Project

General

Profile

Actions

Mod accesslog » History » Revision 31

« Previous | Revision 31/48 (diff) | Next »
mot, 2017-02-24 15:20
Fix link to Wikipedia regarding syslog level and use HTTPS instead of HTTP


Accesslog

Module: mod_accesslog

Description

CLF like by default, flexible like apache

Options

  • accesslog.use-syslog
    send the accesslog to syslog

    Default: disabled

  • accesslog.filename
    name of the file where the accesslog should be written to if syslog is not used.

    if the name starts with a '|' the rest of the name is taken as the name of a process which will be spawned and will get the output

    e.g.:

    accesslog.filename = "/var/log/lighttpd.log" 
    
    $HTTP["host"] == "mail.example.org" {
      accesslog.filename = "|/usr/bin/cronolog" 
    }

    if you have multiple workers on 1.4.x (now, the current version) and want all access logs to be written (without that, only one worker will write logs), use accesslog.filename = "\|/usr/sbin/cronolog.."

    Default: disabled

  • accesslog.format
    the format of the logfile
    Option Description
    %% a percent sign
    %h name or address of remote-host
    %l ident name (not supported)
    %u authenticated user
    %t timestamp of the end-time of the request
    %{...}t timestamp of the end-time of the request (supported in 1.4.40)
    %r request-line
    %s status code
    %b bytes sent for the body
    %i HTTP-header field
    %a remote address (supported in 1.4.40)
    %A local address (supported in 1.4.40)
    %B same as %b
    %C cookie field (supported in 1.4.40)
    %D time used in ms (supported in 1.4.40)
    %e environment
    %f physical filename
    %H request protocol (HTTP/1.0, ...)
    %k num keepalives (supported in 1.4.40)
    %m request method (GET, POST, ...)
    %n notes (internal module notes) (supported in 1.4.43)
    %o response header
    %p server port
    %P (not supported)
    %q query string
    %T time used in seconds
    %{UNIT}T time used in UNIT (s, ms, us, or ns) (supported in 1.4.40)
    %U request URL
    %v server-name
    %V HTTP request host name
    %X connection status
    %I bytes incoming
    %O bytes outgoing

    If %s is written %>s or %<s the < and the > are ignored. They are supported for compatibility with apache.

    %h will always return the IP address of the host, never the name. This makes it equivalent to %a.

    %a, %A, %{name}C, %D, %k, %{...}t, %{...}T are implemented in lighttpd 1.4.40 and later.

    %i and %o expect the name of the field which should be written in curly brackets.

    %q is not prepended with '?', unlike Apache

    %{StrFTime format string}t is supported since 1.4.24.

    %t does not work the same way it works in Apache (where the start of the request is recorded). Instead it shows the time the request actually got delivered. For most users this does not matter as usually requests don't take long to get processed. Use %{begin:...}t for time at start of request.

    %{ratio}n shows file compression ratio for mod_compress and mod_deflate (since 1.4.43)

In lighttpd version 1.3.16, the default format is:

    accesslog.format = "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" 
Default: CLF compatible output.

In lighttpd versions 1.4.13-1.4.20, the default setting is:

    accesslog.format = "%h %V %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" 

The difference between Apache's CLF is the second field changes from ``%l`` to ``%V``.

Response Header

The accesslog module provides a special way to log content from the
application in a accesslog file. It can be used to log the session id into a
logfile.

If you want to log it into the accesslog just specify the field-name within
a %{...}o like ::

  accesslog.format = "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" \"%{X-LIGHTTPD-SID}o\"" 

The prefix ``X-LIGHTTPD-`` is special as every response header starting with
this prefix is assumed to be special for lighttpd and won't be sent out
to the client.

An example the use this functionality is provided below: ::

  <?php

  session_start();

  header("X-LIGHTTPD-SID: ".session_id());

  ?>
  TEST

----
Note: If you log to a pipe and have lighty chrooted the user running lighty will need access to “/bin/sh”.

Updated by mot about 7 years ago · 31 revisions