How to Log the Client IP Address in Apache Behind a Load Balancer

Post Date: January 5, 2016
Last Updated: September 28, 2026

Introduction

When an Apache web server is placed behind a load balancer, the Apache access logs may record the load balancer’s private IP address instead of the original client’s IP address. This can make it difficult to identify the actual source of incoming requests. By configuring Apache to log the X-Forwarded-For header, you can capture the original client IP address along with the load balancer IP address. This article explains how to configure Apache 2.4 to log the originating client IP address when the web server is behind a load balancer.

Prerequisites

Before implementing this configuration, ensure the following requirements are met:

  • Apache HTTP Server 2.4 is installed and running.
  • The web server is running on Ubuntu or a similar Linux distribution.
  • You have root or sudo access to the server.
  • The Apache configuration files are located under /etc/apache2.
  • The web server is behind a load balancer such as an AWS/EC2 load balancer or HAProxy.
  • The load balancer is configured to forward the client’s original IP address using the X-Forwarded-For HTTP header.
  • You have permission to modify Apache configuration files and restart the Apache service.

Implementation

By default, Apache logs the IP address where the request comes from. Consider a scenario where the web server (in our post, we deal with Apache) is behind a load balancer, such as an EC2 load balancer or HAProxy, etc., where the request comes to the load balancer and the load balancer forwards it to the web server.

If you view the Apache access log, you will only see the private IP address of a load balancer, something similar to the below.


172.31.xx.xx – – [04/Jan/2017:13:35:00 +0000] “GET / HTTP/1.1” 301 588 “-” “Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36”
172.31.xx.xx – – [04/Jan/2017:13:35:00 +0000] “GET / HTTP/1.1” 301 588 “-” “Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36”

It will be hard to find out where the origin IP address comes from in case the logs has private IP address. Here comes the post explaining how to log the remote IP address in access.log

Lets find how many LogFormat are available on your web server.

grep LogFormat /etc/apache2/apache2.conf

LogFormat “%v:%p %h %l %u %t \”%r\” %>s %O \”%{Referer}i\” \”%{User-Agent}i\”” vhost_combined
LogFormat “%h %l %u %t \”%r\” %>s %O \”%{Referer}i\” \”%{User-Agent}i\”” combined
LogFormat “%h %l %u %t \”%r\” %>s %O” common
LogFormat “%{Referer}i -> %U” referer
LogFormat “%{User-agent}i” agent

In the above output, the highlighted items are various log formats available that we can use.

Now, we have to find out which log format the domain is using. We assume that the domain configuration /etc/apache2/sites-enabled/000-default.conf.

grep CustomLog /etc/apache2/sites-enabled/000-default.conf

CustomLog ${APACHE_LOG_DIR}/access.log combined

In the above example, the combined log format is used. So, the access.log file will be in the format of “%h %l %u %t \”%r\” %>s %O \”%{Referer}i\” \”%{User-Agent}i\”” as mentioned above.

Now, we are going to create a new logformat and add it to the domain configuration. Open the file /etc/apache2/apache2.conf and append the following line in the LogFormat section

vi /etc/apache2/apache2.conf

LogFormat “%{X-Forwarded-For}i %h %l %u %t \”%r\” %s %b \”%{Referer}i\” \”%{User-agent}i\”” combined-forwarded

Note down the variable(combined-forwarded) that you are using while setting up the new log format. We will be using this variable while setting up a custom log.

%{X-Forwarded-For} – This is a custom HTTP request header developed by the Squid development team. The X-Forwarded-For header reads the IP address and passes it along upstream in the http request.

Open the domain configuration and modify the custom log section to use the newly created logformat.

vi /etc/apache2/sites-enabled/000-default.conf

 CustomLog ${APACHE_LOG_DIR}/access.log combined-forwarded

Check for any syntax errors and make sure it reports Syntax Ok

apachectl -t

Restart the web server for the changes to take effect.

systemctl restart apache2

Access the domain or IP address in the browser(http://IPADDRESS). Check the logs on the server. We will get the origin IP address as well as the load balancer IP address.

tail -f /var/log/apache2/access.log


xx.xx.xx.xx 172.31.xx.xx – – [05/Jan/2017:06:52:50 +0000] “GET / HTTP/1.1” 200 38439 “

Conclusion

By creating a custom Apache LogFormat that includes the X-Forwarded-For header, you can record the original client IP address in the Apache access logs when the web server is behind a load balancer. This provides better visibility into the actual source of incoming requests and can be useful for troubleshooting, monitoring, security analysis, and access-log investigation. After applying the configuration, always verify the Apache syntax before restarting the service and confirm the updated log format by generating a test request.

FAQs

1. Why does Apache log the load balancer IP instead of the client IP?
When Apache is behind a load balancer, the load balancer forwards the request to the web server. Apache may therefore record the load balancer’s IP address as the source IP.

2. What is X-Forwarded-For?
X-Forwarded-For is an HTTP request header used to pass the original client’s IP address through a proxy or load balancer to the backend web server.

3. Can this configuration be used with multiple domains?
Yes. A separate CustomLog configuration can be applied to individual Apache virtual hosts if different domains require custom access-log formats.

How to Configure Country-Based Redirection in Nginx Behind a Load Balancer

Redirect http to https on nginx behind load balancers

Talk to our experts

Looking for the right technology solution for your business?. Our experts can help with web hosting, domain registration, DevOps and cloud, software development, web applications, mobile applications, and enterprise solutions. Get in touch with our team here.

admin

Our team has expertise across software and web development, WordPress, e-commerce, mobile applications, UI/UX, cloud and infrastructure, DevOps, CI/CD, API integration, security, testing, automation, and technical support. The team also works with AI-based software solutions, LLMs, AI workflows, AI agents, and intelligent application development to help businesses automate processes and build smarter digital solutions. We focus on developing, deploying, maintaining, and optimising secure, scalable, and reliable technology solutions while helping businesses adopt modern technologies and drive digital transformation.

Leave a Reply

Scroll to Top