Log File Analyzer

Summarize an access or application log: traffic, status codes, top paths, slow requests and errors, without uploading it anywhere.

Input

Related tools

What it does

Reads a log file and reports what is actually in it: which format it is, how many lines parsed, the time span the log covers, the split of responses across 2xx, 3xx, 4xx and 5xx, the busiest paths, addresses and user agents, total bytes served, the slowest requests, and a sample of the error lines. It recognizes the Apache and nginx combined and common access log formats, JSON lines with the usual field names, and any plain log whose lines start with an ISO 8601 or syslog timestamp. Files up to 50 MB are read in one pass.

How to use it

Paste log lines into the input, or drop a .log or .txt file onto it. The format is detected from the first lines and named in the result along with how much of the sample it matched. Use the options to resize the top lists, keep query strings separate from their path, show addresses in full instead of masked, or narrow the report to just traffic, errors, or timing.

Why this one

Log analyzers on the web want the file on their server, which means handing over every address and request path your users generated. This one runs the parser in your browser, so your files and inputs never leave your device, and it needs no install, no config file, and no account. GoAccess and awk pipelines are still the right answer for a log you own on a machine you control; this is for the log someone just sent you.

FAQ
Which log formats does it understand?
The Apache and nginx combined and common access log formats (including a trailing $request_time or rt= field), JSON lines with one object per line, and generic lines that begin with an ISO 8601 or syslog timestamp. For JSON it looks up fields by the usual names, so timestamp, time or @timestamp for the time, status or status_code for the response, path, url or request for the target, and duration_ms, latency or request_time for the time taken.
Why are the IP addresses shown with an x at the end?
The last octet of an IPv4 address (or the last group of an IPv6 address) is masked by default, because that is the part that identifies a specific machine while the rest is what makes a top list useful. Turn off the masking option to see them in full. Either way the log stays in your browser.
What happens to lines it cannot parse?
They are counted in the skipped total rather than dropped silently, and they are still scanned for the words ERROR, FATAL, CRITICAL, PANIC and EXCEPTION, so a stack trace sitting in the middle of an access log still shows up in the error samples.

Keyboard shortcuts: press ? anywhere on this page to see them.