the console, so logs recorded from queued jobs have no request metadata unless you set it yourself. Enable capture_in_console only when the console request holds the values you want to store.

See request metadata for how captured and explicit values are combined.

Redaction

OptionDefaultDescription
redaction.exclude[]Metadata keys removed from logs.
redaction.mask[]Metadata keys whose values are replaced.
redaction.replacement[REDACTED]Value stored for masked keys.

Both lists must contain only strings; any other value throws an InvalidArgumentException when a log is recorded. See redacting sensitive data for how the rules are applied.

Retention

OptionDefaultDescription
retention.daysnullNumber of days to keep new logs, or null to keep them indefinitely.

When a log is written, its expires_at value is set to occurred_at plus the configured number of days. A null value leaves expires_at empty, and 0 makes logs expire as soon as they occur. Changing the option does not update rows that already exist. A negative value throws an InvalidArgumentException when a log is written.

The package model uses Laravel's MassPrunable trait. Schedule the model:prune command to delete expired rows:

php
use HosmelQ\AuditLog\Models\AuditLog;
use Illuminate\Support\Facades\Schedule;

Schedule::command('model:prune', [
    '--model' => [AuditLog::class],
])->daily();

The command deletes rows whose expires_at value is not null and is in the past. Rows without an expiration date are never pruned. If you register a custom model, you may pass that class instead.

Storage

OptionDefaultDescription
storage.connectionnullDatabase connection for audit logs. null uses the default connection.
storage.tableaudit_logsTable that stores audit logs.
storage.insert_chunk_size500Maximum number of rows per insert statement.

The migrations, the model, and the writer all read the connection and table from this group, so set them before running the migrations.

Each record() call writes its logs inside one database transaction. Larger batches are split into insert statements of insert_chunk_size rows, and every chunk is rolled back if one fails. The chunk size must be at least 1; a smaller value throws an InvalidArgumentException when a log is written.

Environment variables

OptionEnvironment variable
defaults.bucketAUDIT_LOG_DEFAULTS_BUCKET
defaults.sourceAUDIT_LOG_DEFAULTS_SOURCE
request.capture_in_consoleAUDIT_LOG_REQUEST_CAPTURE_IN_CONSOLE
request.capture_remote_ipAUDIT_LOG_REQUEST_CAPTURE_REMOTE_IP
request.capture_user_agentAUDIT_LOG_REQUEST_CAPTURE_USER_AGENT
retention.daysAUDIT_LOG_RETENTION_DAYS
storage.connectionAUDIT_LOG_STORAGE_CONNECTION
storage.insert_chunk_sizeAUDIT_LOG_STORAGE_INSERT_CHUNK_SIZE
storage.tableAUDIT_LOG_STORAGE_TABLE

The redaction options have no environment variables. Edit the lists in config/audit-log.php.

InstallationRecording Audit Logs