↑ ↓ select, Enter open, Esc close

Show all requests from one IP address in the access log

Adjust the values, the command updates live
root@server
awk -v ip="203.0.113.10" '$1 == ip' /var/www/vhosts/system/example.com/logs/access_ssl_log | tail -50

Prints only lines whose first column exactly matches the given IP and shows the last 50 of them. Unlike a plain grep, the exact comparison does not accidentally match similar addresses such as 1203.0.113.10. Useful after an IP has stood out in the top list and you want to know what it requests before blocking it.

Also searched as

  • what is this ip doing on my server
  • show requests from one ip
  • filter access log by ip address
  • investigate suspicious ip

Related one-liners

All in Logs

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.