↑ ↓ select, Enter open, Esc close

Analyze server errors (5xx) in the access log

Adjust the values, the command updates live
root@server
awk '$9 ~ /^5[0-9][0-9]$/ {print $9, $7}' /var/www/vhosts/system/example.com/logs/access_ssl_log | sort | uniq -c | sort -rn | head -20

Prints status code and URL of every request with a 5xx response, grouped and sorted by frequency. This helps narrow down whether a single script is failing or the whole site is affected. The exact cause is then usually found in the error_log of the same domain.

Note: On Plesk with nginx, 502 and 504 errors often appear only in proxy_access_ssl_log, because Apache or PHP-FPM never responded.

Also searched as

  • where do the 500 errors come from
  • find internal server error in log
  • analyze 502 and 504 errors
  • which page throws server errors

Related one-liners

All in Logs

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.