opensourceprojects.dev

A broadsheet for software that doesn't ask for your email

Real-time web log analysis in your terminal, one dependency
GitHub RepoImpressions2

Project Description

View on GitHub

Real-Time Web Log Analysis in Your Terminal, With Only One Dependency

You've got a web server churning out access logs, and something's off—maybe traffic spiked, maybe response times are climbing, maybe you just want to know what's actually hitting your site right now. You could pipe tail -f into grep and squint at raw log lines, or you could open a browser and wait for some heavyweight dashboard to load. GoAccess takes a different approach: it parses your logs in real time and shows you what's happening right there in your terminal.

What It Does

GoAccess is an open source, real-time web log analyzer and interactive viewer. It runs on *nix systems in the terminal, or directly in your browser via a live HTML dashboard. It's built for system administrators, DevOps engineers, and security professionals who need fast, actionable HTTP statistics without a lot of setup.

The core idea is simple: point it at a web log file, pick your log format, and it starts showing you stats. It parses the specified log file and outputs the data to your terminal, with all panels and metrics updating every 200 milliseconds. The HTML output refreshes every second. You get hits, visitors, bandwidth, slowest requests, and a bunch of other breakdowns—by hour, by date, by virtual host, whatever you need.

It's written in C, and it only needs ncurses to run. That's the entire dependency list. It even ships with its own WebSocket server (gwsocket) rather than pulling in something external.

Why It's Cool

  • The dependency situation is genuinely unusual. Most modern tooling drags in a runtime, a package manager, and a small village of transitive dependencies. GoAccess needs ncurses. That's it. For anyone who's ever tried to install a monitoring tool on a locked-down production box, this matters more than it probably should.

  • Real-time means real-time. A 200ms refresh on the terminal output isn't a marketing number—it's fast enough that you can watch traffic patterns shift as you're troubleshooting. The HTML dashboard updates every second, which is plenty for a live view.

  • It handles nearly every log format you'll encounter. Apache, Nginx, Amazon S3, Elastic Load Balancing, CloudFront—and if your format isn't in the predefined list, you can supply any custom log format string. That flexibility means you're not rewriting your logging setup to fit the tool.

  • Response time tracking is built in. You can track how long requests take to serve, which is exactly what you want when you're trying to figure out which pages are dragging your site down. This isn't a separate plugin or a paid tier—it's just there.

  • Incremental processing and persistence. If you don't want to re-parse everything from scratch every time, GoAccess can process logs incrementally using on-disk persistence. Useful for long-running analysis or when your logs are large enough that a full re-parse is annoying.

  • Bot and crawler classification has gotten more thoughtful. It keeps AI crawlers and Fediverse (ActivityPub) traffic in their own categories, separate from traditional search engine crawlers. If you've ever tried to figure out why your traffic numbers look weird because of bot noise, this is a welcome detail.

  • ASN mapping for security work. You can detect malicious traffic patterns by autonomous system number and block whole networks with --exclude-asn. It's a practical feature for anyone doing incident response or ongoing security monitoring.

  • WebSocket authentication that isn't an afterthought. Local and external JWT verification, secure token refresh, and verified tokens tracked to their exp claim—connections close when tokens expire. If you're exposing the HTML dashboard, this is the kind of thing you want handled properly.

  • It scales to large datasets. The in-memory hash tables are optimized for parsing large logs, with good memory usage and performance. You're not going to hit a wall the moment your log file gets into the gigabytes.

How to Try It

The fastest way to get started is to grab it from the repository and build it, or install it through your system's package manager if it's available.

  1. Head to the repository: https://github.com/allinurl/goaccess

  2. Check the installation instructions for your platform. Since it's written in C with only ncurses as a dependency, building from source is straightforward on most *nix systems.

  3. Once installed, run it against an access log:

goaccess /var/log/nginx/access.log --log-format=COMBINED
  1. Pick your log format when prompted (or specify it directly), and you'll get the terminal dashboard immediately.

  2. For the HTML output, you can generate a static report or run the real-time dashboard. The README and the project site at https://goaccess.io have the details on the WebSocket setup if you want the live browser view.

If you're not sure which format to use, the predefined options cover most common servers, and the custom format string support means you can always describe your own.

Final Thoughts

GoAccess is one of those tools that does one thing well and doesn't ask much of you in return. It's not trying to be a full observability platform—it's a log analyzer that runs in your terminal and gives you answers fast. If you're a sysadmin, DevOps engineer, or security person who spends time in logs, it's worth having in your toolkit. The single-dependency design makes it easy to justify installing on servers where you'd rather not add another moving part. Give it a shot next time you're tailing a log file and wishing you had a better view.


Follow @githubprojects for more developer tools and open source projects.

Back to Projects
Project ID: 912d0135-b431-409a-9dec-9295d5508395Last updated: September 29, 2026 at 02:52 AM