Access Log to CSV/TSV — Nginx & Apache Combined

Parse Nginx/Apache combined or common access logs into CSV or TSV. Auto-detect format; malformed lines listed — processing stays local.

Loading…
Access log → CSV/TSV
Turn classic combined/common access logs into spreadsheet-friendly CSV or TSV. Browser-local; cloud JSON access logs are out of scope.

Developer notes

auto tries combined then common on the first usable line and locks that format. Lines over 8 KiB are skipped with an issue. CSV quotes fields containing commas, quotes, or newlines. TSV replaces tab/newline in fields with spaces. Live CSV/TSV updates ~300 ms after typing stops — no Parse click. Zero good rows → failure.

Options

Log format
auto detects combined vs common from the first usable line; or force combined / common.
Output format
csv (RFC4180 quoting) or tsv (tab-separated, sanitized fields).
CSV delimiter
Field separator when output is CSV — comma by default; semicolon for EU Excel.

When teams pick this route

Paste a nginx access.log snippet into Sheets. Extract status and request columns for a quick triage. Convert common-format lines without referer/UA columns. Spot malformed lines via the issues list.

Worked examples

Several combined lines

Input

203.0.113.10 - alice [12/Jul/2026:09:15:01 +0000] "GET /health HTTP/1.1" 200 12 "-" "kube-probe/1.28" 203.0.113.44 - bob [12/Jul/2026:09:15:02 +0000] "POST /v1/orders HTTP/1.1" 201 318 "https://shop.example/cart" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15" 198.51.100.7 - - [12/Jul/2026:09:15:03 +0000] "GET /assets/app.js HTTP/1.1" 200 98421 "https://shop.example/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/126.0.0.0" 203.0.113.44 - bob [12/Jul/2026:09:15:04 +0000] "GET /v1/orders/ord_1001 HTTP/1.1" 200 892 "https://shop.example/account" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15" 192.0.2.55 - - [12/Jul/2026:09:15:05 +0000] "GET /admin HTTP/1.1" 403 19 "-" "python-requests/2.32.3" 203.0.113.99 - carol [12/Jul/2026:09:15:06 +0000] "PUT /v1/profile HTTP/1.1" 204 0 "https://shop.example/settings" "Mozilla/5.0 (X11; Linux x86_64) Firefox/128.0" 198.51.100.7 - - [12/Jul/2026:09:15:07 +0000] "GET /favicon.ico HTTP/1.1" 404 43 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/126.0.0.0" 203.0.113.44 - bob [12/Jul/2026:09:15:08 +0000] "POST /v1/payments HTTP/1.1" 402 156 "https://shop.example/checkout" "Mozilla/5.0 (compatible; Bot, like Gecko)"

CSV (header + row)

remote_addr,remote_user,time_local,request,status,body_bytes_sent,http_referer,http_user_agent 203.0.113.10,alice,12/Jul/2026:09:15:01 +0000,GET /health HTTP/1.1,200,12,-,kube-probe/1.28 …

Common line (fewer columns)

Input

127.0.0.1 - frank [10/Oct/2000:13:55:36 -0700] "GET /apache_pb.gif HTTP/1.0" 200 2326

CSV (header + row)

remote_addr,remote_user,time_local,request,status,body_bytes_sent 127.0.0.1,frank,10/Oct/2000:13:55:36 -0700,GET /apache_pb.gif HTTP/1.0,200,2326

Navigate related log tools

For JSON/NDJSON streams use format JSON logs and validate NDJSON, or open the logs hub.

Access log parser FAQ

Combined & common

Are ALB or Cloudflare JSON logs supported?

Not in v1. This tool targets classic Nginx/Apache combined and common text formats only.

What if auto cannot detect the format?

The run fails and asks you to pick combined or common explicitly when the first line matches neither.

Is there an HTML table preview?

No — v1 outputs CSV or TSV text only for paste into spreadsheets.

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.