The list gets a thin sticky header (received, message time, severity,
host, app, message). Dragging the edge of a header resizes the column,
a double-click returns it to the automatic width; widths are clamped per
column and remembered per browser (logstream.cols.*), and Settings >
Interface has a "Reset column widths" button.
The columns are defined once on a #table wrapper from --col-* variables;
the header and every row use subgrid, so all rows line up (host and app
widths no longer vary from row to row). The wrapper clips with
overflow: clip so that the header can stick under the top bar. Phones
keep the two-line layout without header.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The histogram above the list becomes a configurable timeline:
- Scale linear / sqrt (default) / log, height S/M/L, bars or area.
- Colors: stacked by severity (error+, warning, the rest), intensity
against the median of the window (calm, burst >3x, anomaly >10x), or
none; colors are CSS variables with light and dark values.
- Vertical graduations on round local times (hh:mm:ss, hh:mm, dd/mm).
- Tooltip: interval bounds, total and detail per severity.
- Division automatic (~100 intervals) or fixed (1 s to 1 day), capped at
300 intervals by the server; intervals aligned on the local time zone.
- Refresh off / 5 s / 15 s / 30 s / 1 min / at each new interval. In
live mode the last interval is incremented from the SSE stream and the
timeline reloads at each new interval; paused while the tab is hidden.
- Click a bar to zoom on its interval, drag to zoom on a selection: the
list, export and counters follow through new from/to parameters.
The timeline now runs on the server clock (bounds and "now" come from
/api/histogram): the axis was drawn from the browser clock and refreshed
every 30 s only, so a clock difference with the server or a hidden tab
left it behind the logs.
/api/histogram returns interval indexes with the count per severity; the
division logic lives in histogram.go with table-driven tests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- SyslogServer opens and closes the UDP/TCP listeners at runtime from the
configuration saved in /data/syslog.json; a busy port no longer stops
Logstream, the error is shown in Settings instead.
- Sources tab: syslog section with an on/off switch, UDP and TCP labels,
the live listening state and the published port (SYSLOG_PORT, passed as
SYSLOG_PUBLIC_PORT for display; the mapping stays in docker-compose).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- One label per container (project/service) in a single field, like
tag pickers: followed ones in the project color, a separator, then the
others in grey; a click switches a label. Excluded ones last, locked.
- Stopped containers hidden by default, shown dashed and still editable
with 'Show stopped containers'; filter box; enable/disable all apply to
the labels shown.
- Docker app names in the log list use their compose project color.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- docker.go follows every running container through the Docker API
(events + logs with follow), resumes after a restart from the last
position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
of history for new containers, strips terminal color codes and guesses
the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
project), enable/disable all, follow new containers automatically.
Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
are labelled logstream.exclude=true and never collected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- GET /api/export.csv streams every stored log matching the filters
(newest first, up to EXPORT_MAX rows, 100000 by default) straight from
VictoriaLogs, with dates in the time zone chosen in Settings.
- Export button with two variants: CSV (comma, UTF-8) and CSV for Excel
(semicolon + BOM, formula injection neutralized).
- Store.QueryStream streams query results without buffering them.
- Mobile: filter bar keeps two selects per row, count next to Export.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Tabbed settings dialog (side navigation, 4-column tabs on mobile);
the last opened tab is remembered.
- Interface: theme System/Light/Dark (System follows the OS preference),
log font size (tiny, small, medium, large) and log font: system
monospace or 12 free monospace fonts loaded from Bunny Fonts, with a
live preview. Ligatures disabled in log rows.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- _time is now the reception time; the device timestamp moves to msg_time.
Devices with a wrong clock were indexed in the past and escaped time
ranges and the host list.
- Host/app lists also include values seen in displayed and live logs;
clicking a host or app cell filters on it.
- Severity badges err/crit and warning use the colors of the error and
warning tags; default tags are now pastel (old default colors migrated).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Reverse DNS (cached PTR lookups): IP hosts are stored with their name
in 'host' and the IP in 'host_ip'; older IP-only logs are resolved on
display and the host filter shows 'name (IP)'. RDNS / DNS_SERVER env.
- Settings > Danger zone: delete all logs (type PURGE to confirm) through
VictoriaLogs /delete/run_task; -delete.enable added to docker-compose.
ALLOW_PURGE env to disable it.
- Remove the custom YYYY-MM-DD - HH:MM:SS:mmm format; default is now the
usual French display DD/MM/YYYY HH:MM:SS.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Store a 'received' field (server clock) with every message
- New first column with the reception time
- Settings: time zone (browser, UTC, ~80 zones) and reception time
format (YYYY-MM-DD - HH:MM:SS:mmm by default, ISO 8601, 12h, epoch...)
- The chosen time zone applies to every date shown
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>