Guide · September 1, 2026 · 3 min read
Logs that earn their keep the day you need to understand
Nobody cares about logs until a message has vanished, a role was handed out and nobody knows by whom, or a channel disappeared overnight. At that point, either the trace exists, or there is nothing to say.
Contents
What Discord already keeps
The native audit log records administrative actions: channel creation and deletion, role changes, bans, server modifications. It is reliable and depends on no bot.
It has three limits, and they are exactly the ones that cause trouble in practice.
- It only keeps 45 days. A problem discovered two months later is no longer in it.
- It ignores message content. A deleted message appears nowhere: you know a deletion happened, never what it contained.
- It reads badly. No serious search, no export, no notification.
A bot does not replace that log: it complements it. Both are useful, and the native one stays the reference when the doubt is about the bot itself.
What to log
Logging everything produces an unreadable channel nobody opens. The selection below covers the real needs without drowning the information.
In order of usefulness
- Deleted and edited messages — by far the most consulted. With the previous content.
- Penalties — who penalised whom, why, when.
- Joins and leaves — with the account age: that is what makes a raid visible.
- Role changes — especially roles carrying permissions.
- Channels created, deleted, modified — the trace of a nuke starts there.
- Nickname changes — useful after the fact, when somebody changed name to muddy the trail.
- Voice movements — bulky; keep it for servers that have a use for it.
Splitting the channels
A single log channel becomes unusable at a few hundred members: message deletions drown the role changes, and nobody notices anything any more.
Three channels are enough. One for messages — the chattiest. One for moderation — penalties, warnings, decisions. One for the server — channels, roles, permissions, joins and leaves. The third is quiet in normal times; which is precisely why sudden activity shows up in it.
Filtering out what does not need seeing
Two filters remove half the noise. Channel exclusion — a commands channel, a meme channel, a games channel produce dozens of pointless deletions a day. And role exclusion — bots, whose automatically deleted messages fill the log for nothing.
A third filter is trickier: logging role changes for every role produces a constant stream on a server with role menus. Limiting it to roles carrying permissions keeps the useful information.
Who may read the logs
Logs contain deleted messages, some of which were deleted because they were personal. They are not meant for members, and rarely for the whole team.
A simple rule: message logs are for moderation, server logs for administration. And the team must know that opening those channels is not a neutral act — you do not go there out of curiosity about one particular member.
What to look at without waiting for an incident
Logs mostly serve after the fact, but two regular readings are worth the time they take.
Joins, once a week. A run of accounts created the same day joining minutes apart is a raid in preparation, or one that has just failed.
Permission role changes, every single time. This is the one event that should trigger a systematic check: almost every server takeover starts with a privilege escalation nobody noticed.
Frequently asked questions
How long should logs be kept?
The Discord channel keeps them indefinitely, which is more than necessary. Periodically clearing message logs older than a few months is good practice: they contain personal data you no longer have a use for.
Can the bot's private messages be logged?
No, and you should not try. What a member writes to the bot in private is none of the team's business.
Does the bot see messages deleted before it was set up?
No. A deleted message is only logged if the bot was present and active when it was sent. That is why logs must be configured before you need them.
Can a moderator delete a log entry?
They can delete the message in the channel, like any message. That is why log channels must be read-only, even for the team.
Read next : Warnings and penalties, Anti-nuke: protecting your server, Permission audit.
