TUI & HTML Reports
Two ways to see results live or shareable. Start from Quickstart → step 5; flags in CLI Reference.
TUI — live dashboard (--watch)
caddy-analyze --watch /var/log/caddy/access.log
caddy-analyze --watch docker://caddy
caddy-analyze --watch --detect /var/log/caddy/access.log # with security tab
Keys: 1–9 switch tabs, Tab/Shift+Tab cycle, r reset window, q quit. Auto-reset every 5 min.
| Tab | Shows |
|---|---|
| 1 Summary | Period, RPS, 2xx/3xx/4xx/5xx bars, bytes, P50/P95/P99, human/bot |
| 2 Realtime | Colorized stream (last 15) |
| 3 Security | Top 15 suspicious IPs with confidence and techniques (needs --detect) |
| 4 Top IPs | Top 20 IPs by requests |
| 5 Top Paths | Top 20 paths |
| 6 Top Domains | Top 20 request hosts |
| 7 User Agents | Top 15 UAs |
| 8 Geo | Top 15 countries + top 15 ASNs (needs GeoIP; background download hint if pending) |
| 9 Operational | Level/logger/message counts + last 15 operational events (needs --level or mixed log) |
Combine with global filters: caddy-analyze --watch --from 1h --country IT --no-bots --detect. Flags: --watch is root-only; persistent flags like --top/--format still apply.
HTML report — standalone
caddy-analyze -f html -o report.html --detect testdata/sample.log
caddy-analyze -f html -o report.html --detect /var/log/caddy/access.log
xdg-open report.html # or open / start
Single dark file, no server, no external assets, html.EscapeString safe. Also -f json/-f csv (-o writes 0600):
caddy-analyze -f json -o report.json --detect /var/log/caddy/access.log
caddy-analyze -f csv -o report.csv /var/log/caddy/access.log
Preview
Demo is the HTML formatter output (same CSS as reports). Full CLI for formats: CLI Reference → Output and Guide → Usage → Formats.