Currently (9.0.0.6), when a proxied connection is received the log shows something similar to:
Incoming connection request on HTTPS interface x at accepted from
Cerberus is aware of the X-Forwarded-For header which contains the real client IP, but does not indicate it in this log event. Simply adding “for ” to the end of that log line would be much appreciated.