↑ ↓ select, Enter open, Esc close

Count requests per minute in the access log

Adjust the values, the command updates live
root@server
awk '{print substr($4, 2, 17)}' /var/www/vhosts/system/example.com/logs/access_ssl_log | sort | uniq -c | sort -rn | head -20

Extracts date, hour and minute from the timestamp ([09/Oct/2026:14:03:12) and counts the requests per minute. The 20 minutes with the most hits are shown. Useful for matching a load spike against cron jobs, backups or an attack.

Note: For a chronological timeline instead of a ranking, replace the final sort -rn | head -20 with sort -k2.

Also searched as

  • when was the traffic spike
  • requests per minute from access log
  • count hits per minute
  • at what time did most requests come in

Related one-liners

All in Logs

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.