Make sense of your traffic.
Turn access logs into a clear picture of requests, errors, crawlers, cloud networks, and hosting providers.
Your access logs
Supported log formats
Apache / Nginx common and combined formats, or one JSON object per line. JSON accepts remote_addr, remoteAddress, client_ip, ClientIP, or ip; a status and request path are required. Timing charts use dated entries. JSON request_time is seconds; duration_ms is milliseconds. Forwarded headers are not selected automatically.
Supports up to 200,000 lines and 20,000 unique IPs. You can also reopen an exported Bug Days report JSON file here.
Open an address for optional ISP, ASN, approximate geolocation, and reverse-DNS details. Only that selected IP is checked with IPWhois.io and Cloudflare DNS; the rest of your list is not sent to those services.
A clearer view of every request.
See who is calling, which paths get attention, and where errors gather. Paste a log or start with the example.
No account or API key needed. Bulk matching sends only extracted IPs; optional live enrichment checks one selected address.
Network mix
Response status
HTTPRequest timeline
UTCAddress explorer
| IP address | Network / classification | Region / evidence | Requests | 4xx / 5xx | Details |
|---|
Most requested paths
Query strings excludedTake the findings with you.
Sources, coverage & parsing details
Matches describe published IP ranges, not the identity or intent of a visitor. Live geolocation is an approximate network location—not a home, street address, or proof of where a person is. Cloudflare ranges can identify an intermediary; use correctly configured client-IP logs to investigate the original visitor.
When you inspect one public IP, your browser requests live network context from IPWhois.io and a PTR record from Cloudflare DNS. Results are reused for the current page session and are not written to the IP range database.
Read the pattern behind the requests
Open Nginx or Apache common/combined access logs, or JSON logs with one request per line. See top client IPs, requested paths, response status counts, and a UTC request timeline. JSON logs with request durations also show median and 95th-percentile latency.
Connect requests to cloud and hosting networks
Match logged client IPs to the same cloud, VPS, CDN, service, and crawler datasets used by our bulk hosting IP lookup. Review provider traffic alongside request volume and errors, or follow the guide to identifying hosting IPs in access logs.
A report you can hand over
Raw logs are processed locally; only unique IP addresses are sent to Bug Days for provider matching. If you open one address, that address is also checked for live ISP, ASN, approximate location, and reverse DNS details. Report links include IP evidence, path counts, and summary findings, with query strings and raw lines excluded. Export JSON to reopen later, or use CSV, Excel, and print-to-PDF.