v0.7.4 · updated · GitHub

TUI & HTML Reports

Two ways to see results live or shareable. Start from Quickstart → step 5; flags in CLI Reference.

TUI — live dashboard (--watch)

caddy-analyze --watch /var/log/caddy/access.log
caddy-analyze --watch docker://caddy
caddy-analyze --watch --detect /var/log/caddy/access.log  # with security tab

Keys: 1–9 switch tabs, Tab/Shift+Tab cycle, r reset window, q quit. Auto-reset every 5 min.

TabShows
1 SummaryPeriod, RPS, 2xx/3xx/4xx/5xx bars, bytes, P50/P95/P99, human/bot
2 RealtimeColorized stream (last 15)
3 SecurityTop 15 suspicious IPs with confidence and techniques (needs --detect)
4 Top IPsTop 20 IPs by requests
5 Top PathsTop 20 paths
6 Top DomainsTop 20 request hosts
7 User AgentsTop 15 UAs
8 GeoTop 15 countries + top 15 ASNs (needs GeoIP; background download hint if pending)
9 OperationalLevel/logger/message counts + last 15 operational events (needs --level or mixed log)

Combine with global filters: caddy-analyze --watch --from 1h --country IT --no-bots --detect. Flags: --watch is root-only; persistent flags like --top/--format still apply.

HTML report — standalone

caddy-analyze -f html -o report.html --detect testdata/sample.log
caddy-analyze -f html -o report.html --detect /var/log/caddy/access.log
xdg-open report.html  # or open / start

Single dark file, no server, no external assets, html.EscapeString safe. Also -f json/-f csv (-o writes 0600):

caddy-analyze -f json -o report.json --detect /var/log/caddy/access.log
caddy-analyze -f csv -o report.csv /var/log/caddy/access.log

Preview

Demo is the HTML formatter output (same CSS as reports). Full CLI for formats: CLI Reference → Output and Guide → Usage → Formats.