Photo by Josh Rakower on Unsplash
Centralized Logging with Loki, SeaweedFS, and Grafana
Cool and Collected
If you have to manage hundreds of instances or devices at the same time, you cannot simply use SSH to connect to each separately and examine specific log messages. Classic solutions to this problem from software vendors include the Elasticsearch, Logstash, and Kibana (ELK) stack (Figure 1) or Splunk.
Figure 1: Kibana is the ELK stack's standard tool for sifting through log messages. ELK itself, though, is a complicated beast with tough hardware requirements. © Kibana
However, if you have ever attempted to set up a DIY ELK stack on a six-core server, you will be all too aware of the issues. At first, everything looks fine, then Elasticsearch happily dumps entries onto the disk, RAM utilization escalates into the double-figure gigabyte range, and by the end of the week, you have a server that is almost exclusively occupied with managing itself. If you can afford to do so, you might then turn to Splunk; just make sure you are sitting down when you see your first license bill. For decades, logging in the Linux world has suffered from being either too bloated, too expensive, or both.
Starting in 2018, Grafana Labs has filled this gap with Loki
...
Buy this article as PDF
(incl. VAT)