Shell & DBA Ops

Nginx Access Log Analysis Guide

Use access logs to inspect status codes, latency, upstream behavior and suspicious traffic. Last updated September 1, 2026.

Use access logs to inspect status codes, latency, upstream behavior and suspicious traffic. This page is written as a practical engineering reference: it starts with evidence, keeps risky assumptions visible and links the next useful Formalint checks.

Use it when a ticket, incident or pull request needs a repeatable explanation rather than a quick guess. Keep secrets, customer data and production tokens out of browser tools and shared notes.

When this page is useful

Practical workflow

StepWhat to verify
Identify the host boundaryRecord whether the command runs on local Windows, WSL, Linux, a container or a remote server.
Use status before restartCollect service state, logs, ports, disk and config before changing the running system.
Leave a trailWrite down what changed and how to reverse it after the incident is stable.

Command or pattern to start with

awk '{print $9}' /var/log/nginx/access.log | sort | uniq -c | sort -nr

Review checklist

  1. Confirm the environment where the symptom happens.
  2. Use a redacted sample that is still realistic enough to reproduce the behavior.
  3. Keep request headers, payloads, logs and timestamps together.
  4. Change one variable at a time so the result stays explainable.
  5. Link the final note to a related Formalint reference for the next person.

Common mistake

The common trap is running the strongest command first instead of collecting read-only status and logs.

Formalint is strongest when it becomes part of the incident rhythm: reduce the sample, format the evidence, verify the assumption and only then change the system.

Related Formalint references

Continue with Linux Admin Command Guide, Docker Compose Debugging Guide, Nginx Reverse Proxy Checklist.

Frequently asked questions

Can I paste production data into this workflow?

No. Use redacted or synthetic examples. The workflow is about evidence order, not copying sensitive systems into a browser.

Is this a replacement for logs and tests?

No. Treat it as a field guide that helps you decide which logs, tests and commands matter first.