Sending Logs

You can send logs through a simple HTTP(s) API or send all server logs with our CL Agent

Sending logs through HTTP(s) API

Send a single simple log message:

curl -X POST http://localhost:8080/api/v1/log/{log-source-token} -d "this is a log entry"

Send structured logs in JSON:

curl -X POST http://localhost:8080/api/v1/log/{log-source-token} -d '{"level": "error", "msg": "something went wrong"}'

Send a bunch of logs from a file:

curl -X POST http://localhost:8080/api/v1/ingest_logs/{log-source-token} --data-binary @mylogs.txt

This will make a log entry for every line of text sent separated by new line.

Use --data-binary, not -d. curl -d @file strips newlines from the file before sending it, so the whole file arrives as a single line and is stored as a single row. The response tells you which happened — a file of 900 lines posted with -d comes back as {"logs_ingested": 1}.

You can also pass the token as a Bearer token in the Authorization header instead of the URL:

curl -X POST http://localhost:8080/api/v1/ingest_logs \
    -H "Authorization: Bearer {log-source-token}" \
    --data-binary @mylogs.txt

You can send compressed logs with gzip:

curl -X POST https://localhost:8080/api/v1/ingest_logs/{log-source-token} --data-binary @mylogs.gz

Gzip is detected from the first bytes of the body, not from a header, so no Content-Encoding header is needed.

A single line is stored whole up to 1 MB. A longer line is truncated rather than dropped, and carries ...[truncated by centrallogging: line exceeded 1048576 bytes] on the end. The response reports how many lines that happened to, so {"logs_ingested": 4, "lines_truncated": 1} means four rows went in and one of them was shortened. Find them later with SELECT * FROM logs WHERE msg LIKE '%truncated by centrallogging%'.

Working through this from a script rather than by hand? How to send logs to a server with curl covers the error handling, the Bearer-token setup and the four failures that look like success.

Log Transformation

You can apply a JavaScript transformation to incoming logs. This is useful for parsing, filtering, or restructuring log lines before they are stored.

Transform scripts are configured per log source in the source settings. You can test transformations from the web UI before saving them.

The script receives each log line as input and must return the transformed output. Scripts have a 1 second execution timeout per log line.

💌 Get notified on new features and updates

Only sent when a new version is released. Nothing else.