Get a free website with any plan

See how
CPANEL

Reading raw access logs

Last updated

IN SHORT

Flashcloud raw access logs record every HTTP request to your site in Apache's Combined Log Format. Download the gzipped log in cPanel under Metrics, then Raw Access. Each line captures the visitor IP, timestamp, requested path, HTTP status, and user agent, giving you the exact data required to diagnose traffic spikes, errors, or abuse.

Your raw access logs are in cPanel under Metrics → Raw Access. Download the gzipped log for your domain, unzip it, and open it in a text editor or grep it from the command line. Each line is one HTTP request in Apache's Combined Log Format: who made the request, what they asked for, what came back, and what browser or bot they claimed to be.

If you're chasing a specific problem, don't scroll the whole file by eye. Use grep or zgrep to filter for the status code, IP, or path you care about. That turns a few thousand lines of noise into the ten that matter.

What each field means

A typical line looks like this:

203.0.113.42 - - [28/Sep/2026:14:22:01 +0000] "GET /wp-login.php HTTP/1.1" 200 4102 "-" "Mozilla/5.0"
  • 203.0.113.42, the visitor's IP address.
  • [28/Sep/2026:14:22:01 +0000], the timestamp with timezone offset.
  • "GET /wp-login.php HTTP/1.1", the request line: method, path, protocol.
  • 200, the HTTP status code returned.
  • 4102, the response size in bytes.
  • "-", the referrer (a dash means none was sent).
  • "Mozilla/5.0...", the user agent string, which bots and scrapers can freely fake.

Filtering for what actually matters

A few greps cover most real investigations:

zgrep " 404 " domain.com-Sep-2026.gz | awk '{print $7}' | sort | uniq -c | sort -rn | head -20

This lists the most-requested missing URLs, useful after a redesign or migration to catch broken links before they cost you traffic.

zgrep " 500 " domain.com-Sep-2026.gz

Server errors. Cross-reference the timestamps against cPanel's Errors tool (Metrics → Errors) if you're debugging a crash, since the access log tells you a request failed but not why.

awk '{print $1}' domain.com-Sep-2026.gz | sort | uniq -c | sort -rn | head -20

Top requesting IPs. A single address generating thousands of hits in a short window is either a misbehaving bot, a scraper, or the early signs of a brute-force attempt against a login page.

Spotting abuse and bot traffic

Look for repeated POST requests to /wp-login.php or /xmlrpc.php from the same IP in a tight time window; that's a credential-stuffing attempt, not a real visitor. If one IP is the source, you can block it from cPanel's Security → IP Blocker. Repeated hits from many different IPs hitting the same login endpoint is a distributed attack and blocking one address won't help; that's when a firewall rule or rate limiting at the web server level does more good than IP-by-IP blocking.

Also check the user agent field for known bot strings (bot, crawl, spider) versus requests with no user agent at all or an obviously fake one, since real browsers always send a full user agent string. High-volume traffic with a blank or malformed user agent is worth a closer look.

Raw logs vs. the summary tools

Awstats, also available in cPanel under Metrics, gives you graphs and aggregate numbers: top pages, total bandwidth, visitor trends over time. It's the right tool for "how is my traffic trending." Raw access logs are the right tool when you need the exact request, the exact IP, or the exact second something happened, the kind of detail a summary report throws away. Use Awstats to notice something's off, then drop into the raw log to find out what.

When to open a ticket

If you're seeing a sustained flood of requests that looks like a real denial-of-service attempt, or you've found active exploitation (successful logins from unfamiliar IPs, unexpected file uploads showing up as 200s), open a ticket from the portal.

Common questions

Where do I download my raw access logs?

Find them in cPanel under Metrics, then Raw Access. Download the gzipped archive for your domain, then unpack it to review the requests in a text editor or from the command line.

How do I know if someone is trying to hack my login page?

Look for repeated POST requests to /wp-login.php or /xmlrpc.php from the same IP in a tight window. If one IP causes the spike, block it inside cPanel under Security, then IP Blocker.

Why use raw logs if I already have Awstats?

Raw logs show the exact IP, request, and second an event happened, which Awstats discards in favor of aggregate graphs. Use Awstats to spot broad traffic shifts, then use raw logs to inspect specific errors or scrapers.

Why does a 500 error in my access log not explain the crash?

Access logs record that a request failed, but not the cause. Match the timestamp from your access log with the entries in cPanel under Metrics, then Errors, to find the technical reason for the failure.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.