How to Download and Read Your Raw Access Logs

Every request to your website -- every page, image, bot and hacking attempt -- is written as one line in the web server's access log. Statistics tools like AWStats summarize those lines; the raw log shows you each one. This guide shows how to download and read your raw access logs from cPanel, explains the log format field by field, and shows how to spot bots and attacks in them.

When raw logs are the right tool

  • You want to know exactly who requested a page, when, and what the server answered.
  • Your bandwidth or resource usage jumped and you want to find the IP address or bot responsible.
  • You suspect someone is attacking your login page or probing for weaknesses.
  • A developer or SEO consultant asked you for your server logs.

For monthly totals, AWStats is easier -- see How to View Website Statistics with AWStats and Bandwidth. For the last few hours in a searchable table, Metrics > Visitors is quicker. And for error messages (500 errors, PHP fatal errors) you want the error log instead: How to Check Your Website Error Log and Recent Visitors.

How to download your raw access logs

  1. Log in to cPanel (from the client area: Services > My Services, choose your plan, then Log in to cPanel).
  2. Go to Metrics > Raw Access.
  3. Under Download Current Raw Access Logs, you'll see a table with your domain, the Last Update time and the file size.
  4. Click your domain name to download the log. It saves as a compressed .gz file.

The "current" log holds the requests since the server last processed your statistics, which normally happens about once a day. After processing, the current log starts fresh -- so to keep a longer history you need archiving, below.

Keep a history: turn on log archiving

At the top of the Raw Access page, under Configure Logs:

  1. Tick Archive log files in your home directory after the system processes statistics.
  2. Decide how long to keep them. Tick Remove the previous month's archived logs from your home directory at the end of the month to stop the archive growing forever, or, if your cPanel shows it, use the custom retention option to keep a set number of days. Leave both off only if you really need long history and are happy to manage the space yourself.
  3. Click Save.

Archived logs go into the logs folder in your home directory (/home/username/logs), one compressed file per domain per month, with names along the lines of example.com-ssl_log-Sep-2026.gz. Download them with Files > File Manager: open logs, select the file and click Download.

Archived logs count toward your disk space. A busy site's logs can grow to hundreds of megabytes over a few months, so keep an eye on the folder.

How to open a .gz log file

  • Windows: right-click the file and use 7-Zip (free) to extract it, then open the extracted file in Notepad++ or another text editor. Plain Notepad struggles with big files.
  • Mac: double-click the file to decompress it, then open it in TextEdit or BBEdit.
  • SSH / Terminal: you don't need to decompress it at all. zcat and zgrep read compressed files directly (examples below).

Reading a log line, field by field

Each line follows the standard "combined" log format that almost every web server uses. Here's a typical line:

203.0.113.45 - - [28/Sep/2026:14:02:11 -0400] "GET /contact/ HTTP/2" 200 5123 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0 Safari/537.36"
PartExampleWhat it means
Client IP address203.0.113.45Who made the request. If your site sits behind a CDN such as Cloudflare, this may be the CDN's address rather than the real visitor's.
Identity-Unused on the web today. Always a dash.
User-The username, only when the page is protected with Directory Privacy (a password-protected folder). Otherwise a dash.
Date and time[28/Sep/2026:14:02:11 -0400]When the request arrived. The last part is the offset from UTC -- here, four hours behind.
Request"GET /contact/ HTTP/2"The method (GET to fetch a page, POST to send a form), the address requested, and the protocol version.
Status code200The server's answer. 200 is success; see the table below.
Size5123Bytes sent back (a dash means nothing was sent). Useful for spotting big downloads.
Referrer"https://www.google.com/"The page the visitor came from, when their browser shares it. A dash means none -- someone typed the address, used a bookmark, or a bot.
User agent"Mozilla/5.0 ... Chrome/129.0 ..."The browser or bot's description of itself. Real browsers mention the browser and operating system; bots often name themselves, like Googlebot or bingbot.

Status codes you'll see most

CodeMeaning
200OK -- the file or page was sent.
301 / 302Redirected somewhere else (permanent / temporary).
304Not modified -- the browser already had a current copy, so nothing was re-sent.
403Forbidden -- blocked by a rule, permissions or security software.
404Not found -- the address doesn't exist.
429Too many requests -- the visitor was rate-limited.
500 / 503 / 508Server-side errors -- check the error log and Resource Usage.

Spotting bots and attacks

Most sites get more requests from bots than from people. Most bots are harmless or useful (search engines); some are scrapers; some are looking for a way in. Patterns to look for:

Pattern in the logWhat it usually isWhat to do
Many POST /wp-login.php or POST /xmlrpc.php from one IP or a handful of IPsPassword-guessing (brute force) against WordPressUse strong passwords and 2FA for WordPress admins; WP Toolkit hardening helps. Server-level security already blocks many of these.
Requests for /.env, /.git/config, /phpmyadmin/, /wp-config.php.bak, /backup.zip, all returning 404 or 403Automated scanners probing for common mistakesNormal background noise if they fail. Make sure none of those return 200.
Requests with ../, union select, <script> or base64 in the addressAttack attempts (path traversal, SQL injection, cross-site scripting)Keep all software updated. A 200 on one of these is worth a ticket.
One IP requesting hundreds of pages a minuteA scraper or aggressive crawlerBlock its user agent or IP in .htaccess if it's causing resource problems.
A user agent claiming to be Googlebot from an IP that doesn't belong to GoogleA fake bot pretending to be a search engineDon't trust the name alone -- anyone can write "Googlebot". Google publishes how to verify its crawlers.
Referrers from sites you've never heard of, often spammyReferrer spam -- the referrer field can be fakedIgnore it. Don't visit the links.

Seeing attack attempts in the log doesn't mean you've been hacked. What matters is the status code: attempts that got 403 or 404 failed. If you see something suspicious that returned 200, or your site behaves oddly, read What to Do If Your WordPress Site Is Hacked.

Useful commands for SSH users

If you use SSH or Advanced > Terminal, these one-liners summarize a log in seconds. Run ls ~/logs first to see your exact file names, and replace the name below with yours.

Top 10 IP addresses by number of requests:

zcat ~/logs/example.com-ssl_log-Sep-2026.gz | awk '{print $1}' | sort | uniq -c | sort -rn | head

Most requested addresses that returned 404:

zcat ~/logs/example.com-ssl_log-Sep-2026.gz | awk '$9 == 404 {print $7}' | sort | uniq -c | sort -rn | head -20

Every login attempt on WordPress:

zgrep "POST /wp-login.php" ~/logs/example.com-ssl_log-Sep-2026.gz | awk '{print $1}' | sort | uniq -c | sort -rn

Everything one visitor did:

zgrep "^203\.0\.113\.45 " ~/logs/example.com-ssl_log-Sep-2026.gz

In the awk commands, $1 is the IP address, $7 the address requested and $9 the status code -- the fields from the table above, counted by spaces.

Troubleshooting

The Raw Access page shows no log for my domain, or the file is tiny

The current log is emptied each time statistics are processed, so shortly after that it contains only a few requests. For a brand-new site, there may be nothing until the first visits arrive. Turn on archiving to build up history.

I need logs from last month but archiving was off

They can't be recreated from the current log. AWStats still has the monthly summary. Turn on archiving now so it doesn't happen again; if you need older raw logs for a specific incident, open a ticket and we'll tell you what's possible.

There are two logs for my domain

One is for secure (https) requests and one for plain http. Most traffic is in the https one (the file with ssl in its name).

Every visitor has the same few IP addresses

Your site is probably behind a CDN or proxy such as Cloudflare, so the log records the CDN's servers. Use the CDN's own analytics to see real visitor addresses.

Common questions

Are raw logs the same as my error log?

No. The access log records every request and its status code. The error log records what went wrong and why. Use them together: find the failing request in the access log, then look up the same time in the error log.

Can I import the logs into another analytics tool?

Yes. The combined log format is understood by most log analyzers and many SEO tools.

Do raw logs contain personal data?

They contain IP addresses and the pages people visited, which privacy laws may treat as personal data. Store downloaded logs securely and delete them when you no longer need them.

Related guides

Still stuck? Open a support ticket and the Instant Access Internet Services team will help.

Ultrafast LiteSpeed hosting from InstantAccess.net: free SSL, free backups, cPanel included, no contracts. Check out our $10/month hosting.
  • cpanel raw access logs, download access log cpanel, how to read apache access log, website access log format, find bots in access log, access log attack patterns, archive raw logs cpanel
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How to Change Your PHP Version in cPanel

Running a current PHP version keeps your website faster and more secure, and many WordPress...

How to Change PHP Settings (memory_limit, upload_max_filesize)

If WordPress says "The uploaded file exceeds the upload_max_filesize directive", a plugin runs...

How to Set Up a Cron Job in cPanel

A cron job runs a command or script on a schedule, such as every hour or once a night, without...

How to Check Your Website Error Log and Recent Visitors

When your website shows a blank page, a "500 Internal Server Error" or a feature just stops...

How to View Website Statistics with AWStats and Bandwidth

Your Instant Access Internet Services hosting account includes built-in website statistics, so...