Error Log DirectAdmin

When your website throws an error or behaves unexpectedly, the first place to look is the error log. Logs are the server's recorded evidence of everything that went wrong. DirectAdmin hosting provides several types of logs — Apache Error Log, Access Log, and PHP Error Log — each giving you different diagnostic information.

Types of Logs Available in DirectAdmin

How to View Error Logs in DirectAdmin

Method 1: Via DirectAdmin Panel

  1. Log in to DirectAdmin
  2. Go to Advanced Features → Site Summary / Statistics / Logs
  3. Select the domain you want to view logs for
  4. Click Error Log or Access Log
  5. DirectAdmin displays the last 20–50 lines of the selected log

Method 2: Via File Manager

Log files are stored in these locations (may vary by hosting configuration):

~/logs/yourdomain.com.error.log
~/logs/yourdomain.com.bytes_log
~/logs/yourdomain.com.log   (access log)
~/logs/php_errorlog

Open File Manager in DirectAdmin → navigate to logs/ → right-click a file to view its contents.

Method 3: Via SSH (if available)

tail -n 100 ~/logs/yourdomain.com.error.log
tail -f ~/logs/yourdomain.com.error.log   # real-time streaming

The tail -f command streams the log in real time — ideal for debugging issues as they happen.

Reading the Apache Error Log

Apache error log entries follow this format:

[Thu May 16 10:23:45.123456 2026] [core:error] [pid 12345] [client 1.2.3.4:54321] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error.

Common Errors and How to Fix Them

1. 500 Internal Server Error

[error] [client x.x.x.x] SoftException in Application.cpp:360: Script has to be an executable and writable only by its owner.

Cause: Incorrect file permissions — PHP files should be 644, not 777.

Fix: File Manager → right-click the file → Change Permission → set to 644.

2. Permission Denied

[error] [client x.x.x.x] (13)Permission denied: /home/user/public_html/.htaccess pcfg_openfile: unable to check htaccess file

Cause: Wrong permissions on .htaccess or parent directory.

Fix: Directories should be 755, files should be 644.

3. File Not Found (404)

[error] [client x.x.x.x] File does not exist: /home/user/public_html/wp-login.php

Cause: Missing file, typo in URL, or bot scanning for WordPress entry points.

Fix: If the file should exist, restore it. If it's bot traffic, consider rate-limiting or blocking the offending IPs via .htaccess.

4. .htaccess Redirect Loop

[error] Request exceeded the limit of 10 internal redirects

Cause: A RewriteRule in .htaccess redirects to a URL that matches the same rule, creating an infinite loop.

Fix: Add a guard RewriteCond to prevent the destination from matching the rule again.

Log Levels and What They Mean

Apache classifies log entries into eight severity levels following RFC 5424. Understanding these levels helps you filter for what actually needs attention instead of reading every line:

Level Meaning Action Required
emerg Emergency — server cannot function at all Fix immediately
alert Immediate action required Fix immediately
crit Critical — specific features failing Urgent review
error Request failed — 500, 403, permission errors Review soon
warn Warning — working but something is off Log and monitor
notice / info / debug Informational / debug output Enable only when actively debugging

DirectAdmin shared hosting typically sets LogLevel warn or error — appropriate for production because it avoids flooding your log files with noise. If you need deeper diagnostic output, you can temporarily add this to .htaccess:

LogLevel debug

Remove that line once debugging is complete. Debug logging generates entries for every request processed and can fill your disk quota quickly on busy sites.

Detecting Bots and Attack Patterns in Access Logs

The access log is your first line of defense for spotting automated traffic, vulnerability scans, and brute-force attempts. Warning signs to watch for:

Once you identify a suspicious IP, you can block it immediately via .htaccess:

# Block a single IP
Deny from 203.0.113.1

# Block an entire subnet
Deny from 203.0.113.0/24

For automated rate-limiting, mod_evasive (where supported by your hosting) can block IPs dynamically based on request thresholds — more effective than manual banning when facing distributed attacks.

Quick tip: Use awk to count requests by IP from your access log without SSH pipelines:
awk '{print $1}' ~/logs/yourdomain.com.log | sort | uniq -c | sort -rn | head -20
This outputs the top 20 IP addresses ranked by request count.

Reading the Access Log

Access log entries use the Combined Log Format:

1.2.3.4 - - [16/May/2026:10:23:45 +0700] "GET /index.html HTTP/1.1" 200 1234 "https://google.com" "Mozilla/5.0..."

Use the access log to:

Filter Logs with grep (SSH)

If SSH access is available, use grep to filter specific log entries quickly:

# Find all error entries
grep "\[error\]" ~/logs/yourdomain.com.error.log

# Find 500 errors from access log
grep " 500 " ~/logs/yourdomain.com.log

# Find all requests from a specific IP
grep "^1\.2\.3\.4" ~/logs/yourdomain.com.log

# Find today's 404 errors
grep "16/May/2026" ~/logs/yourdomain.com.log | grep " 404 "

Log files larger than 10 MB should be downloaded and opened locally rather than viewed in File Manager — large files can freeze your browser. Use a text editor like Notepad++ or VS Code with a log viewer extension.

Enable PHP Error Logging

PHP error logs are separate from Apache error logs. Find them at:

~/logs/php_errorlog
# or wherever set in php.ini:
error_log = /home/username/logs/php_errorlog

To enable PHP error logging, add this to your .htaccess:

php_flag log_errors on
php_value error_log /home/username/logs/php_errorlog

Log Rotation and Managing Log File Size

On hosting accounts that have been active for a while, log files accumulate rapidly — access logs in particular record every single request. DirectAdmin handles log rotation automatically on most plans, compressing and archiving logs daily or weekly. Archived logs appear with a numbered suffix:

~/logs/yourdomain.com.error.log       (current)
~/logs/yourdomain.com.error.log.1.gz  (yesterday)
~/logs/yourdomain.com.error.log.2.gz  (two days ago)

You can read compressed archive logs without extracting them using zcat or zgrep:

# Read compressed log
zcat ~/logs/yourdomain.com.error.log.1.gz | tail -100

# Search inside a compressed log
zgrep "\[error\]" ~/logs/yourdomain.com.error.log.1.gz

To free up disk space, you can delete old .gz archive files directly via File Manager. Do not delete the current .log file (no numeric suffix) — Apache writes to it continuously and deleting it can cause logging to stop until the server rotates the log again.

If log files are still growing faster than rotation can handle, consider reducing your Apache LogLevel from warn to error, or enable mod_deflate compression for responses so the bytes-log figures stay smaller.

Hosting with Full Log Access

AsiaGB Hosting gives you access to Error Logs and Access Logs on every account via DirectAdmin — with SSD storage starting at 500 THB/year and 99% Uptime SLA.

View Hosting Plans