Skip to content

Log File Provision

Service Description v7.0 | 31.07.2026

Would you like to continuously analyze and optimize your digital offering individually, or evaluate conspicuous features independently in order to optimally improve the content structures of your offering through transparent insight?

You'll receive data privacy-compliant raw log file data with various parameters, such as document referrer, browser type, and INFOnline-typical key figures like code and offer identifier.

In other words: You always have your raw data right in view!

Scope of service

As part of the Log File Provision service, you are provided with raw logfile data that contains information about the measurement pulses that enter the measurement system for your digital offer. The following parameters are made available to you: document referrer, pixel referrer, browser type, resolution, device information, and the INFOnline-typical key figures such as code, offer identifier and comment.

The data is accessed via an HTTP API from which you can download the log files manually or automatically using curl or a comparable HTTP client.

Order

The Log File Provision service is ordered by e-mail to support@infonline.de. The service can be booked for any registered digital offering.

Provision

  • The raw log data is provided via an HTTP API at https://log.ioam.de/<offer_identifier>.
  • In the setup or confirmation e-mail, the client receives the associated credentials (username and password for HTTP Basic Auth).
  • The username corresponds to the offer identifier (site_id).

The service as well as the mail with all necessary information will be provided within 3 working days.

Note

Only one concurrent data retrieval per offer identifier is possible. If a download is already in progress, HTTP status code 429 (Too Many Requests) is returned.

Data availability

  • The log data is available with a delay of approximately 10 minutes after the end of the requested time range. If a time range is not yet available, HTTP status code 503 is returned with a Retry-After header.
  • The log file data is stored for a maximum of 30 days, after which the data is no longer available.
  • A separate data backup outside this period does not take place.
  • The availability of the log file provision is 99 percent.
  • However, there is no entitlement to subsequent delivery of log file data in the event of technical failures.

Term

The service term applies from the time of setup until the service is terminated or the metering contract for the corresponding digital offer is terminated.

The contract always starts on the 1st of a month; the term is 1 year.

Cancellation

The notice period is always 3 months to the end of the term. It is sufficient to send an e-mail with the reason for termination to the following address: support@infonline.de. If you cancel the measurement of the digital offer, the service will automatically expire.

Costs

Invoicing takes place quarterly in advance. Where the start of the term does not coincide with the start of a quarter, a pro-rata invoice may be issued.

A monthly base fee of 200.00 euros net is charged for the "Log File Provision" service. This covers the use of up to four offer identifiers. For each additional activated offer identifier, an additional monthly fee of 40.00 euros net is charged. The total monthly fee therefore depends on the number of offer identifiers activated in each case.

Technical information

Log file delivery

The log file data is accessed via an HTTP API at:

1
https://log.ioam.de/<offer_identifier>

Authentication is performed via HTTP Basic Auth. The username must match the offer identifier, the password is provided during setup. Data transfer is encrypted via TLS.

Download options

Full day (without time parameter):

1
2
3
curl -u <offer_identifier>:<password> \
  "https://log.ioam.de/<offer_identifier>?date=2026-03-01" \
  -o "<offer_identifier>_2026-03-01.gz"

5-minute time window (with time parameter):

1
2
3
curl -u <offer_identifier>:<password> \
  "https://log.ioam.de/<offer_identifier>?date=2026-03-01&time=10:05" \
  -o "<offer_identifier>_$(date -d '2026-03-01 10:05 UTC' +%s).gz"

The time parameter specifies the end of the 5-minute window. time=10:05 returns data from 10:00 to 10:05 UTC. The value must be a multiple of 5 minutes (e.g. 10:00, 10:05, 10:10, ...).

The special case time=00:00 returns the time window 23:55–00:00 of the previous day.

If the date parameter is omitted, yesterday's date is used by default.

Parameters

Parameter Required Format Description
offer_identifier Yes (URL path) [a-zA-Z0-9_-]+ Offer identifier (must match Basic Auth username)
date No YYYY-MM-DD Date of the data. Default: yesterday. Maximum 30 days in the past.
time No HH:MM 5-minute time window. Specifies the end of the window. Must be a multiple of 5. If omitted, the full day is returned.

Response

  • Content-Type: application/gzip
  • Content-Disposition: attachment; filename="<offer_identifier>_YYYYMMDD_HHMM.log.gz"
  • Body: gzip-compressed, pipe-delimited log lines (14 fields per line)
  • HHMM denotes the start of the delivered time window, not the time parameter: time=10:05 returns <offer_identifier>_20260301_1000.log.gz. For the special case time=00:00 the filename carries the previous day's date and 2355; for a full-day request it is 0000.

HTTP status codes

Code Meaning Description
200 Success Gzip data stream
400 Bad Request Invalid date, time not a multiple of 5, or date older than 30 days
401 Unauthorized Missing or incorrect credentials
403 Forbidden Username does not match offer identifier
429 Too Many Requests Another download for this offer identifier is already in progress
503 Service Unavailable Data is still being processed (includes Retry-After header in seconds)

Health check

An unauthenticated health check endpoint is available at https://log.ioam.de/health.

Log file data

Data fields in log lines

Each log line contains 14 pipe-delimited (|) fields. Pipe characters within field values are automatically removed.

Example: Excerpt from a downloaded log file

1
1772359472.184000|193.46.63.0| |de.ioam.de|OK|1968a1b2c3d4e5f60718293a40001|ap=0&cb=19680522&cn=de&co=Example%20comment&cp=Startseite&cs=k7eobw&ct=0100000000&dc=web&dntt=0&ep=1801747192&i2=19680522a1b2c3d4e5f60718293a4&i3=nocookie&i5=NGYxYTc4ZDMtM2QyMS00YzhhLTliMDEtOTk4ZGYxYzBhNzcy&id=qpc1so&it=mm&lo=DE%2FNordrhein-Westfalen&lt=1772359472184&mo=1&mv=1.12.0&n1=8&nt=1&ps=lin&pt=CP&sc=yes&st=infonlin&tb=0&uahint=&ur=www.infonline.de&vr=5.6.0&vs=1.3.0&xy=1920x1080x24|i00=1968a1b2c3d4e5f60718293a40001%3B68b4c1a0%3B6a2f7d31|Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36|https://www.infonline.de/leistungen/|19680522|web|OK|OK

Explanation of data fields

No. Field Description Example
1 Timestamp Timestamp of the measurement pulse (Unix timestamp in seconds with microseconds) 1772359472.184000
2 Client IP IP address of the client 193.46.63.0
3 X-Forwarded-For Content of the HTTP header "X-Forwarded-For", usually empty
4 Domain Hostname of the requested measurement system de.ioam.de
5 Status code Status code of the measurement pulse. Contains "OK" plus, where applicable, one or more further codes separated by spaces (see below) OK N4 N9
6 Cookie ID ID consisting of: box number (hex) + random number + timestamp (hex) + cookie serial number 1968a1b2c3d4e5f60718293a40001
7 Parameters Parameters collected by sensor/library (URL-encoded, sorted alphabetically, separated by &) ap=0&cb=19680522&cn=de&co=...
8 Cookie string Value of cookie i00 of the domain "ioam.de" i00=1968a1b2c3d4e5f60718293a40001%3B...
9 User agent User agent string of the browser used Mozilla/5.0 ...
10 Referrer Page URL called by the user (HTTP referrer) https://www.infonline.de/
11 Cube no. Identifier of the measurement system that received the request. Empty for app measurement. 19680522
12 Dimension Type of measurement (currently "web", "mew", "app", "hyb" possible) web
13 Status Validation result (currently always "OK") OK
14 Bot detection Result of automatic bot detection: "OK" = human traffic, "ERR" = bot traffic OK
Note

Compared to the previous log file provision, the data format has the following changes:

  • Parameters (field 7): Parameters are now output sorted alphabetically by key. The order may therefore differ from the previous output.
  • Bot detection (field 14): Instead of the user agent whitelist check, automatic bot detection is now performed. "OK" means human traffic, "ERR" means bot traffic.
  • Cube no. (field 11): The cube number is no longer a sequential server number but a fixed identifier of the measurement system. For app measurement the field stays empty.

Explanation of status codes (field 5)

Field 5 contains "OK" plus, where applicable, one or more further codes separated by spaces (e.g. OK N4 N9). Every delivered log line starts with "OK".

The following codes describe how the measurement pulse was processed and attributed to a client. The list is not exhaustive — further codes may occur, among others from older web sensor versions. Unknown codes should therefore be tolerated when parsing and not validated against a fixed list.

Code Description
OK The measurement pulse was processed normally
N4 No i00 cookie present in the request
N9 Client identified via hash of IP, X-Forwarded-For and user agent, additionally with JavaScript fingerprint
N8 Client identified via hash of IP, X-Forwarded-For and user agent, without JavaScript fingerprint
N6 Multi-identifier (mi=) was adopted
N7 LocalStorage value (ls=) was present
N3 App measurement: UUID from the ae container used
N1 App measurement: no usable UUID found, fallback applies
N24 App measurement: UUID is on the blacklist and was skipped
N11 JavaScript error during the measurement call (reported by the measurement script)

Explanation of parameters (field 7)

The following parameters may be present in field 7. Not all parameters are always available — availability depends on the integration type and web sensor version.

Parameter Description
Public (set by the customer via the web sensor or in the app)
cp= Page code (can also be specified via fp= [Flash], np= [newsletters], xp= [non-counting test])
st= Offer identifier / app identifier for app measurement
Public / Optional (optionally set by customer)
co= Comment field
sc= MCVD (Multistage Client & Visit Detection) activation, Web/MEW only
ie= Customer-provided fingerprint for the client
mc= Transfer value for MCLIENT method
mo= Response mode (no value/1 = blank.gif, 2 = empty script)
cn= Market (country) for which the digital content is primarily measured (default "de"). From web sensor version 5.0.0.
Private (collected by measurement script or library)
cb= Cube number: identifier of the measurement system that delivered the measurement script (usually matches field 11)
cs= Checksum over all transmitted parameters
ev= Event for apps, video and audio measurement
i2= ID of the 1st-party cookie
i3= Information about the 1st-party cookie
id= Browser fingerprint (Jenkins hash of plugin information)
lo= Location as country and state
lt= Local time on client
pt= Pixel type
r2= Unshortened document referrer
rf= Document referrer
ur= Pixel referrer (accessed website of the offer)
u2= Unshortened pixel referrer (only with certain browsers)
vr= Version of the script "iam.js"
xy= Resolution and color depth of client screen
ct= INFOnline consent notation (TCF2.x)
tb= Tab detection status
ap= Google AMP integration flag (0/1). From web sensor version 5.0.0.
fb= Facebook Instant Article integration flag (0/1). From web sensor version 5.0.0.
dc= Distribution channel (web, hyb, ctv). From web sensor version 5.0.0.
it= Integration type (mm = Measurement Manager, sa = Standalone). From web sensor version 5.0.0.
nt= Navigation type based on Performance Navigation API (0–4). From web sensor version 5.0.0.
vs= Data schema version of the measurement request. From web sensor version 5.0.0.
uahint= User-Agent Client Hints
mv= Measurement Manager version. From web sensor version 5.1.0.
i5= Origin identifier, hashed UUIDv4. From web sensor version 5.5.0.
ps= Privacy setting of the measurement call
dntt= Do Not Track signal of the browser
ep= Expiry of the 1st-party cookie
n1= Length of the cookie identifier
Private (added by measurement system)
la= Last occurrence of the cookie
mt= Time of event registration on the IO measurement server
u3= Hash of unshortened pixel referrer
Private / Apps (collected by measurement library only)
ae= [Native app measurement] complex JSON data type (see below)
bo= [Hybrid app measurement] Unix timestamp of DeviceID registration
er= [Hybrid app measurement] Transmitted error
fs= [Hybrid app measurement] Original offer identifier of the web page
ls= [Hybrid app measurement] LSO identifier
mi= [Hybrid app measurement] complex JSON data type (see below)

JSON data fields in app log files

In app measurement, additional data is transmitted by the library in JSON format:

  • ae (native apps): Events in the native part of an app
  • mi (hybrid apps): Events in the hybrid part of an app (e.g. content from web page)

This JSON data is included in the parameters field (field 7) as a URL-encoded JSON string.

JSON data structure:

JSON data structure Description
application [ae] App version details
client [ae, mi] Client details (OS, OS version, country, language, carrier, etc.)
client/screen [ae, mi] Information about the screen resolution of the client
client/uuids [ae, mi] UUIDs of the client (e.g. "advertisingIdentifier" for iOS or "androidId" for Android)
events [ae] OS event that triggered the measurement pulse
library [ae, mi] Information about the version of the measurement library
protocolVersion [ae] Version of the JSON object
stats [ae] Event handling error

Last update: September 10, 2026