Before configuring what to log, understand what must never be logged. On a Tor hidden service, all connections arrive from 127.0.0.1 (the local Tor daemon), so traditional IP logging is already neutralized. However, several other data points can deanonymize visitors or compromise your service:
- User-Agent strings - Tor Browser uses a standardized User-Agent, but logging it can still fingerprint non-standard Tor clients or reveal when a visitor is not using Tor Browser.
- Exact timestamps - Precise request timestamps combined with traffic analysis can correlate visitors across multiple .onion services. Round timestamps to the nearest hour or day.
- Request paths with query parameters - Query strings may contain search terms, session IDs, or other identifying information. Log paths only if necessary, and strip query parameters.
- Referrer headers - These reveal which page the user came from, potentially linking their activity across multiple .onion sites.
- Cookie values - Session cookies or tracking cookies should never appear in logs.
The principle is data minimization - log only what you absolutely need for operational purposes, and nothing that could identify or track individual visitors.