Get a free website with any plan

See how
CPANEL

Reading your traffic in Awstats

Last updated

IN SHORT

Awstats is cPanel's built-in traffic tool on Flashcloud, turning raw server access logs into visual reports. It tracks all server requests without tracking code or JavaScript on your site. This lets you inspect total server load, automated bot traffic, and error codes directly from your cPanel Metrics menu.

Awstats is cPanel's built-in traffic report, generated straight from your server's raw access logs. Open cPanel for your domain, then look under Metrics for the Awstats tile. Click it and pick the domain you want stats for. It turns those logs into graphical reports: visits by hour and day, top pages, countries, browsers, operating systems, referring sites, and search keywords (where still available). It needs no tracking snippet on your pages, since it reads the server's access logs.

If you just want a quick traffic overview without digging into cPanel, the portal's Viewing your website statistics page covers the basics: visitor traffic, top pages, bandwidth, and storage, all in one place. This article is for when you want more: hourly breakdowns, country-level detail, and the ability to see exactly what a bot or scraper was requesting.

What Awstats shows you

The main report page is a single scrollable dashboard with several sections:

  • Monthly history - a table of visits, pages, hits, and bandwidth for every month Awstats has data for. This is the fastest way to spot a traffic spike or a sudden drop.
  • Days of month / days of week - bar charts showing which days get the most traffic. Useful for spotting whether your audience is weekday business traffic or weekend browsing.
  • Hours - a 24-hour breakdown. If you're chasing a performance problem, cross-reference this against when the site felt slow.
  • Countries - visits grouped by country of origin, based on IP geolocation. Handy for confirming whether a spike is real customers or a scripted hit from a single region.
  • Robots/spiders visitors - a separate table just for known bots and crawlers (Googlebot, Bingbot, and others Awstats recognizes). Keeping this separate from human traffic is one of the more useful things Awstats does that JavaScript analytics can't.
  • Visitors - a list of individual visitor IPs with their number of visits, pages, and last visit date.
  • Referrers - which sites sent traffic your way, plus search engine keywords when they're still passed along (most modern search traffic arrives without a keyword, which is a search engine limitation, not an Awstats one).
  • Browsers and operating systems - a breakdown by browser (Chrome, Safari, Firefox, and so on) and OS. Useful for deciding whether a compatibility bug is worth fixing.
  • HTTP status codes - counts of 200s, 404s, 500s, and other response codes, often the fastest way to notice something is broken before a customer emails you about it.

Why the numbers differ from Google Analytics

Awstats counts every request that hits your server: humans, bots, monitoring services, RSS readers, and scrapers. It doesn't need JavaScript enabled to count a visit, and it doesn't try to filter out non-human traffic in most of its default tables (aside from the dedicated robots section). That makes its totals almost always higher than what you'll see in Google Analytics or Plausible, which only count visitors running JavaScript and actively filter bots.

Neither number is "wrong." They're answering different questions. Awstats tells you what your server actually handled, which matters for bandwidth, load, and catching automated abuse. JavaScript analytics tell you what real visitors did on the page, which matters for marketing and conversion tracking. If you're trying to reconcile a discrepancy between the two, start by checking the robots/spiders table in Awstats. A large chunk of "extra" traffic there usually explains most of the gap.

Finding a specific spike or problem

To track down what caused a spike in traffic or bandwidth:

  1. Open the monthly history table and identify which month or day jumped.
  2. Switch to that month's report and check the days of month chart to narrow it to a specific day.
  3. Check hours for that day to narrow further, if the spike was concentrated.
  4. Cross-reference visitors and robots/spiders - a spike from a handful of IPs hitting the same pages repeatedly usually means a bot, a scraper, or in rarer cases, an attack.
  5. Check HTTP status codes for a jump in 4xx or 5xx responses, which points to broken links, a misconfigured redirect, or a plugin throwing errors under load. If your account was suspended and you're trying to figure out why, see Why was my account suspended.

If you need the raw request lines rather than aggregated reports, cPanel's Raw Access tool sits right next to Awstats under Metrics and gives you the actual log files - the right tool when you're piping data into your own analysis script or need to see exact request headers and query strings.

When Awstats reports look empty or stale

Awstats processes log files periodically rather than in real time, so a brand-new domain or one that just started receiving traffic may show nothing for the first day. If reports stay empty well beyond that, or a report for the current month never populates, open a ticket from the portal's Support section.

Common questions

Why does Awstats show higher traffic than Google Analytics?

Awstats counts every server request, including bots, scrapers, and visits without JavaScript. Services like Google Analytics only record visitors who run JavaScript and actively filter automated crawlers. Check the robots/spiders section in Awstats to see how much bot activity accounts for the difference.

Why is my Awstats page empty?

Awstats processes server logs on a periodic schedule instead of in real time. A new domain or a site that just started receiving traffic can take up to a full day to show data. If reports stay empty beyond that, open a ticket from the portal Support section.

How do I tell if a traffic spike is a bot or an attack?

A spike from a handful of IPs hitting the same pages repeatedly usually indicates a bot, scraper, or attack. Cross-reference the visitors and robots/spiders sections to locate those addresses. You can also check the countries report to see if the traffic originates from a single region.

Do I need to install a tracking script to use Awstats?

No, tracking scripts are not required. Awstats generates reports directly from your server access logs. It functions without adding any code to your website.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.