Short answer: The page sends one request, a time window or a line count, and lets the backend that holds the logs apply it. Docker‘s logs API and Loki‘s query_range both answer with a list of lines. Any further filter selects from that list. It does not start another…
Category: Docker
How Promtail reads the Docker API and pushes logs to Loki
Short answer: Promtail does not open Docker’s log files. It connects to the local Docker socket, lists container ids, and calls the engine logs API with follow. It splits stdout from stderr, removes Docker’s timestamp prefix, and POSTs the lines to Loki at /loki/api/v1/push. This page assumes that push…
