Synthetic worked example · Maintained by Data Demon Systems

Find 5xx Errors in an NGINX Access Log

Find HTTP 500 and 503 requests in a synthetic NGINX access log. Filter, inspect and export matching records locally with Data Demon Log Viewer.

Find the failed requests

  1. Download the synthetic fixture below, then open Log Viewer and choose that local file. Alternatively, use “Open example in tool” to open the shared example immediately.
  2. Check that the format is NGINX / Apache combined. Override the parser if automatic detection selects a different format.
  3. Open Advanced evidence filters, select 5xx in Status, then press Apply filters under Search and filters. The “HTTP failures” shortcut includes both 4xx and 5xx responses, so it is not the same filter.
  4. Inspect the two matching records. The 503 response is GET /api/jobs; the 500 response is GET /api/report.
  5. Select Preview export, review its coverage, then Confirm and export. Reopen the derivative to check that it contains only those two records.

Expected results

The input has ten records: seven 2xx responses, one 404 response and two 5xx responses. Filtering by 5xx must return exactly records 4 and 8. A 404 is a client-error response and must not appear in this filter.

The tests run this fixture through the same streaming parser and status filter as the browser tool. Data Demon Systems maintains the fixture; all addresses are from the documentation range 192.0.2.0/24 and the host is synthetic.

What an access log can and cannot tell you

A 5xx status identifies a failed HTTP response; it does not establish the underlying cause. Correlate its time and path with application and upstream logs before drawing conclusions.

This example uses the combined access-log format, not every custom NGINX log format. Ten records demonstrate filtering correctness, not large-file performance. The viewer supports source files up to 4 GiB; actual timings depend on the browser, machine and input. Browser fallback Blob exports are capped at 100 MB.

Your source remains local and unchanged. Real logs may contain identifiers, tokens or personal data: choose redaction categories explicitly and review the exported derivative before sharing it. Detection is not a guarantee that all sensitive data was found.

Log & Diagnostic Data Redactor is the next step when your task is preparing a diagnostic derivative for review.

Complete synthetic fixture

192.0.2.10 - - [02/Oct/2026:09:12:00 +0000] "GET /health HTTP/1.1" 200 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.11 - - [02/Oct/2026:09:12:01 +0000] "GET /products HTTP/1.1" 200 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.12 - - [02/Oct/2026:09:12:02 +0000] "GET /api/jobs HTTP/1.1" 202 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.13 - - [02/Oct/2026:09:12:03 +0000] "GET /api/jobs HTTP/1.1" 503 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.14 - - [02/Oct/2026:09:12:04 +0000] "GET /assets/app.css HTTP/1.1" 200 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.15 - - [02/Oct/2026:09:12:05 +0000] "GET /missing HTTP/1.1" 404 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.16 - - [02/Oct/2026:09:12:06 +0000] "GET /api/health HTTP/1.1" 200 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.17 - - [02/Oct/2026:09:12:07 +0000] "GET /api/report HTTP/1.1" 500 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.18 - - [02/Oct/2026:09:12:08 +0000] "GET /products HTTP/1.1" 200 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"
192.0.2.19 - - [02/Oct/2026:09:12:09 +0000] "GET /health HTTP/1.1" 204 42 "https://console.example.test/" "DataDemonSyntheticFixture/1.0"