DocsWebsite statistics

Website statistics

Read a website's visitors, page views, bandwidth, errors and live traffic from its server logs, block abusive IPs, and check your account's resource usage.

ZoPanel shows traffic statistics for every website on its Analytics tab, computed from the web server's access logs. There is no tracking script and no cookie, so nothing is added to your pages and visitors are not tracked across sites. The Resources page shows what the whole hosting account uses: disk, CPU, memory, monthly bandwidth and the package limits.

Where the numbers come from

nginx writes one line per request to the website's access log, /var/log/zopanel/sites/<domain>.access.log (standard combined format). When you open the Analytics tab, ZoPanel reads that log and its rotated copies and counts the lines. Nothing is stored in a separate analytics database.

Logs are rotated daily, compressed, and 31 rotated files are kept, so about a month of history exists at any time and the 30 days view is complete. On a server updated from an older version, which kept 15 days, the view fills up over the following weeks.

Every request is logged, static files included (images, CSS, JS, fonts, videos), so they count in requests and bandwidth.

Read the Analytics tab

  1. Open Websites, click the website and open the Analytics tab.
  2. Choose the period: Live, 24h, 7 days or 30 days. 7 days is the default.

Summary cards

Card What it counts
Visitors Distinct visitors, where a visitor is one IP address with one browser (user agent). Bots are excluded.
Page views Successful (2xx or 3xx) requests by people for pages, not for static assets or /.well-known/ files. The small line shows the total number of requests, bots included.
Bandwidth Bytes of response bodies sent, for all logged requests (headers are not counted).
Errors Server errors (5xx) / client errors (4xx), and the number of requests made by bots.

A request counts as a bot when its user agent looks like a crawler or a tool: names containing bot, crawl, spider, curl, wget, python-requests, Go-http-client, headless, uptime monitors, load-testing tools, or an empty user agent.

Traffic chart

The Traffic chart shows Visitors (solid) and requests (dashed), per hour for 24h and per day for 7 days and 30 days.

Top lists

List Content
Top pages The 15 most viewed paths. Query strings are removed, so /product?id=1 and /product?id=2 count as /product.
Referrers The 10 most frequent outside sites that sent visitors (host names only). Links from the website's own domain are ignored.
Top IPs The 10 addresses with the most requests from people, with a block button.
Browsers Chrome, Safari, Firefox, Edge, Opera, Cốc Cốc, Samsung Internet, Other.
Operating systems Android, iOS, Windows, macOS, Linux, Other.
Status codes The 10 most frequent HTTP status codes, bots included.

Live view

Live refreshes every 5 seconds and reads the end of the current log:

  • Online now: distinct visitors (bots excluded) in the last 5 minutes.
  • Requests this minute and Requests (30 min).
  • Live traffic: requests per minute over the last 30 minutes.
  • Top IPs (5 minutes): the busiest addresses right now, bots included, with a block button.
  • Latest requests: the 50 most recent requests with time, IP, method and path, status, and a bot badge.

Use it to see a traffic spike, a crawler or an attack as it happens.

Block an IP address

Next to an address in Top IPs or Top IPs (5 minutes), click the block icon (Block this IP on the website) and confirm. To block an address or range by hand, use the Blocked IPs on this website card at the bottom of the tab: enter an IP or a CIDR range such as 198.51.100.0/24 and click Block. Click Unblock to remove it.

nginx answers 403 to every request from a blocked address, on this website only. A website can block up to 500 addresses or ranges. You cannot block the address you are using, and a range that covers every address (0.0.0.0/0) is refused. When the administrator has turned on Websites behind Cloudflare in Settings, ZoPanel sees and blocks the visitor's real IP, not Cloudflare's.

Administrators also see Block this IP on the whole server (firewall). It drops every connection from that address to every service (web, SSH, mail); unblock it in Security → Firewall.

Privacy

  • No script, cookie or fingerprint is added to your pages. The statistics only use what the web server already logs.
  • Access logs contain visitor IP addresses and user agents, which can be personal data under laws such as the GDPR. They stay on the server and are deleted by the daily rotation after about a month.
  • Only people who can open the website in the panel see its statistics: the account owner, its administrator or reseller, and members of the website (View only members included). See Website members.

Monthly bandwidth

The account's bandwidth is the sum of the Bandwidth of all its websites in the current calendar month, from the same access logs, collected every hour. It resets on the 1st of each month. Customers see it as Bandwidth this month on the Resources page.

When the package sets Monthly bandwidth (MB), the customer is warned at 80% and 100%, and the administrator or reseller is told at 100%. What happens past 100% is set by the administrator in Settings → General → When an account uses up its monthly bandwidth: Only notify, or Suspend until next month (or a bigger plan). A suspension made for bandwidth is lifted automatically on the 1st of the next month or when the package is raised. See Packages and limits.

Account resources

Resources (in the Account menu for customers) shows the package and what the account uses:

Card Content
Storage and mail Disk space, Files (inodes) when disk quotas are on, and Emails sent this hour. Without quotas, disk usage is measured hourly.
Right now CPU, Memory and Processes of all websites and apps of the account, plus disk read/write since start and processes stopped for exceeding memory.
Plan usage Websites, databases, mailboxes, FTP accounts, cron jobs and Bandwidth this month against the package limits.
Usage history CPU (% of one core) and memory over 24 h, 7 days, 30 days or 1 year: average, and peak (dashed).
Disk usage Click folders to find what takes space in the home folder.

Bars turn orange at 75% and red at 90% of a limit. Usage history is recorded every 5 minutes; 5-minute points are kept for 3 days, hourly figures for about 400 days. Administrators and resellers open the same page for any account from Accounts.

Uptime: the Domains tab of a website shows its availability over 24 hours, 7 and 30 days, and a bar per day for the last 90 days. ZoPanel checks each active website about every 3 minutes.

Troubleshooting

Problem Cause and fix
No data yet The website has had no logged traffic in the period, or the domain does not point to this server yet. Open the website in a browser and check Live.
Visitors seem low compared with Google Analytics Bots are excluded, and one IP with one browser counts once (a whole office behind one IP may count as one visitor). JavaScript analytics count differently; neither is "wrong".
30 days shows only about two weeks The server was updated from a version that kept 15 days of logs; the view fills up within a month (see above).
Bandwidth looks smaller than expected Responses cached at a CDN (such as Cloudflare) never reach the server, so they are not counted.
The tab is slow or times out on a busy website Reading 30 days of a large log takes time; the panel waits up to 60 seconds. Use 7 days or 24h.
All visitors show Cloudflare addresses Ask the administrator to turn on Websites behind Cloudflare in Settings. It applies to new log lines only.
this would block your own address (…) You tried to block the IP or range you are connected from.
invalid IP or range Enter one IPv4/IPv6 address or a CIDR range.
this feature is not included in your hosting package on logs The package leaves out logs; ask your provider.

← Website members Node.js and Python apps →