Skip to main content
vekbox

Caddy Access Log Analyzer

Open one supported static Caddy access-log file in your browser and review JSON access-log requests, HTTP status codes, client sources, response bytes, and request timing when a supported duration field is present. The file is not uploaded to our servers; parsed records may be stored in this browser's IndexedDB.

CADDY · access log Read locally in this browser

Open an access log

Drop or choose a static Caddy access log. Supported JSON and text entries are parsed locally.

Open an access log

Drop or choose a static Caddy access log. Supported JSON and text entries are parsed locally.

.log.txt.jsonRead locally in this browser

Nginx, Apache, Caddy, or HAProxy access log

Caddy Access Log Analyzer

Caddy Access Log Analyzer is for examining a saved access-log snapshot after an incident, deployment, or traffic change. It is not live monitoring: HTTP errors mean parsed records with status 400 or higher, and risk indicators are heuristic review prompts rather than attack findings.

What the Caddy analyzer reads

The parser reads supported fields from one static Caddy access log at a time and builds a local snapshot of JSON access-log requests, HTTP status codes, client sources, response bytes, and request timing when a supported duration field is present. It does not parse the server's error-log format or follow a live stream; selecting another file replaces the current local dataset.

How to interpret the results

Use the timeline, filters, summaries, and matching raw lines to verify what the file contains. Signals based on sensitive paths, user-agent signatures, HTTP-error ratios, or request volume only flag records for review; they do not establish that a request or client is malicious.

What You Can Do

  • —Read one supported static Caddy access log inside the current browser; the selected file is not uploaded to our servers.
  • —Filter parsed records by status class, request method, time range, and text, then inspect the matching raw lines.
  • —Compare request counts, client IPs, status codes, paths, and response bytes; timing appears only when the log provides a compatible duration field.
  • —Follow heuristic review signals back to matching raw records before drawing a security conclusion.

FAQ

Does Caddy Access Log Analyzer upload my log?

No. The selected file is read in your browser and is not uploaded to our servers. Parsed records may remain in this browser's IndexedDB until you clear or replace the dataset, or remove the site's stored data.

What files can Caddy Access Log Analyzer read?

It accepts one supported static Caddy access-log file at a time. It does not parse Caddy server error logs, monitor a live stream, or keep a multi-file archive.

What counts as an HTTP error?

Any parsed access record with an HTTP status of 400 or higher appears as an HTTP error, including 4xx and 5xx responses. That label does not by itself imply an attack.

Does Caddy Access Log Analyzer identify attacks?

No. It highlights explainable heuristics such as sensitive-path matches, selected suspicious user-agent signatures, high HTTP-error ratios, or high request volume. Review the matching raw records and surrounding context before deciding what happened.

Which metrics are available?

Metrics depend on fields successfully parsed from the selected format. Request counts, unique client IPs, status codes, paths, and response bytes may be available; referrer, user-agent, and timing views require corresponding fields, and timing requires a compatible duration value.

vekbox

Local analysis • Clear evidence • Focused review

The selected log file is read in your browser. Parsed records may be kept in local IndexedDB until you clear or replace the dataset; log content is not uploaded to our servers.

Built by vekbox team • 2026