← All guides

nginx access logs without visitor IP addresses

nginx can switch off access logging directly. If technical logs are required, the format can be defined without a visitor address.

Prerequisites

You need access to the appropriate nginxserverblock and permission to test the configuration and reload nginx.

Switch off access log

server {
    server_name example.de;
    access_log off;
}

Log without visitor IP

log_format wsn_noip '$time_local "$request" $status $body_bytes_sent';
access_log /var/log/nginx/example-access.log wsn_noip;

$remote_addr may not be in the format. Furthermore, do not include the original address behind proxies in the log via X-Forwarded-For, Forwarded, CF-Connecting-IP or comparable headers.

Control

Test configuration, reload nginx, generate some requests and then check both access and error logs. Applications can store their own request data independently of nginx.

Dismantling

If there are problems, restore the previous access_logand log_formatconfiguration, run nginx -t and only then reload nginx.

Other log levels

Setting this level alone does not exclude other logs. In addition, What does my hosting provider store about website visitors? and check web server, proxy/CDN, security and provider separately.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑