Point it at an Nginx or Apache access log and it gives you the numbers you'd
otherwise grep for by hand: request volume, error rate, who's hitting you the
hardest, and which paths are getting the most traffic. It also runs a few
rule-based checks on top — nothing fancy, but enough to catch a scanner
probing for .env files or a single IP hammering your server before you'd
notice it in a wall of log lines.
Only speaks Combined Log Format (the Apache/Nginx default). No log shipping, no dashboards, no dependencies — just a regex and some counting, because that's genuinely all this needs.
git clone https://github.com/SafraNako/log-analyzer.git
cd log-analyzer
pip install -e .log-analyzer /var/log/nginx/access.log14231 requests, 3.2% errors, 892,441,102 bytes served
Status codes
200 13102
301 412
404 598
500 119
Top IPs
203.0.113.44 820
198.51.100.9 311
...
Top paths
/api/v1/search 3021
/ 1884
...
Alerts
[CRITICAL] '.env' probed by 4 distinct IP(s)
[WARNING] 203.0.113.44 made 820 requests — possible bot or brute-force attempt
Options worth knowing about:
--top 20 # show more than the default 10 IPs/paths
--error-threshold 0.05 # alert if error rate goes above 5% instead of the default 10%
--repeat-threshold 500 # alert threshold for requests from a single IP
--skip-errors # don't abort on a line that doesn't match CLF, just count it and move onReal log files usually have a handful of malformed lines somewhere — a
truncated write from a crash, someone's manual edit, whatever. Without
--skip-errors the tool stops on the first one so you notice; with it, it
just tallies how many it dropped.
parser.py turns lines into LogEntry objects, stats.py aggregates them,
rules.py runs the alert checks against that summary. pytest for tests,
nothing else.
MIT licensed, see LICENSE.