← All guides

Apache access logs without visitor IP addresses

Apache needs to process the IP address for the ongoing network connection. However, it does not have to end up permanently in the normal access log.

Requirements

You need access to the website's Apache configuration and permission to test and reload the configuration.

Variant 1: No access log for the website

If no request protocol is required, an unwritten access log is the most data-efficient variant. Also check the server's global GlobalLogor CustomLogdirectives.

Variant 2: Technical log without client IP

LogFormat "%t "%r" %>s %b" wsn_noip
CustomLog /var/log/apache2/example-access.log wsn_noip

Apache 2.4 documents %a as client IP and %h as remote host, which also regularly contains the IP when hostname lookups are deactivated. Both therefore do not belong in an IP-free format. Also only log referrers, user agents and query strings when they are really needed.

Test

After the change, test the Apache configuration, reload it, create a test call and then check whether no visitor IP was written in the access log actually used.

Restore

If an application or troubleshooting requires the previous logging, restore the changed CustomLogand LogFormatdirectives from the previous configuration and test Apache again.

Don't forget

Error logs, PHP/CMS logs, reverse proxies and the host are separate levels. An IP-free Apache access log says nothing about what is stored there.

Additional log levels

Setting this level alone does not exclude other protocols. In addition, What does my hosting provider store about website visitors? and check web server, proxy/CDN, security and provider separately.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑