Upload your web server access log and we'll crawl your site, classify every request against our AI blueprint engine, and email you a detailed threat report. It costs nothing, and you won't need an account.
Takes less than 5 minutes · Standalone HTML report emailed to you
Real threat report for a New Zealand website, where 80.7% of all traffic turned out to be attacks. Your report will show your own data.
The whole thing runs on its own once you submit your domain and upload your log.
Submit your website's domain name and email address, and we start crawling your site right away to build a blueprint of what legitimate traffic looks like.
Once we've crawled your site, we'll email you a secure upload link. Drop in your web server access log, whether that's nginx, Apache, or a cPanel download. .log, .gz, .zip, and .tar.gz archives all work.
We classify every request in your log against your site's blueprint using the same AI engine that powers Moat AIS protection, then email you a personalised HTML report, ready to open in any browser.
Total requests, attack count, the share of traffic that turned out malicious, and an overall risk rating from Low to Critical.
Every IP that sent malicious traffic, ranked by volume, alongside their top probe paths and the attack types they favoured.
Legitimate visitors, bots, scanners, and attack traffic broken apart and shown as a donut chart with a detailed table underneath.
SQL injection, path scanning, credential stuffing, vulnerability probing: each category ranked by volume, with real example URLs pulled straight from your log.
Attack requests broken down by hour, so you can see when your site draws the most attention and how steady that rate is.
Every attack that reached your server, with confirmation that Moat AIS would have stopped it automatically before it got there.
Your web server keeps a detailed record of every request that hits it. Here's where that record lives.
/var/log/nginx/access.log
/var/log/nginx/access.log.1
Rotated files are numbered. Pass them all through for a fuller picture; anything ending in .gz gets decompressed automatically.
/var/log/apache2/access.log
/var/log/httpd/access_log
The location shifts depending on your distribution. Check /etc/apache2/
or /etc/httpd/ to confirm yours.
cPanel → Metrics → Raw Access
Download the last 7 to 30 days. cPanel zips its logs automatically, so just upload the .zip and we'll handle the rest.
Got a .tar.gz or .zip full of logs? Just upload the archive as it is. We'll extract every log file inside and analyse them together for a complete picture.
Enter your domain and email, and we'll crawl your site, analyse your logs, and send you a security report. No account or credit card needed.
Get my free threat reportAlready protected? Sign in to your dashboard →