nginx access logs without visitor IP addresses
nginx can switch off access logging directly. If technical logs are required, the format can be defined without a visitor address.
Prerequisites
You need access to the appropriate nginxserverblock and permission to test the configuration and reload nginx.
Switch off access log
server {
server_name example.de;
access_log off;
}
Log without visitor IP
log_format wsn_noip '$time_local "$request" $status $body_bytes_sent'; access_log /var/log/nginx/example-access.log wsn_noip;
$remote_addr may not be in the format. Furthermore, do not include the original address behind proxies in the log via X-Forwarded-For, Forwarded, CF-Connecting-IP or comparable headers.
Control
Test configuration, reload nginx, generate some requests and then check both access and error logs. Applications can store their own request data independently of nginx.
Dismantling
If there are problems, restore the previous access_logand log_formatconfiguration, run nginx -t and only then reload nginx.
Other log levels
Setting this level alone does not exclude other logs. In addition, What does my hosting provider store about website visitors? and check web server, proxy/CDN, security and provider separately.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.