v0.6.1 · Go 1.25 · Zero dependencies · MIT
Caddy JSON logs,
finally readable — and secured.
Caddy v2 writes nested JSON (request.uri, status, tls, headers) — not Common Log Format. grep, goaccess and lnav miss it. caddy-analyzer parses it natively, ranks traffic, and flags attacks with a dual-pass 26-category engine.
26
Categories
~70K
Parse / sec
~7K
Detect / sec
0
Deps
What it solves vs. generic tools
| caddy-analyzer | goaccess / lnav / grep | |
|---|---|---|
| Caddy JSON native | ✓ no regex, no config | ✗ misses nested fields |
| 26-category detection | ✓ dual-pass, confidence-scored | ✗ |
| Firewall guard | ✓ iptables / DOCKER-USER / nftables | ✗ |
| Sources | file, stdin, docker://, k8s://, journalctl:// | file only |
Documentation
QuickstartInstall → first command → first report, copy-paste.
InstallationLinux, macOS, Windows, Docker, binaries, verify.
Log SourcesHow to connect to each source + minimal perms.
CLI ReferenceAll flags and subcommands.
Threat Engine26 categories, MITRE, Sigma, guard overview.
TUI & HTML ReportsLive dashboard and export.
Next step
New here? Follow the 60-second quickstart — every command is copy-paste and produces a real report. Already installed? Jump to usage or CLI reference.