Grafana Loki无法持久化旧日志?如何上传并查询旧日志?
如何将超过24小时的旧日志上传至Loki并查询?
我在本地通过Docker运行grafana/loki:3.4.2和grafana/alloy:latest,尝试上传50小时前的日志到Loki做测试,但Loki无法持久化这些旧日志(24小时内的日志可正常存储)。
调试现状
- Grafana Alloy已正确解析日志中的时间戳
- Loki日志显示已成功接收Alloy推送的请求(存在"push request parsed"消息)
- 调用
GET http://localhost:3100/loki/api/v1/labels能正常返回标签,但GET http://localhost:3100/loki/api/v1/series返回空响应
相关配置文件
Docker Compose配置 (./docker-compose.yaml)
networks: loki: volumes: alloy: loki: services: loki: image: grafana/loki:3.4.2 ports: - "3100:3100" command: -config.file=/etc/loki/local-config.yaml volumes: - './infrastructure/loki/local-config.yaml:/etc/loki/local-config.yaml:ro' - 'loki:/loki' networks: - loki alloy: image: grafana/alloy:latest ports: - "12345:12345" volumes: - './logs:/var/log/test:ro' - 'alloy:/var/lib/alloy/data' - './infrastructure/alloy/config.alloy:/etc/alloy/config.alloy:ro' command: run --server.http.listen-addr=0.0.0.0:12345 --storage.path=/var/lib/alloy/data /etc/alloy/config.alloy networks: - loki
Grafana Alloy配置 (./infrastructure/alloy/config.alloy)
logging { level = "debug" format = "json" } livedebugging { enabled = true } local.file_match "local_files" { path_targets = [{"__path__" = "/var/log/test/**/*.jsonl"}] sync_period = "5s" } loki.source.file "log_scrape" { targets = local.file_match.local_files.targets forward_to = [loki.process.parse_logs.receiver] tail_from_end = false } loki.process "parse_logs" { forward_to = [loki.relabel.add_static_label.receiver] stage.json { expressions = { timestamp = "\"@t\"", level = "\"@l\"", application = "\"@a\"", } } stage.timestamp { source = "timestamp" format = "RFC3339" } stage.labels { values = { level = "", application = "", } } } loki.relabel "add_static_label" { forward_to = [loki.write.grafana_loki.receiver] rule { target_label = "environment" replacement = "dev" } rule { target_label = "system" replacement = "main" } } loki.write "grafana_loki" { endpoint { url = "http://loki:3100/loki/api/v1/push" } }
Loki配置 (./infrastructure/loki/local-config.yaml)
auth_enabled: false server: http_listen_port: 3100 log_level: debug common: instance_addr: 127.0.0.1 path_prefix: /loki storage: filesystem: chunks_directory: /loki/chunks rules_directory: /loki/rules replication_factor: 1 ring: kvstore: store: inmemory compactor: working_directory: /loki/compactor compaction_interval: 1m retention_enabled: true retention_delete_delay: 1m retention_delete_worker_count: 10 delete_request_store: filesystem limits_config: retention_period: 8760h reject_old_samples: false reject_old_samples_max_age: 8760h schema_config: configs: - from: 2020-10-24 store: tsdb object_store: filesystem schema: v13 index: prefix: index_ period: 24h ruler: alertmanager_url: "" analytics: reporting_enabled: false
测试日志文件 (./logs/test/log20250516.jsonl)
{"@t":"2025-05-16T11:21:10.5111356+00:00","@l":"Information","@m":"Now listening: \"http://[::]:8080\"","@i":"d826f4b8","address":"http://[::]:8080","EventId":{"Id":14,"Name":"ListeningOnAddress"},"SourceContext":"Microsoft.Hosting.Lifetime","@a":"test"} {"@t":"2025-05-16T11:21:10.5123889+00:00","@l":"Information","@m":"Application started. Press Ctrl+C to shut down.","@i":"dcaefe54","SourceContext":"Microsoft.Hosting.Lifetime","@a":"test"}
解决方法
1. 重置Alloy的读取位置
Alloy会将日志文件的读取位置保存在存储卷中,如果之前已经读取过目标日志文件,即使设置了tail_from_end = false也不会重新读取。执行以下步骤重置:
- 停止Alloy容器:
docker-compose stop alloy - 删除Alloy的存储卷:
docker volume rm <你的项目名>_alloy(替换为实际项目名称) - 重启Alloy:
docker-compose up -d alloy
2. 确认Loki Compactor处理旧索引
你的Loki配置中索引周期为24小时,旧日志属于过去的索引周期,需要确保Compactor完成对应周期的索引合并:
- 查看Loki日志,搜索
compaction completed相关内容,确认是否处理了旧日志对应的索引周期 - 若Compactor未自动处理,可等待默认的1分钟间隔,或重启Loki容器触发Compaction
3. 直接指定时间范围查询旧日志
/loki/api/v1/series返回空可能是因为默认查询范围为最近1小时,尝试明确指定旧日志的时间范围查询:
curl "http://localhost:3100/loki/api/v1/query_range?query={environment=\"dev\"}&start=2025-05-16T00:00:00Z&end=2025-05-17T00:00:00Z"
4. 补充Loki TSDB索引保留配置
在Loki的limits_config中添加tsdb_retention_period,确保索引保留时间与日志保留时间一致:
limits_config: retention_period: 8760h reject_old_samples: false reject_old_samples_max_age: 8760h tsdb_retention_period: 8760h # 新增该行
修改后重启Loki容器。
内容的提问来源于stack exchange,提问作者K. V.
相关产品推荐
相关产品推荐

