Skip to content
Docs menu: Logs

Moderation

Logs

About this feature: Logs

In short

Bastion posts in a private channel every time it acts, saying who, what and why. /setup makes one called bastion-logs for you, or you can pick your own in the dashboard. Pick an alert role and your staff are pinged in an emergency. The security and moderator logs are free. Message logs and the server changes log need Pro.

Why you want this

Without a log channel, Bastion still protects your server. You just won't see it happen. A member gets timed out and nobody knows why. An admin gets quarantined and you find out from an angry message.

With a log channel, every action comes with its reason. It's also worth 5 points on your security score.

Turn it on

  1. Run /setup in Discord

    Bastion makes a private channel called bastion-logs and starts posting there. That's all most servers need.

  2. Pick who gets pinged

    Open Logs in the dashboard. Under Getting your attention, choose your staff role. Without this, alerts are posted but nobody gets a notification.

  3. Press Save

    Only the server owner and trusted people can change the Logs page.

The four log channels

SettingWhat it doesDefault
Security alertsWhat Bastion does on its own: anti-nuke, automod, join gate, raids, lockdowns and restores.bastion-logs, once you run /setup
Moderator actionsCases your staff make with commands: warnings, timeouts, kicks, bans, purges and quarantines. Left empty, they go to the security channel.Not set
Edited and deleted messagesMessages your members delete or edit. Pro. Left empty, message logs are off.Not set
Server changesWho changed what: channels, roles, members, invites and server settings, one plain sentence each. Pro. Left empty, the server changes log is off.Not set

You can use the same channel for all of them. Busy servers usually prefer to keep them apart, because message logs are noisy.

Security alerts and Moderator actions are free. The other two are part of Pro. On the free plan they're locked, and pressing one opens a prompt that explains Pro.

Only the server owner and trusted people can change the Logs page. Other admins can read it. See the dashboard.

Alert roles: who gets pinged

Bastion's alerts don't ping anyone unless you choose a role. An attack at four in the morning is posted quietly in a channel nobody is looking at.

On the Logs page, under Getting your attention, pick up to 5 roles under Roles to ping in an emergency. Bastion pings them for the serious things only:

Everyday posts ping nobody: a spammer timed out, an account turned away at the gate, a raid ending. Alert roles are free.

  • The role is pinged in whichever channel the alert is posted in.
  • @everyone can't be an alert role.
  • A role that has been deleted is skipped.
  • Removing every alert role raises a Protection was weakened alert, because it leaves nobody to notify.

TipMake a small role such as Security and give it to the two or three people who should be woken up. Pinging your whole staff team for every raid gets old fast.

A channel for each kind of alert

By default every security alert goes to the Security alerts channel. Busy servers can split them up. Open Advanced settings on the Logs page and find A channel for each kind of alert. This is free.

SettingWhat goes thereDefault
Anti-Nuke alertsAnti-Nuke stopping someone or asking for your help, and panic mode starting and ending.Not set
Automod alertsAutomod timeouts, kicks and bans, webhooks it removed, raid panic and ping flood lockdowns.Not set
Join Gate and Anti-Raid alertsAccounts and bots the Join Gate caught, name changes it caught, and raids starting and ending.Not set
Verification alertsPeople removed for failing or not finishing verification, and Verification is misconfigured.Not set

Leave one empty and that kind of alert goes to Security alerts. If Bastion can't post in the channel you picked, it falls back to Security alerts too, so an alert is never lost to a deleted channel.

Everything without a channel of its own stays in Security alerts: lockdowns your staff start, restored backups and Protection was weakened.

Set it up by hand

/setup does all of this for you. The channel it makes is hidden from everyone except Bastion and administrators, so add your moderator role in the channel's permissions if they should see it. If a bastion-logs channel that everyone can see already exists, /setup makes a new private one and leaves the old one for you to delete. Follow the steps below only if you want a different channel.

  1. Make a private channel

    Create a text channel such as #bastion-logs. Hide it from @everyone and allow your staff roles to view it.

  2. Let Bastion in

    Give the Bastion role View Channel, Send Messages and Embed Links in that channel.

  3. Choose it in the dashboard

    Open the Logs page, pick the channel under Security alerts, and save.

  4. Repeat for moderator actions

    Pick a second channel under Moderator actions, or leave it empty to use the same one.

CarefulKeep log channels private. They show who was punished and why, and that isn't something every member should read.

What a log entry tells you

  • Who it was about, and who or what did it.
  • What happened: timed out, quarantined, kicked and so on.
  • Why. For Automod this is the list of heat reasons, such as pinging people or repeating the same message. For Anti-Nuke it's the limit that was broken.
  • The case number, on moderator actions, so you can look it up with /case view.

What appears in the security log

  • Anti-nuke stopping someone, or asking for your help when it couldn't.
  • Automod timeouts, spamming webhooks it removed, and raid panic starting.
  • Accounts the Join Gate turned away or flagged.
  • A raid starting and ending.
  • Members kicked for not passing verification in time.
  • Lockdowns starting and ending, single channel locks and join locks.
  • A quarantined member rejoining and being quarantined again.
  • Backups being restored.
  • Protection being weakened from the dashboard. See below.
  • Verification being misconfigured, when the member role has become too powerful to hand out.
  • A moderator reaching a ban or kick limit with Bastion's commands.

Verification passes and ordinary failures, quarantines and new backups aren't posted in the channel. They're recorded on the Activity page of the dashboard, along with everything above. Security events there are kept for 90 days.

Protection was weakened

If someone makes the server less protected from the dashboard, Bastion posts an alert titled Protection was weakened. It names who saved the change and lists what changed. It also sends the server owner a private message, at most one every 5 minutes for a server.

  • Anti-Nuke, the Join Gate, Anti-Raid or Automod was switched off.
  • Block dangerous permissions was switched off.
  • The Join Gate stopped checking who adds bots.
  • The Security alerts channel was removed. The alert is posted in that channel one last time.
  • Someone was added to the trusted list.
  • Block dangerous channel permissions was switched off.
  • Keep quarantined people quarantined was switched off.
  • Every alert role was removed.
  • A staff tier was added, given another command or given to more roles.

If you didn't expect it, open the dashboard, switch it back and check who has the Manage Server permission.

Edited and deleted messages (Pro)

Pick a channel under Edited and deleted messages on the Logs page and Bastion posts there when a member deletes or edits a message. This is part of Pro.

EntryWhat it shows
Message deletedWho wrote it, which channel, the text (up to 1000 characters) and how many attachments it had.
Message editedWho wrote it, which channel, the text before and after (up to 500 characters each) and a link to jump to the message.
Messages deleted in bulkHow many messages were deleted at once and in which channel. The text isn't shown. A /purge usually appears this way.

Long messages are cut short, to 20 lines at most. Mentions in the quoted text don't ping anyone.

What's left out

  • Messages from bots and webhooks.
  • Messages Automod deleted itself. Those are already reported in the security log.
  • Anything that happens inside the message log channel.
  • Edits where the words didn't change, such as a link preview loading or a message being pinned.

Messages sent before Bastion was watching

Bastion can only show text it saw while it was running. If a message was sent before Bastion started, or long enough ago that Bastion no longer remembers it, the entry says the text is not available. For a deleted message like that, the author shows as Not known. For an edit, the Before side is missing, and Bastion only logs it if the edit happened in the last few seconds.

During a flood

Bastion posts at most 20 message log entries every 10 seconds for a server. Anything over that is counted, not posted. When things calm down you get one entry called Message log paused that says how many weren't shown.

Where the text goes

The message text appears in the log post in your Discord channel and nowhere else. Bastion never saves it to its database. If you delete the log post, the text is gone. See privacy and data.

CarefulA message log channel shows things members chose to delete. Keep it private, and only let in staff who need it.

Server changes (Pro)

The server changes log is a running record of who changed what in your server. Discord keeps an audit log of its own, but it's slow to read and it expires. Bastion turns each entry into one plain sentence and posts it in a channel you choose. This is part of Pro.

  1. Check the server is on Pro

    On the free plan the Server changes setting is locked. See Pro.

  2. Make a private channel

    Something like #server-changes. Give the Bastion role View Channel, Send Messages and Embed Links there.

  3. Choose it in the dashboard

    Open the Logs page, pick the channel under Server changes, and save.

  4. Pick what to record, if you want

    Open Advanced settings and find Which server changes to record. Most are already on.

Bastion builds this log from Discord's audit log, so it needs the View Audit Log permission. Run /status to check.

What it records

These switches are under Advanced settings, in the group Which server changes to record. They only matter once a Server changes channel is set.

SettingWhat it doesDefault
Channels created, edited or deletedChannels being created, changed or deleted, and permissions being set, changed or removed for a role or member in a channel.On
Roles created, edited or deletedRoles being created, changed or deleted.On
Kicks, bans, timeouts, role and nickname changesKicks, bans, unbans and prunes. Timeouts given and removed. Nickname changes. Roles given to or taken from a member. Bots being added, with who added them.On
Server settingsChanges to the server itself, such as its name, icon or verification level.On
Invites created or deletedNew invites, with the channel, when they expire and how many uses they allow. Only the first 3 characters of the code are shown. Deleted invites, without the code.On
WebhooksWebhooks being created, changed or deleted.On
Emoji and stickersEmoji and stickers being added, changed or deleted.On
ThreadsThreads being created, changed or deleted. Busy servers create a lot of threads.Off
Members joining and leavingEach person who joins, with how old their account is, and each person who leaves. This is noisy on busy servers.Off

A channel for each kind of change

You can send one kind of change to its own channel. Open Advanced settings and find A channel for each kind of change. There's one setting for each row in the table above: Channel changes, Role changes, Member changes, Server settings, Invites, Webhooks, Emoji and stickers, Threads, and Joins and leaves.

  • Leave one empty and that kind goes to the Server changes channel.
  • Joins and leaves is the one most servers split off, because it's the noisiest.
  • The switch for that kind must still be on under Which server changes to record.
  • Like the rest of the server changes log, this is part of Pro.

What an entry looks like

  • A title naming the kind of change, such as Channel change or Member change.
  • One sentence saying who did what. For example: Alex (alex, 123456789012345678) deleted the channel general.
  • What changed, for edits. Up to five lines such as name: old -> new, then a count of any others.
  • The reason, if the person gave Discord one.

Names and values are cut short and can't ping anyone.

Changes are grouped

Bastion doesn't post each change the moment it happens. It collects changes for about 2 seconds and sends them together as one post, so an entry can appear a few seconds late. One post holds up to 15 changes, one after another.

If every change in a post is the same kind, the title names that kind. If they're mixed, the title is Server changes. When a post gets very long, each change is cut down to one short line.

What's left out on purpose

  • What Bastion did itself. That's already in your security log or moderator log, so it isn't repeated here. The exceptions are members Bastion bans or kicks during a raid or while joins are locked. Those are posted nowhere else one by one, so they do appear.
  • Deleted and edited messages. Those belong to the message log above.
  • The details of a permission change. The entry says permissions were changed and for whom, not which boxes were ticked. Open Discord's audit log if you need that.
  • Icons, banners and avatars. The entry says they changed, not what they changed to.
  • The full code of an invite. A new invite shows only the first 3 characters of its code. That's enough to tell two invites apart and not enough to use one. A deleted invite shows no code at all.

During a flood

Bastion sends at most 4 server changes posts every 10 seconds for a server, each with up to 15 changes. If the Server changes channel is also your Security alerts channel, it sends at most 2, to leave room for alerts.

Anything over that is counted, not posted. You then get one entry called Server changes log paused. It reads like this: 12 more changes were not shown. This stops a nuke turning your log channel into a second flood and holding up security alerts.

Where it's kept

Server change posts live in your Discord channel and nowhere else. Bastion doesn't save them to its database. If you delete a post, it's gone. See privacy and data.

Nothing is being posted.

Check a channel is chosen and saved, and that Bastion can view it, send messages and embed links there. Then check something has actually happened. A quiet log often just means a quiet server.

The log channel was deleted.

Bastion has nowhere to post. Run /setup to make a new one, or pick another channel on the Logs page.

Can members see the logs?

Only if they can see the channel. Hide it from @everyone.

Nobody was pinged when the server was attacked.

No alert role is set. Open the Logs page and choose one under Roles to ping in an emergency. Check the role still exists, too.

Can alerts ping @everyone?

No. Pick a staff role.

Automod alerts are drowning out everything else.

Give them their own channel. Open Advanced settings on the Logs page and pick one under Automod alerts.

How do I find out why someone was timed out?

Search the log channel for their name, or run /cases on them. See moderation.

A deleted message shows no text.

It was sent before Bastion started watching, so Bastion never saw the words. Discord doesn't let a bot read a message after it's deleted.

The message log says it was paused.

More than 20 changes happened in 10 seconds, usually a mass delete. The entry tells you how many weren't shown.

I picked a message log channel and nothing is posted.

Check the server is on Pro and that Bastion can view the channel, send messages and embed links there. Messages from bots are never logged.

The server changes log is empty.

Check the server is on Pro, that a channel is chosen under Server changes and saved, and that Bastion has View Audit Log. Things Bastion did itself aren't repeated there, and threads and joins are off until you switch them on under Advanced settings.

The server changes log says it was paused.

More changes happened in 10 seconds than fit in 4 posts of 15, or 2 posts if the channel is shared with Security alerts. The entry tells you how many weren't shown. Discord's own audit log still has them.

Several changes are in one post.

That's on purpose. Changes made within a couple of seconds of each other are sent together, up to 15 in a post.

A new invite shows only three characters.

On purpose. The log isn't a place to pick up working invites. Open Server Settings, Invites in Discord to see the full code.

Is the server changes log part of Pro?

Yes. Server changes and Edited and deleted messages both need Pro. Security alerts and Moderator actions are free.

The Server changes setting is locked.

The server is on the free plan. Press the setting and a prompt explains Pro and shows the buttons to buy it. If Pro ends, the server changes log stops by itself.

Can logs be switched off?

Clear the channel on the Logs page and save. Bastion keeps working but stops posting. Removing the Security alerts channel sends one last alert there and messages the owner, because it leaves alerts with nowhere to go.

Last updated