When your website throws an error or behaves unexpectedly, the first place to look is the error log. Logs are the server's recorded evidence of everything that went wrong. DirectAdmin hosting provides several types of logs — Apache Error Log, Access Log, and PHP Error Log — each giving you different diagnostic information.
Types of Logs Available in DirectAdmin
- Apache Error Log — records web server errors: permission denied, file not found, 500 internal server errors
- Apache Access Log — records every HTTP request received, useful for traffic analysis and detecting anomalies
- PHP Error Log — records PHP-level errors specifically: warnings, fatal errors, and notices from your code
- FTP Transfer Log — records file uploads and downloads via FTP
How to View Error Logs in DirectAdmin
Method 1: Via DirectAdmin Panel
- Log in to DirectAdmin
- Go to Advanced Features → Site Summary / Statistics / Logs
- Select the domain you want to view logs for
- Click Error Log or Access Log
- DirectAdmin displays the last 20–50 lines of the selected log
Method 2: Via File Manager
Log files are stored in these locations (may vary by hosting configuration):
~/logs/yourdomain.com.error.log ~/logs/yourdomain.com.bytes_log ~/logs/yourdomain.com.log (access log) ~/logs/php_errorlog
Open File Manager in DirectAdmin → navigate to logs/ → right-click a file to view its contents.
Method 3: Via SSH (if available)
tail -n 100 ~/logs/yourdomain.com.error.log tail -f ~/logs/yourdomain.com.error.log # real-time streaming
The tail -f command streams the log in real time — ideal for debugging issues as they happen.
Reading the Apache Error Log
Apache error log entries follow this format:
[Thu May 16 10:23:45.123456 2026] [core:error] [pid 12345] [client 1.2.3.4:54321] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error.
- Date/time — when the error occurred
- [core:error] — the Apache module and severity level
- [client IP] — the IP address that made the request
- Error message — what went wrong
Common Errors and How to Fix Them
1. 500 Internal Server Error
[error] [client x.x.x.x] SoftException in Application.cpp:360: Script has to be an executable and writable only by its owner.
Cause: Incorrect file permissions — PHP files should be 644, not 777.
Fix: File Manager → right-click the file → Change Permission → set to 644.
2. Permission Denied
[error] [client x.x.x.x] (13)Permission denied: /home/user/public_html/.htaccess pcfg_openfile: unable to check htaccess file
Cause: Wrong permissions on .htaccess or parent directory.
Fix: Directories should be 755, files should be 644.
3. File Not Found (404)
[error] [client x.x.x.x] File does not exist: /home/user/public_html/wp-login.php
Cause: Missing file, typo in URL, or bot scanning for WordPress entry points.
Fix: If the file should exist, restore it. If it's bot traffic, consider rate-limiting or blocking the offending IPs via .htaccess.
4. .htaccess Redirect Loop
[error] Request exceeded the limit of 10 internal redirects
Cause: A RewriteRule in .htaccess redirects to a URL that matches the same rule, creating an infinite loop.
Fix: Add a guard RewriteCond to prevent the destination from matching the rule again.
Log Levels and What They Mean
Apache classifies log entries into eight severity levels following RFC 5424. Understanding these levels helps you filter for what actually needs attention instead of reading every line:
| Level | Meaning | Action Required |
|---|---|---|
emerg |
Emergency — server cannot function at all | Fix immediately |
alert |
Immediate action required | Fix immediately |
crit |
Critical — specific features failing | Urgent review |
error |
Request failed — 500, 403, permission errors | Review soon |
warn |
Warning — working but something is off | Log and monitor |
notice / info / debug |
Informational / debug output | Enable only when actively debugging |
DirectAdmin shared hosting typically sets LogLevel warn or error — appropriate for production because it avoids flooding your log files with noise. If you need deeper diagnostic output, you can temporarily add this to .htaccess:
LogLevel debug
Remove that line once debugging is complete. Debug logging generates entries for every request processed and can fill your disk quota quickly on busy sites.
Detecting Bots and Attack Patterns in Access Logs
The access log is your first line of defense for spotting automated traffic, vulnerability scans, and brute-force attempts. Warning signs to watch for:
- High request volume from a single IP — e.g., 1,000+ requests per minute from one address
- Suspicious User-Agent strings — such as
python-requests/2.x,curl/7.x, orGo-http-client/2.0 - Repeated URL patterns — targeting
/wp-admin/,/xmlrpc.php,/.env, or/admin/login - High 404 volume in short bursts — classic signature of vulnerability scanners probing known paths
Once you identify a suspicious IP, you can block it immediately via .htaccess:
# Block a single IP Deny from 203.0.113.1 # Block an entire subnet Deny from 203.0.113.0/24
For automated rate-limiting, mod_evasive (where supported by your hosting) can block IPs dynamically based on request thresholds — more effective than manual banning when facing distributed attacks.
Quick tip: Use awk to count requests by IP from your access log without SSH pipelines:awk '{print $1}' ~/logs/yourdomain.com.log | sort | uniq -c | sort -rn | head -20
This outputs the top 20 IP addresses ranked by request count.
Reading the Access Log
Access log entries use the Combined Log Format:
1.2.3.4 - - [16/May/2026:10:23:45 +0700] "GET /index.html HTTP/1.1" 200 1234 "https://google.com" "Mozilla/5.0..."
1.2.3.4— visitor's IP addressGET /index.html— HTTP method and requested URL200— HTTP status code returned1234— response size in bytes"https://google.com"— referer (where the visitor came from)"Mozilla/5.0..."— user agent string (browser/bot identifier)
Use the access log to:
- Identify IPs sending unusually high request volumes (DDoS/bots)
- Verify which pages search engine crawlers are accessing
- Find frequently occurring 404 and 500 errors
- Analyze bandwidth usage per request
Filter Logs with grep (SSH)
If SSH access is available, use grep to filter specific log entries quickly:
# Find all error entries grep "\[error\]" ~/logs/yourdomain.com.error.log # Find 500 errors from access log grep " 500 " ~/logs/yourdomain.com.log # Find all requests from a specific IP grep "^1\.2\.3\.4" ~/logs/yourdomain.com.log # Find today's 404 errors grep "16/May/2026" ~/logs/yourdomain.com.log | grep " 404 "
Log files larger than 10 MB should be downloaded and opened locally rather than viewed in File Manager — large files can freeze your browser. Use a text editor like Notepad++ or VS Code with a log viewer extension.
Enable PHP Error Logging
PHP error logs are separate from Apache error logs. Find them at:
~/logs/php_errorlog # or wherever set in php.ini: error_log = /home/username/logs/php_errorlog
To enable PHP error logging, add this to your .htaccess:
php_flag log_errors on php_value error_log /home/username/logs/php_errorlog
Log Rotation and Managing Log File Size
On hosting accounts that have been active for a while, log files accumulate rapidly — access logs in particular record every single request. DirectAdmin handles log rotation automatically on most plans, compressing and archiving logs daily or weekly. Archived logs appear with a numbered suffix:
~/logs/yourdomain.com.error.log (current) ~/logs/yourdomain.com.error.log.1.gz (yesterday) ~/logs/yourdomain.com.error.log.2.gz (two days ago)
You can read compressed archive logs without extracting them using zcat or zgrep:
# Read compressed log zcat ~/logs/yourdomain.com.error.log.1.gz | tail -100 # Search inside a compressed log zgrep "\[error\]" ~/logs/yourdomain.com.error.log.1.gz
To free up disk space, you can delete old .gz archive files directly via File Manager. Do not delete the current .log file (no numeric suffix) — Apache writes to it continuously and deleting it can cause logging to stop until the server rotates the log again.
If log files are still growing faster than rotation can handle, consider reducing your Apache LogLevel from warn to error, or enable mod_deflate compression for responses so the bytes-log figures stay smaller.
Hosting with Full Log Access
AsiaGB Hosting gives you access to Error Logs and Access Logs on every account via DirectAdmin — with SSD storage starting at 500 THB/year and 99% Uptime SLA.
View Hosting Plans