You can send logs through a simple HTTP(s) API or send all server logs with our CL Agent
Send a single simple log message:
curl -X POST http://localhost:8080/api/v1/log/{log-source-token} -d "this is a log entry"
Send structured logs in JSON:
curl -X POST http://localhost:8080/api/v1/log/{log-source-token} -d '{"level": "error", "msg": "something went wrong"}'
Send a bunch of logs from a file:
curl -X POST http://localhost:8080/api/v1/ingest_logs/{log-source-token} --data-binary @mylogs.txt
This will make a log entry for every line of text sent separated by new line.
Use --data-binary, not -d. curl -d @file strips newlines from the file
before sending it, so the whole file arrives as a single line and is stored as
a single row. The response tells you which happened — a file of 900 lines
posted with -d comes back as {"logs_ingested": 1}.
You can also pass the token as a Bearer token in the Authorization header instead of the URL:
curl -X POST http://localhost:8080/api/v1/ingest_logs \
-H "Authorization: Bearer {log-source-token}" \
--data-binary @mylogs.txt
You can send compressed logs with gzip:
curl -X POST https://localhost:8080/api/v1/ingest_logs/{log-source-token} --data-binary @mylogs.gz
Gzip is detected from the first bytes of the body, not from a header, so no
Content-Encoding header is needed.
A single line is stored whole up to 1 MB. A longer line is truncated rather
than dropped, and carries ...[truncated by centrallogging: line exceeded 1048576 bytes] on the end. The response reports how many lines that happened
to, so {"logs_ingested": 4, "lines_truncated": 1} means four rows went in and
one of them was shortened. Find them later with
SELECT * FROM logs WHERE msg LIKE '%truncated by centrallogging%'.
Working through this from a script rather than by hand? How to send logs to a server with curl covers the error handling, the Bearer-token setup and the four failures that look like success.
You can apply a JavaScript transformation to incoming logs. This is useful for parsing, filtering, or restructuring log lines before they are stored.
Transform scripts are configured per log source in the source settings. You can test transformations from the web UI before saving them.
The script receives each log line as input and must return the transformed output. Scripts have a 1 second execution timeout per log line.
💌 Get notified on new features and updates