Appearance
Logs
The platform records what it does so you can audit and troubleshoot. There are two scopes: project Logs (HTTP and audit events for one project) and global diagnostics (platform health and app log via Status).
Project log views support filtering and update automatically.
Project logs
Open a project and choose Logs in the sidebar. It has two tabs.
Scan Activity
Every action taken during the project's scans — most importantly, the HTTP requests made to targets — so you can reconstruct exactly what the platform did. Columns:
- Time — when it happened.
- Scan — the scan's short ID (hover for the full ID).
- Level —
debug,info,warn, orerror. - Category —
http,lifecycle,module,worker, orerror. Bustah degradation notes also appear asbustah_degraded(warn level) when a scan's coverage was reduced; the scan listdegradedbadge summarizes the first note — see Scans → Degraded scans. - Detail — the log message. Nikto and Bustah request lines name the protocol that was actually negotiated (
GET http://host/path HTTP/2), so two probes that differ only in protocol are distinguishable. An unknown protocol prints nothing rather than an assumedHTTP/1.1. Crawl rollup lines carry no protocol.
If a Nikto scan cannot resolve a hostname for the probes that need an IP (the extra Host=<IP> header variant, IP-named backup-file guesses), a warn row names the host and which probes were skipped. The rest of the scan continues. A proxied scan does not look up the target itself, so it does not write that note.
Filter by Level and Category. This view tails live as scans run.
Per-scan activity is also available inside the scan detail modal (Activity tab) from any scan list or Active Jobs — see Scans → Scan detail modal. That viewer paginates with Load older; if the scan was deleted while the modal is open, the fetch fails with a clear HTTP error instead of showing stale rows.
Crawl traffic to out-of-scope third-party hosts (CDN scripts, analytics, etc.) is still logged for audit, with a [third-party] marker in the detail line so you can distinguish it from in-scope target requests.
Requests the scanner refuses because of the address-tier rule are logged too — named by host, with the reason — not dropped silently.
Events
A higher-level audit trail of changes in the project — for example when a scan, target, finding, host, or proxy is created or modified. Columns:
- Time, Type (the entity), Action, Actor, and a Detail payload.
Filter by Type.
Global app log (Status)
Open Status in the lower (global) part of the sidebar. It opens /nikto-diag in a new tab with build/runtime diagnostics and a live App Log inset at the bottom of the page.
Columns in the inset: Time, Level (debug/info/warn/error), Component, and Message. The view tails new rows automatically and offers Load older for pagination.
Use this for platform-wide issues (workers, database, browser sidecar) that are not tied to one project's scan activity.
Auditing a scan
Scan Activity records every request to a target: URL, method, order, and result.