**English** · [Français](presets.fr.md) # Color tag presets In **Settings › Filters**, the **+ Preset…** menu adds a group of ready-made color tags in one click. Added tags are ordinary tags: you can change their color, pattern or options, or delete them. A tag whose pattern is already in the list is not added twice. The list comes from a text file, [`presets.json`](../presets.json), built into LogStream. You can replace it with your own file (see [Using your own file](#using-your-own-file)). ## Built-in presets ### HTTP/HTTPS These presets read access logs from nginx and Apache (common and combined formats), Traefik (CLF and JSON), Caddy (JSON) and HAProxy (`option httplog`). | Preset | Tags | What gets colored | | --- | --- | --- | | HTTP status codes | `HTTP 2xx` green, `HTTP 3xx` blue, `HTTP 4xx` orange, `HTTP 5xx` red | only the status code, e.g. `404` in `"GET /x HTTP/1.1" 404 153`, `"status":404` or `"DownstreamStatus":404`. Other numbers on the line (size, path) are left alone. | | HTTP methods | `GET/HEAD/OPTIONS` grey, `POST/PUT/PATCH` purple, `DELETE` pink | only the method in `"GET /path` or `"method":"GET"` (upper case only) | | Probes and attacks | `probes / attacks` | `wp-login.php`, `xmlrpc.php`, `wp-admin`, `phpmyadmin`, `/.env`, `/.git`, `/.aws`, `/cgi-bin/`, `../`, `%2e%2e`, `/etc/passwd`, `…)`, colors only that part of the match, as the HTTP presets do with `(?5\\d\\d)`.