ServerAvatarDocs
Server management

System logs

Every readable log on the server in one reader — live tail, severity filters, search, download and clear.

System Logs reads the log files on this server without you having to remember where any of them live. It finds them, groups them, and gives all of them the same reader: live tail, a filter box, a severity switch, copy and download.

The System Logs screen: a left rail of sources grouped as Web, Database, PHP, System, Security, Daemon, Cache and Cronjob with file sizes, and the PHP 8.4 FPM log open in the reader on the right

The source rail

The left rail is every log the panel can read, grouped by what produced it:

GroupWhat's in it
WebNginx (or OpenLiteSpeed) access and error logs.
DatabaseMySQL/MariaDB error, PostgreSQL, MongoDB.
PHPThe FPM log for each installed PHP version.
SystemSyslog, auth, kernel, the systemd journal.
SecurityThe firewall (UFW) log, Fail2ban, Let's Encrypt.
DaemonSupervisor.
CacheRedis.
CronjobOne source per cron job, with its captured output.

A green dot means the file has been written to recently. The size next to each name is the file on disk. The footer counts the sources, and says how many need elevated access.

Sources the panel cannot read yet are marked Needs elevated access — the file exists, but the panel's user has no permission to open it.

Reading a log

The header above the reader tells you what you are looking at: the source name, how many lines were loaded and whether that is the whole file, and the reminder that times are the server clock.

The controls, left to right:

  • Filter lines… — plain substring search over the loaded lines.
  • All / Errors / Warnings+ — severity filter.
  • Last 200 lines — how much to load, with a Custom… option.
  • Newest first / Oldest first, Wrap lines, Copy visible lines, Reload, Download.
  • Live — tail the file as it is written.
  • Clear log — empty the file on the server.

When the view is scrolled back and new lines arrive, a Jump to latest button appears with the count of what you have not seen.

Only the lines you loaded are searched

The filter searches the lines in the reader, not the whole file. If nothing matches, the panel says so and tells you how many lines were actually searched — load more lines to search deeper.

Cron output lands here

A cron job's captured output is a log source like any other, under Cronjob. View output on a cron row opens it directly.

The reader showing the Cron — Demo disk report source: repeated df output, each run followed by an exit=0 marker line with its timestamp

See Cron jobs for what the marker lines mean.

Clearing a log

Clear log empties the file on the server. Everything recorded so far is gone and cannot be recovered; the log keeps recording from that point.

Security logs are evidence

For the auth, firewall and Fail2ban logs the confirmation says something stronger: these record sign-ins, blocked requests and bans, so clearing one destroys evidence you may need after a break-in. Download it first if there is any doubt.

Limits and caveats

  • Live is off for logs over 2 MB. Turn it on explicitly to follow a large file.
  • Some sources are not files. The systemd journal is read through journalctl, so it cannot be downloaded or cleared from here.
  • Rotation is the system's, not the panel's. A log that rotated away since the page loaded shows Log no longer available; reload to refresh the list. Old rotated archives are what Disk cleaner offers to remove.
  • Per-application access and error logs have their own screen — see Application logs.

On this page