Logs and LogFormat

Error Logs, Access Logs and LogFormat

The error log (ErrorLog, filtered by LogLevel) records startup messages, refused requests, PHP fatals under mod_php and anything a module reports. The access log (CustomLog) records one line per request in a format defined by LogFormat. Both can be set per virtual host, as site-b.conf did in Virtual Hosts. Ubuntu 225 keeps them in /var/log/apache2/ and rotates them daily, keeping 14 (Log Rotation); hosts without their own CustomLog share other_vhosts_access.log.

The stock combined format, which Cut, Sort and Count splits into fields, logs the client (%h), time (%t), request line (%r), final status (%>s), bytes sent (%O) and the Referer and User-Agent headers (%{Name}i). The timed format in site-b.conf adds %{Host}i and %D, the time taken in microseconds. After a success, the denied file from Directory, Files, Location and a missing stylesheet:

Reading the per-site access and error logsShell
sudo tail -n 3 /var/log/apache2/site-b-access.log
sudo tail -n 1 /var/log/apache2/site-b-error.log
Output
::1 www.site-b.example "GET / HTTP/1.1" 200 238 373us "curl/8.18.0"
::1 site-b.example "GET /private/secret.txt HTTP/1.1" 403 480 257us "curl/8.18.0"
::1 site-b.example "GET /missing.css HTTP/1.1" 404 477 308us "Mozilla/5.0"
[Wed Sep 23 15:11:16.979922 2026] [authz_core:error] [pid 31572:tid 31572] [client ::1:46276]
AH01630: client denied by server configuration: /var/www/site-b/private/secret.txt

The 403 left an error line naming the module and file; the 404 did not. LogLevel takes per-module levels, as in LogLevel warn authz_core:info, and Rewrite Tracing raises rewrite to its trace levels the same way; keep warn in production, since trace levels write several lines per request. The journal (journalctl) holds service starts and stops, never requests.