← All guides

GoAccess: Anonymize IP addresses when evaluating logs

GoAccess evaluates existing web server logs. With --anonymize-ip and different anonymization levels, the client address used in the GoAccess result can be reduced.

Enable anonymization

goaccess access.log --anonymize-ip --anonymize-level=3

The stages mask increasingly larger portions of IPv4 and IPv6 addresses. Which level makes sense depends on whether address-based evaluation is even needed.

Important: Source remains crucial

GoAccess reads an already existing log. Therefore, anonymization in GoAccess does not retroactively remove the full IP from the original Apache/nginx file. For “We don’t save!” Source logging should already take place without a complete visitor IP or be omitted entirely.

Minimize further data

Query strings, referrers and user agents can also contain unnecessary or identifying information. Only log and evaluate the fields that are actually needed.

Check log source

GoAccess evaluates existing logs. Therefore additionally Web server, proxy and provider logs Check and minimize the source data if possible.

Requirements

Access to the log files to be evaluated and knowledge of the log format; Use a small test file before making changes.

Dismantling

If complete addresses are required for a specific diagnosis, use the unchanged log source only for this limited purpose and then do not keep the data longer than necessary.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑