# Network logs

> See every HTTP request Caddy served for a Falak site — per deployment, with status, method, path and client — in the Network Logs tab and the API.

Source: https://falak.sh/docs/observability/network-logs/

**Network logs** are the edge's access logs: one entry per request Caddy served for the site, on its servers or on the load balancer in front of them. They answer "what did users actually get from this deployment?"

## How they are collected

- Caddy writes each route's requests as JSON to `/var/log/falak/access/<site>.log` (10 MB × 3 files, rotated, kept out of the edge journal).
- The agent tails that directory, attributes entries by file name, and turns them into OpenTelemetry HTTP attributes. Request headers other than `User-Agent` are dropped.
- `5xx` responses are logged as ERROR, `4xx` as WARN.
- Sites behind a load balancer are logged on the **load balancer**, not on the backends.

## Read them

**Deployment panel → Network Logs** lists requests served by that deployment's release since it started, with a status filter, refreshing every 10 seconds while live.

Through the API:

```bash
curl "https://falak.example.com/api/v1/sites/shop/access-logs?status=5xx&since=3600" \
  -H "Authorization: Bearer $FALAK_TOKEN" -H "Accept: application/json"
```

```json
{"data": [{"ts": "1790000000000000002", "at": "2026-09-28T10:00:02.000000+00:00", "method": "GET", "path": "/cart",
           "query": "x=1", "status": 502, "duration_ms": 12.3, "bytes": 512, "request_bytes": 0,
           "client_ip": "203.0.113.9", "user_agent": "curl/8.5", "host": "shop.example.com",
           "server_id": "01k…", "deployment_id": "01k…", "release_id": "01k…"}],
 "meta": {"cursor": "1790000000000000002"}}
```

| Filter | Meaning |
|---|---|
| `server` | Server id |
| `deployment` | Requests served while that deployment's release was live |
| `method` | HTTP method |
| `status` | A code (`404`) or class (`5xx`) |
| `path` | Substring of the request URI |
| `client_ip` | Client address |
| `since`, `limit`, `cursor` | As for [logs](/docs/observability/logs/#filters) |

`503` when Loki is not configured.

## Limits

- Verified with FrankenPHP servers. The PHP-FPM + standalone Caddy path and Caddy versions older than 2.9 have not been verified.
- After upgrading from falak-ctl v0.2.5 or older, run `falak-ctl reload-configs` once, or Loki may keep an old configuration and access logs are not queryable. See [Upgrade](/docs/operations/upgrade/).

## Next steps
