---
title: Next-Gen WAF configuration changes now recorded in the event log
summary: null
url: >-
  https://www.fastly.com/documentation/reference/changes/2026/09/add-ngwaf-event-log-types
---

The [Event logs API](https://www.fastly.com/documentation/reference/api/account/events/) now records Next-Gen WAF configuration changes no matter where they are made — through the [Next-Gen WAF API](https://www.fastly.com/documentation/reference/api/ngwaf/), the Fastly control panel, the Next-Gen WAF control panel, or Terraform. Previously, only changes made through Fastly were recorded, so a workspace edited from the Next-Gen WAF control panel left no entry in your event log.

All Next-Gen WAF event types are now documented and can be used with `filter[event_type]` on [list events](https://www.fastly.com/documentation/reference/api/account/events/#list-events). They cover workspaces, rules, lists, custom signals, redactions, virtual patches, thresholds, workspace alerts, header links, rate limited sources, custom dashboards, request reports, and agent keys. Some of these resources have no Next-Gen WAF API endpoint for changing them, but changes made to them elsewhere are recorded all the same.

The following event types are deprecated and are no longer recorded. Use the `ngwaf.*` equivalent instead — for example, `ngwaf.rule.create` in place of `security.rule.create`. Entries already in your event log keep their original event type.

- `security.workspace.create`, `security.workspace.update`, `security.workspace.delete`
- `security.redaction.create`, `security.redaction.update`, `security.redaction.delete`
- `security.rule.create`, `security.rule.update`, `security.rule.delete`
- `security.virtual_patch.create`, `security.virtual_patch.update`, `security.virtual_patch.delete`
- `security.event.update`
