Your raw access logs are in cPanel under Metrics → Raw Access. Download the gzipped log for your domain, unzip it, and open it in a text editor or grep it from the command line. Each line is one HTTP request in Apache's Combined Log Format: who made the request, what they asked for, what came back, and what browser or bot they claimed to be.
If you're chasing a specific problem, don't scroll the whole file by eye. Use grep or zgrep to filter for the status code, IP, or path you care about. That turns a few thousand lines of noise into the ten that matter.
What each field means
A typical line looks like this:
203.0.113.42 - - [28/Sep/2026:14:22:01 +0000] "GET /wp-login.php HTTP/1.1" 200 4102 "-" "Mozilla/5.0"
- 203.0.113.42, the visitor's IP address.
- [28/Sep/2026:14:22:01 +0000], the timestamp with timezone offset.
- "GET /wp-login.php HTTP/1.1", the request line: method, path, protocol.
- 200, the HTTP status code returned.
- 4102, the response size in bytes.
- "-", the referrer (a dash means none was sent).
- "Mozilla/5.0...", the user agent string, which bots and scrapers can freely fake.
Filtering for what actually matters
A few greps cover most real investigations:
zgrep " 404 " domain.com-Sep-2026.gz | awk '{print $7}' | sort | uniq -c | sort -rn | head -20
This lists the most-requested missing URLs, useful after a redesign or migration to catch broken links before they cost you traffic.
zgrep " 500 " domain.com-Sep-2026.gz
Server errors. Cross-reference the timestamps against cPanel's Errors tool (Metrics → Errors) if you're debugging a crash, since the access log tells you a request failed but not why.
awk '{print $1}' domain.com-Sep-2026.gz | sort | uniq -c | sort -rn | head -20
Top requesting IPs. A single address generating thousands of hits in a short window is either a misbehaving bot, a scraper, or the early signs of a brute-force attempt against a login page.
Spotting abuse and bot traffic
Look for repeated POST requests to /wp-login.php or /xmlrpc.php from the same IP in a tight time window; that's a credential-stuffing attempt, not a real visitor. If one IP is the source, you can block it from cPanel's Security → IP Blocker. Repeated hits from many different IPs hitting the same login endpoint is a distributed attack and blocking one address won't help; that's when a firewall rule or rate limiting at the web server level does more good than IP-by-IP blocking.
Also check the user agent field for known bot strings (bot, crawl, spider) versus requests with no user agent at all or an obviously fake one, since real browsers always send a full user agent string. High-volume traffic with a blank or malformed user agent is worth a closer look.
Raw logs vs. the summary tools
Awstats, also available in cPanel under Metrics, gives you graphs and aggregate numbers: top pages, total bandwidth, visitor trends over time. It's the right tool for "how is my traffic trending." Raw access logs are the right tool when you need the exact request, the exact IP, or the exact second something happened, the kind of detail a summary report throws away. Use Awstats to notice something's off, then drop into the raw log to find out what.
When to open a ticket
If you're seeing a sustained flood of requests that looks like a real denial-of-service attempt, or you've found active exploitation (successful logins from unfamiliar IPs, unexpected file uploads showing up as 200s), open a ticket from the portal.