Skip to content

Network logs

Network logs are the edge’s access logs: one entry per request Caddy served for the site, on its servers or on the load balancer in front of them. They answer “what did users actually get from this deployment?”

  • Caddy writes each route’s requests as JSON to /var/log/falak/access/<site>.log (10 MB × 3 files, rotated, kept out of the edge journal).
  • The agent tails that directory, attributes entries by file name, and turns them into OpenTelemetry HTTP attributes. Request headers other than User-Agent are dropped.
  • 5xx responses are logged as ERROR, 4xx as WARN.
  • Sites behind a load balancer are logged on the load balancer, not on the backends.

Deployment panel → Network Logs lists requests served by that deployment’s release since it started, with a status filter, refreshing every 10 seconds while live.

Through the API:

Terminal window
curl "https://falak.example.com/api/v1/sites/shop/access-logs?status=5xx&since=3600" \
-H "Authorization: Bearer $FALAK_TOKEN" -H "Accept: application/json"
{"data": [{"ts": "1790000000000000002", "at": "2026-09-28T10:00:02.000000+00:00", "method": "GET", "path": "/cart",
"query": "x=1", "status": 502, "duration_ms": 12.3, "bytes": 512, "request_bytes": 0,
"client_ip": "203.0.113.9", "user_agent": "curl/8.5", "host": "shop.example.com",
"server_id": "01k…", "deployment_id": "01k…", "release_id": "01k…"}],
"meta": {"cursor": "1790000000000000002"}}
Filter Meaning
server Server id
deployment Requests served while that deployment’s release was live
method HTTP method
status A code (404) or class (5xx)
path Substring of the request URI
client_ip Client address
since, limit, cursor As for logs

503 when Loki is not configured.

  • Verified with FrankenPHP servers. The PHP-FPM + standalone Caddy path and Caddy versions older than 2.9 have not been verified.
  • After upgrading from falak-ctl v0.2.5 or older, run falak-ctl reload-configs once, or Loki may keep an old configuration and access logs are not queryable. See Upgrade.