My log_format allows to store such fields at logs:
upstream_addr http_x_forwarded_for remote_addr
All of them have the same addresses in many cases.
What field will contain the real IP address I need to monitor I can block in case of a problem?
What are the differences between them in simple words and why there’re three exactly same fields value?