v0.7.4 · updated · GitHub
v0.6.1 · Go 1.25 · Zero dependencies · MIT

Caddy JSON logs,
finally readable — and secured.

Caddy v2 writes nested JSON (request.uri, status, tls, headers) — not Common Log Format. grep, goaccess and lnav miss it. caddy-analyzer parses it natively, ranks traffic, and flags attacks with a dual-pass 26-category engine.

caddy-analyze --detect /var/log/caddy/access.log
Period: 2026-08-31 00:00 → 01:00  ·  12,450 req  ·  RPS 3.46
2xx ████████████████░░ 89%  ·  3xx ██░░░░ 2%  ·  4xx ███░░ 7%  ·  5xx █░░░░ 2%
Avg 4.2 KB  ·  P50 18ms  P95 210ms  ·  Human 92%  Bot 8%

Top IPs
  203.0.113.18    1,204  ████████████
  198.51.100.23     892  ████████

Suspicious (26-category detect)
  198.51.100.23  15 malicious
    [sql_injection T1190] GET /search?id=1' OR '1'='1 -- 
    [xss T1189] GET /q=<script>alert(1)</script>
    [scanner] GET /.env  ·  GET /.git/config
  203.0.113.18    8 malicious
    [path_traversal] GET /../../../../etc/passwd
26
Categories
~70K
Parse / sec
~7K
Detect / sec
0
Deps

What it solves vs. generic tools

caddy-analyzergoaccess / lnav / grep
Caddy JSON native✓ no regex, no config✗ misses nested fields
26-category detection✓ dual-pass, confidence-scored✗
Firewall guard✓ iptables / DOCKER-USER / nftables✗
Sourcesfile, stdin, docker://, k8s://, journalctl://file only

Documentation

Next step

New here? Follow the 60-second quickstart — every command is copy-paste and produces a real report. Already installed? Jump to usage or CLI reference.