Record parsing
The analyzer reads the input line by line and interprets records that resemble supported Apache, Nginx, or auth.log formats. Depending on the record, relevant evidence can include timestamps, client addresses, HTTP methods, request targets, status codes, authentication outcomes, and the program that emitted a message. Missing or nonstandard fields limit which connections the report can make.