Church Cashbook Maintenance Manual
Review raw audit logs for anomalies.
Two logging layers
Church Cashbook maintains two distinct logging systems. This page covers the file-based audit logs — JSONL files written to church_records/logs/errors/. The database-based activity log is covered in the next section.
What the audit logs capture
The audit log records server-side errors, warnings, and security events. Each entry is a JSON line containing a timestamp, event type, message, file location, request URI, and the user ID if a session was active. Entries include:
- PHP errors and exceptions that reached the error handler
- Failed authentication attempts beyond the rate-limit threshold
- Security violations (CSRF failures, access control rejections)
- Application-level warnings (e.g. Gift Aid encryption issues, file write failures)
Reviewing the logs
The quickest way to review recent entries is via Admin → System Info → Recent error entries (View last 20 button). This shows the 20 most recent entries from the current error log file in a formatted table.
For deeper investigation, log files are accessible via cPanel file manager or SFTP at church_records/logs/errors/. Files are named errors-YYYY-MM-DD.jsonl. Each line is a JSON object that can be parsed with any standard tool.
What to look for monthly
- Any
E_ERRORor unhandled exception entries — these indicate code-level problems requiring investigation - Repeated failed login attempts against the same user account — may indicate a targeted attack
- CSRF failures — occasional failures are normal (browser back button), but a spike warrants investigation
- Access control rejections from unexpected IP addresses or user agents
- Any Gift Aid encryption errors — these require immediate attention as they may indicate data integrity issues