You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Grafana Loki无法持久化旧日志?如何上传并查询旧日志?

如何将超过24小时的旧日志上传至Loki并查询?

我在本地通过Docker运行grafana/loki:3.4.2和grafana/alloy:latest,尝试上传50小时前的日志到Loki做测试,但Loki无法持久化这些旧日志(24小时内的日志可正常存储)。

调试现状

  • Grafana Alloy已正确解析日志中的时间戳
  • Loki日志显示已成功接收Alloy推送的请求(存在"push request parsed"消息)
  • 调用GET http://localhost:3100/loki/api/v1/labels能正常返回标签,但GET http://localhost:3100/loki/api/v1/series返回空响应

相关配置文件

Docker Compose配置 (./docker-compose.yaml)

networks:
  loki:

volumes:
  alloy:
  loki:

services:
  loki:
    image: grafana/loki:3.4.2
    ports:
      - "3100:3100"
    command: -config.file=/etc/loki/local-config.yaml
    volumes:
      - './infrastructure/loki/local-config.yaml:/etc/loki/local-config.yaml:ro'
      - 'loki:/loki'
    networks:
      - loki
  alloy:
    image: grafana/alloy:latest
    ports:
      - "12345:12345"
    volumes:
      - './logs:/var/log/test:ro'
      - 'alloy:/var/lib/alloy/data'
      - './infrastructure/alloy/config.alloy:/etc/alloy/config.alloy:ro'
    command: run --server.http.listen-addr=0.0.0.0:12345 --storage.path=/var/lib/alloy/data /etc/alloy/config.alloy
    networks:
      - loki

Grafana Alloy配置 (./infrastructure/alloy/config.alloy)

logging {
  level  = "debug"
  format = "json"
}
livedebugging {
  enabled = true
}
local.file_match "local_files" {
    path_targets = [{"__path__" = "/var/log/test/**/*.jsonl"}]
    sync_period = "5s"
}
loki.source.file "log_scrape" {
  targets    = local.file_match.local_files.targets
  forward_to = [loki.process.parse_logs.receiver]
  tail_from_end = false
}
loki.process "parse_logs" {
  forward_to = [loki.relabel.add_static_label.receiver]
  stage.json {
    expressions = {
      timestamp = "\"@t\"", 
      level = "\"@l\"",
      application = "\"@a\"",
    }
  }
  stage.timestamp {
    source = "timestamp"
    format = "RFC3339"
  }
  stage.labels {
    values = {
      level = "",
      application = "",
    }
  }
}
loki.relabel "add_static_label" {
    forward_to = [loki.write.grafana_loki.receiver]
    rule {
        target_label = "environment"
        replacement  = "dev"
    }
    rule {
        target_label = "system"
        replacement  = "main"
    }
}
loki.write "grafana_loki" {
  endpoint {
    url = "http://loki:3100/loki/api/v1/push"
  }
}

Loki配置 (./infrastructure/loki/local-config.yaml)

auth_enabled: false

server:
  http_listen_port: 3100
  log_level: debug

common:
  instance_addr: 127.0.0.1
  path_prefix: /loki
  storage:
    filesystem:
      chunks_directory: /loki/chunks
      rules_directory: /loki/rules
  replication_factor: 1
  ring:
    kvstore:
      store: inmemory

compactor:
  working_directory: /loki/compactor
  compaction_interval: 1m
  retention_enabled: true
  retention_delete_delay: 1m
  retention_delete_worker_count: 10
  delete_request_store: filesystem

limits_config:
  retention_period: 8760h
  reject_old_samples: false
  reject_old_samples_max_age: 8760h

schema_config:
  configs:
    - from: 2020-10-24
      store: tsdb
      object_store: filesystem
      schema: v13
      index:
        prefix: index_
        period: 24h

ruler:
  alertmanager_url: ""

analytics:
  reporting_enabled: false

测试日志文件 (./logs/test/log20250516.jsonl)

{"@t":"2025-05-16T11:21:10.5111356+00:00","@l":"Information","@m":"Now listening: \"http://[::]:8080\"","@i":"d826f4b8","address":"http://[::]:8080","EventId":{"Id":14,"Name":"ListeningOnAddress"},"SourceContext":"Microsoft.Hosting.Lifetime","@a":"test"}
{"@t":"2025-05-16T11:21:10.5123889+00:00","@l":"Information","@m":"Application started. Press Ctrl+C to shut down.","@i":"dcaefe54","SourceContext":"Microsoft.Hosting.Lifetime","@a":"test"}

解决方法

1. 重置Alloy的读取位置

Alloy会将日志文件的读取位置保存在存储卷中,如果之前已经读取过目标日志文件,即使设置了tail_from_end = false也不会重新读取。执行以下步骤重置:

  • 停止Alloy容器:docker-compose stop alloy
  • 删除Alloy的存储卷:docker volume rm <你的项目名>_alloy(替换为实际项目名称)
  • 重启Alloy:docker-compose up -d alloy

2. 确认Loki Compactor处理旧索引

你的Loki配置中索引周期为24小时,旧日志属于过去的索引周期,需要确保Compactor完成对应周期的索引合并:

  • 查看Loki日志,搜索compaction completed相关内容,确认是否处理了旧日志对应的索引周期
  • 若Compactor未自动处理,可等待默认的1分钟间隔,或重启Loki容器触发Compaction

3. 直接指定时间范围查询旧日志

/loki/api/v1/series返回空可能是因为默认查询范围为最近1小时,尝试明确指定旧日志的时间范围查询:

curl "http://localhost:3100/loki/api/v1/query_range?query={environment=\"dev\"}&start=2025-05-16T00:00:00Z&end=2025-05-17T00:00:00Z"

4. 补充Loki TSDB索引保留配置

在Loki的limits_config中添加tsdb_retention_period,确保索引保留时间与日志保留时间一致:

limits_config:
  retention_period: 8760h
  reject_old_samples: false
  reject_old_samples_max_age: 8760h
  tsdb_retention_period: 8760h  # 新增该行

修改后重启Loki容器。

内容的提问来源于stack exchange,提问作者K. V.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 02:27:08