← All guides

Traefik: Configure access logs to save data

Traefik can specifically keep, discard or edit access log fields. Client and request data in particular should be carefully selected.

Requirements

You need access to the static Traefik configuration and should save the previous access log configuration.

Setting

accessLog:
  format: json
  fields:
    defaultMode: keep
    names:
      ClientAddr: drop
      ClientHost: drop
      ClientPort: drop
    headers:
      defaultMode: drop
    queryParameters:
      defaultMode: drop

Test

Generate test requests and check the access logs. According to the configuration, ClientAddr, ClientHost, request header and query parameters may no longer be logged.

Dismantling

If problems occur, restore the backed up access log configuration and reload Traefik with the previous configuration.

ClientAddr usually contains IP and port, ClientHost the remote IP. Query parameters can contain email addresses, tokens or search terms; Headers can transport cookies and other identifiers.

If you don't need access logs, you shouldn't activate them just as a precaution.

Other log levels

Setting this level alone does not exclude other logs. In addition, What does my hosting provider store about website visitors? and check web server, proxy/CDN, security and provider separately.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑