No — and this is the core reason this tool exists. Parsing happens in JavaScript in your browser. Your visitors' IP addresses, user agents and behaviour never touch any server, making the analyzer safe for client and production logs.
Paste an access or auth log and get top IPs, status codes, top 404s, bot traffic, failed logins and suspicious probe detection — instantly. The log never leaves your browser, which makes this safe for logs you could never upload anywhere.
tail -n 20000 /var/log/nginx/access.log, an Apache log, auth.log — or just drop the file below.
The format is auto-detected (Apache/Nginx access, Nginx error, auth.log). Up to 50,000 lines per analysis.
Top IPs, status codes, 404s, bots, slow requests, hourly traffic and a threat panel for probes & brute force.
Copy an abuse report for the top offending IP, export the summary, or block the IP with your firewall. Zero uploads.
Drop a log file here — or , or paste log lines below.
Processed locally in your browser · max ~50,000 lines · nothing uploaded
What the analyzer recognises, and the shell one-liners to grab fresh data from your server.
| Source | Recognised format & how to fetch it |
|---|---|
| Apache / Nginx access log | Combined Log Format: IP - user [date] "METHOD path proto" status bytes "referer" "user-agent" — fetch with tail -n 20000 /var/log/nginx/access.log or tail -n 20000 /var/log/apache2/access.log. Missing referer/agent still parses; Nginx $request_time / Apache %T extra fields enable the slow-request table. |
| Nginx error log | 2026/10/09 10:14:22 [error] 1234#5678: *9 message, client: IP, server: …, request: "…" — the analyzer extracts client IPs and messages. Fetch: tail -n 20000 /var/log/nginx/error.log |
| sshd / auth.log | Lines containing Failed password, Invalid user, Accepted password / Accepted publickey — the tool builds failed-login counts per IP and per username. Fetch: grep sshd /var/log/auth.log | tail -n 20000 |
| Probe patterns | Flagged paths: /wp-login.php, /xmlrpc.php, /.env, /.git/config, /wp-config backup patterns, /phpmyadmin, /vendor/phpunit, /eval-stdin. Many hits from one IP = scanner, and the tool writes your abuse report. |
No — and this is the core reason this tool exists. Parsing happens in JavaScript in your browser. Your visitors' IP addresses, user agents and behaviour never touch any server, making the analyzer safe for client and production logs.
Apache and Nginx combined access format (with or without referer/user-agent), Nginx error logs, and sshd lines from auth.log (failed and accepted logins). The format is auto-detected per paste; mixed pastes are split by type.
About 50,000 lines per analysis — comfortable for typical tail output on a busy site. For huge logs, use tail or grep on the server first (one-liners in the guide table above), then paste the slice you care about.
Copy the abuse report for evidence, then block at the firewall: ufw insert 1 deny from 203.0.113.15 — or better, install fail2ban so repeat offenders are banned automatically. Never rely on .htaccess alone for a flood.
Typical sites see 25–50% bot traffic: search crawlers, SEO scrapers, uptime monitors and hostile scanners. The bot table separates good bots (Googlebot, Bingbot) from unknown agents so you can decide what to block in robots.txt and what to rate-limit.