TYPO3: Configure IP anonymization and logs correctly
With TYPO3 it is particularly important not to copy old internet instructions. Historical stat_IP_anonymizeoptions were removed many versions ago.
Requirements
Access to the TYPO3 system configuration as well as the application and server logs actually used.
Current setting
$GLOBALS['TYPO3_CONF_VARS']['SYS']['ipAnonymization'] controls masking in TYPO3 anonymization tasks. Value 1 masks the last byte in IPv4, value 2 masks the last two bytes; For IPv6, the interface ID or additionally the SLA ID are masked.
Important restriction
The current TYPO3 documentation explicitly states that this setting is taken into account for anonymization tasks, not when creating new log entries. It is therefore not a substitute for checking the logs that have actually been written.
Check production logs
TYPO3 itself points out that logs may contain personal data such as IP addresses. Additionally check web server, proxy and hoster logs and limit retention.
Test
Generate test calls and check the newly written logs.
Dismantling
If there are problems, restore the previous setting and check again.
Additional levels
In addition, use the checking checklist for unnecessary visitor data so that TYPO3 logging is not evaluated in isolation from web server, proxy and provider logs.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.