← All guides

TYPO3: Configure IP anonymization and logs correctly

With TYPO3 it is particularly important not to copy old internet instructions. Historical stat_IP_anonymizeoptions were removed many versions ago.

Requirements

Access to the TYPO3 system configuration as well as the application and server logs actually used.

Current setting

$GLOBALS['TYPO3_CONF_VARS']['SYS']['ipAnonymization'] controls masking in TYPO3 anonymization tasks. Value 1 masks the last byte in IPv4, value 2 masks the last two bytes; For IPv6, the interface ID or additionally the SLA ID are masked.

Important restriction

The current TYPO3 documentation explicitly states that this setting is taken into account for anonymization tasks, not when creating new log entries. It is therefore not a substitute for checking the logs that have actually been written.

Check production logs

TYPO3 itself points out that logs may contain personal data such as IP addresses. Additionally check web server, proxy and hoster logs and limit retention.

Test

Generate test calls and check the newly written logs.

Dismantling

If there are problems, restore the previous setting and check again.

Additional levels

In addition, use the checking checklist for unnecessary visitor data so that TYPO3 logging is not evaluated in isolation from web server, proxy and provider logs.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑