Call Flow Studio keeps four logs on the PBX: every change made in it, every sign-in and account change, license status changes, and automatic updates. They stay on the PBX. Nothing in them is sent anywhere.
Where they are
All four live in /var/log/cfstudio/, on FreePBX and VitalPBX alike.
- The folder sits outside the Call Flow Studio program folder, so upgrades never touch it, and outside the web root, so it can’t be browsed.
- Only root and the PBX’s web server user can read it, because the lines contain usernames, IP addresses and change details. Use
sudo. - Uninstalling Call Flow Studio leaves the folder in place on purpose. It’s your record of who changed what and who signed in.
- If the folder is missing or can’t be written to, Call Flow Studio carries on without logging. A logging problem never blocks an edit.
Reading a line
Except for the update log, each line is one event, with fields separated by |:
2026-09-25 11:10:27 EDT | user=jsmith | ip=192.168.1.50 | node_action:save_route | OK | role=admin | request={...} | result={...}
That’s the time (in the PBX’s time zone), who, from which IP address, what happened, the result (OK, FAIL, or one of the words described below), then the details.
Each log rolls over at 10 MB and keeps nine older copies (audit.log.1 through audit.log.9; the oldest is dropped). This is built in, so there’s no logrotate setup to do.
audit.log: changes
One line for every change requested in Call Flow Studio: rewiring a destination, creating a record, editing IVR options, and so on. Changes to the global default settings and hiding or showing branches are recorded here too.
Each line says who asked, when, from where, what they asked for and what Call Flow Studio answered. When the change is one you can undo, the line also holds the before and after.
Edits that were refused are logged as DENIED with a code, as long as someone was signed in:
| Code | Meaning |
|---|---|
| 402 | The license on this PBX doesn’t allow editing, so it’s view-only |
| 403 | The user’s role or permissions don’t allow that change |
Anything that looks like a password, PIN, token or license key is written as ***.
auth.log: sign-ins and accounts
- Sign-ins that succeed, fail, or get the account locked (
LOCKED), and sign-outs. - Forgotten-password requests and the resets that follow, password resets from the command line, and the first admin account created at install.
- User administration: adding and deleting users, role changes, unlocking an account, resetting or changing a password.
- On VitalPBX, changes to which tenants a user can see, with the tenant names.
If someone keeps trying a locked account, only the first attempt gets its own line. The rest are counted and written as a single summary line after the lockout ends, so a password-guessing run can’t push your real history out of the log.
license.log: license status
Only changes are written, not every check, so this one stays short. The first line on a PBX records the status it started with (CURRENT). After that you’ll see lines for a trial starting, being extended or expiring, a purchase, a license being changed, expiring, revoked, found in use on another PBX, or released to move to other hardware, the offline grace period running out, a license being restored, or no license at all. On VitalPBX, a change in how many tenants the license covers is logged too.
Status is checked after each check-in with the licensing server, after a license key is installed, and once a night. The nightly check means an expiry gets recorded even on a PBX that can’t reach the internet.
autoupdate.log: automatic updates
If automatic updates are on, the nightly update check writes what it checked and what it did. These are plain lines rather than the | format above:
[2026-08-23 18:28:32] message
This log rolls over at 1 MB and keeps one older copy (autoupdate.log.1). If you’re upgrading from a version that kept it at /var/log/cfs-autoupdate.log, the upgrade moves it into this folder for you.
Handy commands
Watch changes as they happen:
sudo tail -f /var/log/cfstudio/audit.log
Everything one user did, across all the logs:
sudo grep 'user=jsmith' /var/log/cfstudio/*.log
Failed sign-ins:
sudo grep ' | FAIL' /var/log/cfstudio/auth.log
If an install check fails, the installer writes its own diagnostic to /tmp instead. See Installing CFS.