Ubuntu22非Docker环境Loki面板大日志不显示及查询超限求助
Loki部署问题排查与解决
问题描述
在Ubuntu 22服务器部署Grafana、Loki和Promtail后,日志可正常采集,但出现三个核心问题:
- 响应超过最大消息大小(193605955 vs 104857600)
- 存在过多未处理请求(too many outstanding requests)
- 查询条目数超过限制:
max entries limit per query exceeded, limit > max_entries_limit (100000 > 5000)
当前Loki配置(loki.yaml):
auth_enabled: false server: http_listen_port: 3100 grpc_listen_port: 9096 common: instance_addr: 127.0.0.1 path_prefix: /tmp/loki storage: filesystem: chunks_directory: /tmp/loki/chunks rules_directory: /tmp/loki/rules replication_factor: 1 ring: kvstore: store: inmemory query_range: results_cache: cache: embedded_cache: enabled: true max_size_mb: 100 schema_config: configs: - from: 2020-10-24 store: tsdb object_store: filesystem schema: v12 index: prefix: index_ period: 24h ruler: alertmanager_url: http://localhost:9093
曾尝试修改loki-local-config.yaml,设置max_query_size=10000并添加limit_configs,但问题未解决:
storage_config: ... limit_configs: - name: "loki_logs_per_stream" type: logs enforce_within_query_window: true period: 168h limit: 5000000 - name: "loki_series" type: series enforce_within_query_window: false period: 0 limit: 2000000
解决方案
针对三个问题,分别调整Loki核心配置:
1. 解决响应超过最大消息大小问题
在server块中添加gRPC消息大小限制参数,同时延长HTTP超时时间:
server: http_listen_port: 3100 grpc_listen_port: 9096 # 增大gRPC消息大小限制(单位:字节,示例为200MB) grpc_server_max_recv_msg_size: 209715200 grpc_server_max_send_msg_size: 209715200 # 延长HTTP读写超时,避免大请求被中断 http_server_write_timeout: 300s http_server_read_timeout: 300s
2. 解决过多未处理请求问题
调整查询并发参数,提升Loki的请求处理能力,同时优化Promtail的推送策略:
# Loki配置中调整查询并发 query_range: results_cache: cache: embedded_cache: enabled: true max_size_mb: 100 # 增加允许的并发查询数 max_concurrent_queries: 20 # 按时间拆分大查询,降低单请求负载 split_queries_by_interval: 15m # 如果是多实例部署,可添加frontend配置(单实例可选) frontend: max_outstanding_per_tenant: 1000 compress_responses: true
Promtail配置优化(减少频繁推送):
clients: - url: http://localhost:3100/loki/api/v1/push batchsize: 1048576 # 1MB,增大批次大小 batchwait: 1s # 延长等待时间,攒够批次再推送
3. 解决查询条目数超过限制问题
添加独立的limits_config块(注意不是storage_config下的子项),调整查询条目限制:
limits_config: # 单查询允许返回的最大条目数,匹配报错中的需求值 max_entries_limit_per_query: 100000 # 单租户最大并发查询数 max_concurrent_queries: 20 # 允许的最长查询时间范围 max_query_length: 30d # 单查询结果的最大大小(单位:字节,示例为200MB) max_query_size: 209715200
完整调整后的Loki配置示例
auth_enabled: false server: http_listen_port: 3100 grpc_listen_port: 9096 grpc_server_max_recv_msg_size: 209715200 grpc_server_max_send_msg_size: 209715200 http_server_write_timeout: 300s http_server_read_timeout: 300s common: instance_addr: 127.0.0.1 path_prefix: /tmp/loki storage: filesystem: chunks_directory: /tmp/loki/chunks rules_directory: /tmp/loki/rules replication_factor: 1 ring: kvstore: store: inmemory query_range: results_cache: cache: embedded_cache: enabled: true max_size_mb: 100 max_concurrent_queries: 20 split_queries_by_interval: 15m limits_config: max_entries_limit_per_query: 100000 max_concurrent_queries: 20 max_query_length: 30d max_query_size: 209715200 schema_config: configs: - from: 2020-10-24 store: tsdb object_store: filesystem schema: v12 index: prefix: index_ period: 24h ruler: alertmanager_url: http://localhost:9093
注意事项
- 修改配置后需重启Loki服务:
sudo systemctl restart loki - 参数值需根据服务器硬件配置(CPU、内存)合理调整,避免资源过载
- 长期建议优化日志查询语句,缩小时间范围或添加过滤条件,从根源减少返回数据量
内容的提问来源于stack exchange,提问作者omkark
相关产品推荐
相关产品推荐

