---
name: audit-logger
description: "Structured JSONL audit logging for all OpenClaw events"
metadata: { "openclaw": { "emoji": "📋", "events": ["message:received", "message:sent", "command:new", "command:reset", "command:stop", "gateway:startup", "agent:bootstrap"] } }
---
# Audit Logger

Provides structured JSONL audit logging for all significant OpenClaw events. Logs are written to `~/.openclaw/security/audit.jsonl` with automatic 10MB rotation.

## Logged Events

| Event | Details Captured |
|-------|-----------------|
| `message:received` | Session, channel, group status, message length |
| `message:sent` | Session, channel, group status, message length |
| `command:new` | Session key |
| `command:reset` | Session key |
| `command:stop` | Session key, success status |
| `gateway:startup` | Session key, timestamp |
| `agent:bootstrap` | Session key, timestamp |

## Log Format

Each entry is a JSONL line:

```json
{
  "timestamp": "2026-03-27T10:00:00.000Z",
  "event": "message:received",
  "sessionKey": "session-abc123",
  "channel": "C012AB3CD",
  "isGroup": false,
  "alerts": [],
  "metadata": { "messageLength": 42 }
}
```

## Storage

- **Location**: `~/.openclaw/security/audit.jsonl` (configurable via `OPENCLAW_SECURITY_LOG_DIR`)
- **Rotation**: When file exceeds 10MB, renamed to `audit.jsonl.1`
- **Format**: One JSON object per line (JSONL / NDJSON)
