🪵HTTP Access Log Line Parser

Split a Combined or Common log line into fields

LineResultStatusRequest or reason it stopped

Fields are not cut on every space: spaces inside quotes and brackets stay in one field, and a backslash-escaped quote is read as a character. Status codes are grouped from 1xx to 5xx only, without per-code meanings.

You Might Also Need

How to use the access log line parser

Paste an access log line and the field count decides whether it is Combined or Common, then the page splits out the client, time, method, path, query, status code, response size, referer and user agent. Paste several lines and each one gets a pass or fail row in the table, with the detailed breakdown taken from the first line that parsed. You can also pick the format yourself.

How the parsing works

Fields are not cut on whitespace. A small state machine keeps everything inside a quote or a bracket together until the pair closes, and resolves backslash escapes along the way. The time field is read in the NCSA shape dd/Mon/yyyy:HH:MM:SS +ZZZZ and converted to ISO 8601 UTC with the offset applied. The field layouts follow the Common and Combined definitions in the Apache HTTP Server documentation, as of October 2026.

Limits worth knowing

Custom nginx formats and JSON logs are out of scope. When the field count is neither seven nor nine the automatic choice is refused, so select the format by hand. Extra fields past the format are ignored and the page says so. Log lines often carry addresses and request paths that count as personal data, so check before sharing them. Everything is processed in your browser.

Frequently Asked Questions

Why can I not just split on spaces?

The user agent, the request line and the time field all contain spaces. A plain split breaks one field into pieces and shifts the status code out of place. This parser closes each quote and bracket before moving to the next field.

What does it tell me when parsing fails?

It names the line, the field number and the character position where it stopped, and says whether a closing quote was missing or the time, status or size field had the wrong shape.

What does this tool not do?

It does not aggregate a whole log file, estimate traffic or crawl budget, and it does not explain what each status code means. It stays on splitting one line into fields.