- Intermediate
- 5 min read
- Updated 2026-10-09
Export the access log as CSV
What ClearDeck's access-log CSV actually contains, why it is UTF-8 with a BOM, and how to sort and filter it to find the apps and trackers that try hardest to reach out.
ClearDeck’s access log is a rolling record of what your apps tried to reach while protection was running. It is readable on the phone, but it is not meant to be read there for long — the app keeps only a bounded window of recent attempts. Tools → Export access log writes the current session out as a CSV file, and that is where the log becomes genuinely useful: you can sort it, filter it, and compare two exports in any spreadsheet.
Export before protection stops
Where to find it
There are two entry points. They produce the same format on different scopes:
- Tools → Export access log exports the whole session, for every app.
- An app’s detail page has Export log, which exports that app’s records. Reaching it: open the Dashboard, tap the Connections figure to open the app list, then open an app.
The export is written to a file and offered to the system’s share sheet, so you can save it to Downloads, mail it to yourself, or send it to a spreadsheet app directly.
What is in the file
“this session’s attempts” means exactly that: everything recorded since protection started, for every app, with blocked requests included. It is not a lifetime history and it is not only blocked traffic — allowed requests are in there too, which is what makes the file useful for more than counting blocks.
Each row is one attempt. A request that was blocked and the same request retried a minute later appear as two rows. There are no summary rows and no totals; every number you want comes from aggregating the rows yourself.
The format
The file is CSV, following RFC 4180, encoded as UTF-8 with a BOM.
The BOM is the part that matters in practice. Excel on Windows does not assume a
CSV is UTF-8; when there is no byte-order mark it falls back to your system’s
local codepage, and any non-ASCII text turns into mojibake. Chinese app names
are exactly the kind of text this wrecks — a perfectly readable 微信 can arrive as
a row of question marks. The BOM is what tells Excel to read the file as UTF-8
so the names survive the trip. (If you open the file in Google Sheets, Numbers,
LibreOffice, or pandas.read_csv, the BOM is handled for you and you can ignore
this.)
The filename follows this pattern:
cleardeck-access-<subject>-<yyyyMMdd-HHmm>.csv
The <subject> segment identifies what was exported — the whole session when
you export from Tools, or the app whose detail page you exported from. The
timestamp is when the export was taken, in yyyyMMdd-HHmm form, so repeated
exports sort in chronological order in a folder listing.
The columns
Headers are written in the language the app is currently using.
| Column | English header | Chinese header | What it holds |
|---|---|---|---|
| 1 | Package |
应用包名 |
The Android package name, e.g. com.example.app |
| 2 | App |
应用名称 |
The app’s display name, as shown in the launcher |
| 3 | Time |
时间 |
When the attempt happened |
| 4 | Host |
域名 |
The host the app tried to reach |
| 5 | Result |
结果 |
Blocked / Allowed (拦截 / 放行) |
Package is the stable identifier; App is the human-readable name. Keep both
in mind: two apps can share a display name, while a package name is unique. If a
package name looks unfamiliar, it may be a system component or an app you
uninstalled — the request was still attempted.
Turning it into answers
The export is plain tabular data, so the analysis is ordinary spreadsheet work. Three recipes cover most of what people actually want to know.
Find the noisiest tracker. Sort the Host column. The hosts that repeat
most often are the ones your apps are hitting constantly. A single host
appearing hundreds of times across several apps is usually a shared
analytics or ad endpoint rather than something you asked for.
Find which app tries hardest to phone home. Filter Result to Blocked,
then group or count by App. The app with the most blocked rows is the one
generating the most traffic the rules decided to stop. Compare it with the same
app’s row count before you installed ClearDeck’s modules, if you have an older
export.
See what changed. Export once, then change one thing — turn off a module,
add a block or allow rule from the app’s access log, or just use the phone
differently for a day — and export again. Diff the two files on the Host
column: hosts that vanished are the ones the change stopped. This is the most
reliable way to tell whether a switch you flipped actually did anything.
Record more next time
The export can only contain what the app kept. The Access log window in Settings controls how many recent attempts are retained per app:
| Setting | Values | Default |
|---|---|---|
| Access log window | 100 / 500 / 1000 / 2000 entries | 500 |
The app explains the trade-off directly: a larger window keeps more history but uses more memory. If you are trying to catch something that happens rarely, raise it before you reproduce the problem; if memory matters more than detail, lower it. The per-app view this feeds is covered in the app list and access log.
Next
- Read an app’s access log — Block, Allow, and what the filters do before you export
- Read the dashboard — the counts the export sits behind
- What leaves your phone — why the traffic this file describes never leaves the device
This guide is also available in 简体中文