Raw web-server logs in, a readable incident report out. This one is loaded with 82 lines of nginx traffic that hide a bad deploy and a vulnerability scanner — see how fast you can spot both. Then paste your own; nothing leaves this tab.
Hover or focus the chart and use ← → to walk the buckets;
Enter filters the table to that moment, Esc clears.
Click a status pill to filter by class.
| # | method | agent |
|---|
Reads combined and common log format:
ip - user [10/Aug/2026:13:52:04 +0000] "GET /path HTTP/1.1" 200 5821 "ref" "agent"