Access Log समझना
In this page:
यह कहाँ रहता है
Ubuntu/Debian पर, default access log /var/log/apache2/access.log है; RHEL-family systems पर यह /var/log/httpd/access_log है। हर VirtualHost CustomLog directive के साथ अपना खुद का define कर सकता है (और आमतौर पर करना चाहिए), ताकि अलग-अलग sites का traffic एक ही file में न मिल जाए।
CustomLog Directive
CustomLog /var/log/apache2/example.com-access.log combined उस VirtualHost की हर request को दी गई file में लिखता है, named log format के हिसाब से formatted -- combined Apache का standard, information-rich built-in format है (Custom Log Formats lesson में पूरी तरह covered)।
एक Log Line पढ़ना
एक typical combined-format line ऐसी दिखती है: 203.0.113.5 - - [10/Mar/2024:14:22:01 +0000] "GET /index.html HTTP/1.1" 200 5423 "https://example.com/" "Mozilla/5.0 ..." -- order में, यह client IP, request का timestamp, request line खुद, HTTP status code, bytes में response size, referring page, और browser की user agent string है।
आम इस्तेमाल
Access log traffic analytics के पीछे का raw material है, "क्या कोई actually इस URL को hit कर रहा है" जैसे debugging questions, suspicious request patterns spot करना, और fail2ban जैसे tools जो इसे repeated failed attempts के लिए scan करते हैं और offending IP को firewall level पर temporarily block कर देते हैं।
tail -f /var/log/apache2/access.log नई requests को real time में आते ही दिखाता है -- यह देखने के लिए handy कि live site पर कुछ test करते समय exactly क्या हो रहा है।उदाहरण: Per-site access log in a VirtualHost
<VirtualHost *:80>
ServerName example.com
DocumentRoot /var/www/example.com/public
CustomLog /var/log/apache2/example.com-access.log combined
</VirtualHost>
# Example combined-format log line:
# 203.0.113.5 - - [10/Mar/2024:14:22:01 +0000] "GET /index.html HTTP/1.1" 200 5423 "https://example.com/" "Mozilla/5.0"
{# Flagged by hand after confirming a runner can't handle this example
(a shell command / go.mod file stored as a TopicExample, a language
feature the configured runner version doesn't support, or output
that blows a runner's sandbox limit) -- see TopicExample.norun.
Never render the run button for these, regardless of language,
since it would just fail at execute_code (or worse, hang the
Judge0 queue on a submission that can never finish cleanly). #}
- हर VirtualHost को same shared access log पर लिखने देना, यह बताना मुश्किल बनाते हुए कि कोई given request असल में किस site की है।
- यह मान लेना कि अकेला access log आपको errors के बारे में बताता है -- application के अंदर fail हुई एक request Apache को खुद कोई problem कभी न दिखने पर access log में
200 OKकी तरह दिख सकती है। - access log को rotate न करना (Log Rotation lesson में covered), किसी busy site पर इसे disk भरने तक अनिश्चित काल तक बढ़ने देना।
Chapter Quiz — Complete all 4 topics to unlock
0/4 topics done
Complete these topics first: