Short answer: The page sends one request, a time window or a line count, and lets the backend that holds the logs apply it. Docker‘s logs API and Loki‘s query_range both answer with a list of lines. Any further filter selects from that list. It does not start another…
Tag: Loki
How Loki query responses are gzipped on the way to a log viewer
Short answer: Loki gzips query_range when frontend.compress_responses is true and the client sends Accept-Encoding: gzip. On 3.4.2 the help text for -querier.compress-http-responses says that default is true. It is not the value the process runs with. RegisterFlags then registers -frontend.support-parquet-encoding on that same bool, with default false, so gzip…
How Promtail reads the Docker API and pushes logs to Loki
Short answer: Promtail does not open Docker’s log files. It connects to the local Docker socket, lists container ids, and calls the engine logs API with follow. It splits stdout from stderr, removes Docker’s timestamp prefix, and POSTs the lines to Loki at /loki/api/v1/push. This page assumes that push…
How Promtail ships container logs to Loki across an IPsec split tunnel
Short answer: Do not open a remote Docker socket to read container stdout. Promtail on the remote host tails the local socket and pushes to Loki. If that host’s IPsec policy can reach only one virtual address, and Loki is bound to a different virtual address on the same…
