Your raw access log is a plain text file that records every single request made to your website: every page view, image load, bot visit, and failed request, each with its own timestamp, IP address, and response code. It is more detailed than a visitor statistics tool, which only summarizes the data. You would use a raw access log when you need to see exactly which IP address is hammering your site, confirm whether a specific page was ever actually requested, or feed the data into your own analytics or security tool.
Raw access logs can grow large quickly on a busy site. Most hosting accounts only keep a few days or weeks of logs before older entries are rotated out or deleted, so download a copy if you need to keep records for longer.
In cPanel
- Log in to your cPanel account.
- Under the Metrics section, click Raw Access.
- If your domain has more than one log archived, you'll see a list. Click Download next to the domain and date you want.
- The file downloads as a compressed .gz archive. Extract it on your computer with any standard archive tool, or use the cPanel File Manager to extract it directly on the server first.
- On the same Raw Access page, you can also turn on Archive logs and choose whether to remove the previous month's log after archiving, so you keep a running history instead of losing it each time logs rotate.
In DirectAdmin
- Log in to your DirectAdmin account.
- Go to Account Manager, then click Show All Files or open the System Info & Files section depending on your theme, and look for Website Log Files (sometimes listed directly as Logs).
- Choose the domain you want logs for, then select the access log file from the list.
- Click to view it in the browser, or right-click and save it to download a copy to your computer.
- DirectAdmin typically rotates and compresses older logs automatically; look for files with a date or .gz extension in the same folder for previous periods.
Making sense of a log line
Each line follows a standard format, usually starting with the visitor's IP address, followed by the date and time, the exact request (the page or file requested and the method used), the HTTP status code returned, and the size of the response. A line ending in a 404 status means that request couldn't find the page; a line ending in 200 means it was served successfully. Repeated requests from the same IP address in a short span are often a bot or scanner rather than a real visitor.
For most day-to-day questions, such as how many visitors you had this month or which pages are most popular, the summarized Awstats report is faster to read, as covered in how to view your website's visitor statistics. Raw access logs are the better tool when you need the specific, line-by-line detail that a summary leaves out.