↑ ↓ select, Enter open, Esc close

Find the top IP addresses in the access log

Adjust the values, the command updates live
root@server
awk '{print $1}' /var/www/vhosts/system/example.com/logs/access_ssl_log | sort | uniq -c | sort -rn | head -20

Counts how often each IP address appears in the log and lists the 20 most frequent with their count. Useful when a server is suddenly under load and you want to know whether individual clients are responsible. Works with the combined format of Apache and nginx, where the IP is in the first column.

Note: On Plesk, HTTP and HTTPS requests are logged separately in access_log and access_ssl_log. Only the period since the last rotation is counted.

Also searched as

  • which ip makes the most requests
  • top ips in access log
  • who is hitting my site so often
  • count ip addresses in log file

Related one-liners

All in Logs

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.