{"id":971,"date":"2017-01-05T12:36:25","date_gmt":"2017-01-05T07:06:25","guid":{"rendered":"https:\/\/pheonixsolutions.com\/blog\/?p=971"},"modified":"2026-09-28T19:27:50","modified_gmt":"2026-09-28T13:57:50","slug":"enable-remote-ip-address-logging-apache2-behind-load-balancer","status":"publish","type":"post","link":"https:\/\/pheonixsolutions.com\/blog\/enable-remote-ip-address-logging-apache2-behind-load-balancer\/","title":{"rendered":"How to Log the Client IP Address in Apache Behind a Load Balancer"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Post Date:<\/strong> January 5, 2016<br><strong>Last Updated:<\/strong> September 28, 2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When an Apache web server is placed behind a load balancer, the Apache access logs may record the load balancer&#8217;s private IP address instead of the original client&#8217;s IP address. This can make it difficult to identify the actual source of incoming requests. By configuring Apache to log the <code>X-Forwarded-For<\/code> header, you can capture the original client IP address along with the load balancer IP address. This article explains how to configure Apache 2.4 to log the originating client IP address when the web server is behind a load balancer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before implementing this configuration, ensure the following requirements are met:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Apache HTTP Server 2.4 is installed and running.<\/li>\n\n\n\n<li>The web server is running on Ubuntu or a similar Linux distribution.<\/li>\n\n\n\n<li>You have root or sudo access to the server.<\/li>\n\n\n\n<li>The Apache configuration files are located under <code>\/etc\/apache2<\/code>.<\/li>\n\n\n\n<li>The web server is behind a load balancer such as an AWS\/EC2 load balancer or HAProxy.<\/li>\n\n\n\n<li>The load balancer is configured to forward the client&#8217;s original IP address using the <code>X-Forwarded-For<\/code> HTTP header.<\/li>\n\n\n\n<li>You have permission to modify Apache configuration files and restart the Apache service.<\/li>\n<\/ul>\n\n\n<h2>Implementation<\/h2>\n<p>By default, Apache logs the IP address where the request comes from. Consider a scenario where the web server (in our post, we deal with Apache) is behind a load balancer, such as an EC2 load balancer or HAProxy, etc., where the request comes to the load balancer and the load balancer forwards it to the web server.<\/p>\n<p>If you view the Apache access log, you will only see the private IP address of a load balancer, something similar to the below.<\/p>\n<hr \/>\n<p>172.31.xx.xx &#8211; &#8211; [04\/Jan\/2017:13:35:00 +0000] &#8220;GET \/ HTTP\/1.1&#8221; 301 588 &#8220;-&#8221; &#8220;Mozilla\/5.0 (Windows NT 6.1) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/55.0.2883.87 Safari\/537.36&#8221;<br \/>172.31.xx.xx &#8211; &#8211; [04\/Jan\/2017:13:35:00 +0000] &#8220;GET \/ HTTP\/1.1&#8221; 301 588 &#8220;-&#8221; &#8220;Mozilla\/5.0 (Windows NT 6.1) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/55.0.2883.87 Safari\/537.36&#8221;<\/p>\n<p>It will be hard to find out where the origin IP address comes from in case the logs has private IP address. Here comes the post explaining how to log the remote IP address in <em>access.log<\/em><\/p>\n<p>Lets find how many\u00a0<em>LogFormat are <\/em>available on your web server.<\/p>\n<p><code>grep LogFormat \/etc\/apache2\/apache2.conf<\/code><\/p>\n<blockquote>\n<p>LogFormat &#8220;%v:%p %h %l %u %t \\&#8221;%r\\&#8221; %&gt;s %O \\&#8221;%{Referer}i\\&#8221; \\&#8221;%{User-Agent}i\\&#8221;&#8221; <span style=\"color: #ff6600;\">vhost_combined<\/span><br \/>LogFormat &#8220;%h %l %u %t \\&#8221;%r\\&#8221; %&gt;s %O \\&#8221;%{Referer}i\\&#8221; \\&#8221;%{User-Agent}i\\&#8221;&#8221; <span style=\"color: #ff6600;\">combined<\/span><br \/>LogFormat &#8220;%h %l %u %t \\&#8221;%r\\&#8221; %&gt;s %O&#8221; <span style=\"color: #ff6600;\">common<\/span><br \/>LogFormat &#8220;%{Referer}i -&gt; %U&#8221; <span style=\"color: #ff6600;\">referer<\/span><br \/>LogFormat &#8220;%{User-agent}i&#8221; <span style=\"color: #ff6600;\">agent<\/span><\/p>\n<\/blockquote>\n<p>In the above output, the highlighted items are various log formats available that we can use.<\/p>\n<p>Now, we have to find out which log format the domain is using. We assume that the domain configuration <em>\/etc\/apache2\/sites-enabled\/000-default.conf.<\/em><\/p>\n<p><code>grep CustomLog \/etc\/apache2\/sites-enabled\/000-default.conf<\/code><\/p>\n<blockquote>\n<p>CustomLog ${APACHE_LOG_DIR}\/access.log <span style=\"color: #ff6600;\">combined<\/span><\/p>\n<\/blockquote>\n<p>In the above example, the <em>combined<\/em> log format is used. So, the <strong>access.log\u00a0<\/strong>file will be in the format of &#8220;%h %l %u %t \\&#8221;%r\\&#8221; %&gt;s %O \\&#8221;%{Referer}i\\&#8221; \\&#8221;%{User-Agent}i\\&#8221;&#8221; as mentioned above.<\/p>\n<p>Now, we are going to create a new logformat and add it to the domain configuration. Open the file <em>\/etc\/apache2\/apache2.conf\u00a0<\/em>and append the following line in the <em>LogFormat <\/em>section<\/p>\n<p><code>vi \/etc\/apache2\/apache2.conf<\/code><\/p>\n<blockquote>\n<p>LogFormat &#8220;%{X-Forwarded-For}i %h %l %u %t \\&#8221;%r\\&#8221; %s %b \\&#8221;%{Referer}i\\&#8221; \\&#8221;%{User-agent}i\\&#8221;&#8221; <span style=\"color: #ff6600;\">combined-forwarded<\/span><\/p>\n<\/blockquote>\n<p>Note down the variable(combined-forwarded) that you are using while setting up the new log format. We will be using this variable while setting up a custom log.<\/p>\n<p>%{X-Forwarded-For} &#8211; This is a custom HTTP request header developed by the Squid development team. The X-Forwarded-For header reads the IP address and passes it along upstream in the http request.<\/p>\n<p>Open the domain configuration and modify the custom log section to use the newly created logformat.<\/p>\n<p><code>vi\u00a0\/etc\/apache2\/sites-enabled\/000-default.conf<\/code><\/p>\n<blockquote>\n<p>\u00a0CustomLog ${APACHE_LOG_DIR}\/access.log <span style=\"color: #ff6600;\">combined-forwarded<\/span><\/p>\n<\/blockquote>\n<p>Check for any syntax errors and make sure it reports <strong>Syntax Ok<\/strong><\/p>\n<p><code>apachectl -t<\/code><\/p>\n<p>Restart the web server for the changes to take effect.<\/p>\n<p><code>systemctl restart apache2<\/code><\/p>\n<p>Access the domain or IP address in the browser(http:\/\/IPADDRESS). Check the logs on the server. We will get the origin IP address as well as the load balancer IP address.<\/p>\n<p><code>tail -f \/var\/log\/apache2\/access.log<\/code><\/p>\n<hr \/>\n<p>xx.xx.xx.xx 172.31.xx.xx &#8211; &#8211; [05\/Jan\/2017:06:52:50 +0000] &#8220;GET \/\u00a0HTTP\/1.1&#8221; 200 38439 &#8220;<\/p>\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By creating a custom Apache <code>LogFormat<\/code> that includes the <code>X-Forwarded-For<\/code> header, you can record the original client IP address in the Apache access logs when the web server is behind a load balancer. This provides better visibility into the actual source of incoming requests and can be useful for troubleshooting, monitoring, security analysis, and access-log investigation. After applying the configuration, always verify the Apache syntax before restarting the service and confirm the updated log format by generating a test request.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Why does Apache log the load balancer IP instead of the client IP?<\/strong><br>When Apache is behind a load balancer, the load balancer forwards the request to the web server. Apache may therefore record the load balancer&#8217;s IP address as the source IP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. What is <code>X-Forwarded-For<\/code>?<\/strong><br><code>X-Forwarded-For<\/code> is an HTTP request header used to pass the original client&#8217;s IP address through a proxy or load balancer to the backend web server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Can this configuration be used with multiple domains?<\/strong><br>Yes. A separate <code>CustomLog<\/code> configuration can be applied to individual Apache virtual hosts if different domains require custom access-log formats.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related Articles<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/country-based-redirection-nginx-behind-load-balancergeo-location-based-redirection\/\">How to Configure Country-Based Redirection in Nginx Behind a Load Balancer<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/redirect-http-https-nginx-behind-load-balancers\/\">Redirect http to https on nginx behind load balancers<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Talk to our experts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Looking for the right technology solution for your business?. Our experts can help with\u00a0web hosting, domain registration, DevOps and cloud, software development, web applications, mobile applications, and enterprise solutions. Get in touch with our team\u00a0<a href=\"https:\/\/pheonixsolutions.com\/contact\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Post Date: January 5, 2016Last Updated: September 28, 2026 Introduction When an Apache web server is placed behind a load [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1022],"tags":[278,261,159],"class_list":["post-971","post","type-post","status-publish","format-standard","hentry","category-web-architecture","tag-apache","tag-linux","tag-webserver","psol-cat-web-architecture"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/phn2x7-fF","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/971","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/comments?post=971"}],"version-history":[{"count":2,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/971\/revisions"}],"predecessor-version":[{"id":11967,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/971\/revisions\/11967"}],"wp:attachment":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/media?parent=971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/categories?post=971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/tags?post=971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}