Raw access logs provide request-level evidence for investigating missing pages, suspicious traffic and unexpected bandwidth. Download the relevant period before rotation removes evidence, and treat the files as potentially sensitive.
IN THIS ARTICLE
What you need before you begin
Identify the domain, incident time zone and whether traffic passed through a CDN. Logs may contain IP addresses, paths and query strings that should not be shared publicly.
01 Download raw access logs for an incident investigation
- Open Raw Access and locate the correct domain and available HTTP or HTTPS log entry.
- Check its update time and download the compressed log. Keep the original archive unchanged and analyse a working copy locally.
- Search for the incident time, request path, response status or known client address. Compare neighbouring requests to understand the sequence.
- If future retention is needed, review the available log archiving and retention settings. Choose a retention period appropriate for available storage and operational requirements.
- Save your findings with representative redacted lines, timestamps and the exact log source. Correlate them with application or security logs when necessary.
Confirm the expected result
The evidence should identify actual requests handled by the selected server. A CDN cache hit may never reach the origin, so the hosting log can legitimately show fewer requests than edge analytics.
Troubleshoot unexpected results
If the relevant period is missing, inspect available archived logs or ask support about retention. Do not assume enabling archives today reconstructs old records. Keep compressed archives outside the public website and remove temporary analysis copies according to your retention policy.
Are access logs a complete audit trail?
No. They describe the requests and fields recorded by that service. Application actions, database changes and requests served elsewhere require their own evidence.