A segmented control at the start of the filter bar switches between
Stream (sliding duration, live view) and Time range (start and end
dates in the chosen time zone, previous/next and zoom-out buttons).
Timeline clicks and drags switch to Time range mode; the mode and
range are kept across reloads.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New GET /api/dbstats reads VictoriaLogs /metrics (stored lines, size on
disk, raw size, free space, partitions, retention) and two LogsQL queries
(period covered, distinct hosts and apps, lines of the last 24 h and hour),
cached for 30 s. The danger zone shows them, sizes in KB/MB/GB or Ko/Mo/Go.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- The dialog uses most of the screen (up to 1280 px wide, full height);
sections become cards laid out in two columns when there is room.
- Settings > Filters: compact tag rows in one wide column, a toolbar that
stays in view (add, presets, filter, reset), a filter on keyword, label
or code, and a tag count.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- ALLOW_PURGE is now false by default; the UI shows a banner when there is
no authentication.
- Read-only role: AUTH_VIEWER_USER/AUTH_VIEWER_PASS in local mode, or
OIDC_ADMIN_GROUP in OIDC mode; changes get 403 and the admin settings
are greyed out.
- Content-Security-Policy (inline scripts allowed by hash) and other
security headers; cross-site changes are refused.
- Syslog TCP: at most SYSLOG_TCP_MAX_CONNS connections, closed after
SYSLOG_TCP_IDLE of silence; HTTP idle timeout.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Batches that fail go to /data/spool (SPOOL_MAX_MB, 1 GiB by default) and
are sent again oldest first; retries no longer block the store loop and
follow the shutdown context.
- Docker and host logs wait for room in a full queue instead of being
dropped; the Docker position only moves once a line is stored or spooled.
- Reverse DNS no longer holds up the syslog listeners, with an LRU cache
and a cap on concurrent lookups.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Existing tags.json files are unchanged; only new installs and "Restore
default tags" get the shorter list.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The presets move from app.js to presets.json, built into the binary and
served by /api/presets. PRESETS_FILE (default /data/presets.json) replaces
the list when present; it is read again each time Settings opens and the
built-in list is used if it is invalid. docs/presets.md (EN/FR) explains
each preset and the file format.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The preset menu is grouped (HTTP/HTTPS, System, Applications, General) and
gains SSH/logins, sudo, kernel, systemd, firewall/fail2ban, Docker,
databases, log levels and IPv4 addresses.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Inconsolata Condensed (Inconsolata pinned at width 75, 0.4em per
character) is now the narrowest option. Ubuntu Mono moves from Bunny
Fonts to the built-in fonts, so it works offline too.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Settings > Interface > Log display gets a Density switch (Normal/Compact)
that tightens row padding and line height, and the font list gets Iosevka,
a narrow SIL OFL monospace font served from web/fonts (Latin subset,
13 KB per weight) so it works offline, unlike the Bunny Fonts ones.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Each tag gets a stable code (01-99) assigned by the server and stored in
tags.json; existing tags get one when the file is loaded. A fixed-width
Filters column shows the codes of the active tags found in each message
(room for 3, then 2 + "+N", all listed in the tooltip).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A '+ Preset…' menu in Settings > Filters adds groups of tags for status
codes, methods, probes, bots and TLS/proxy errors (nginx, Apache, Traefik,
Caddy, HAProxy). A regex group named hl colors only that part of a match,
and tags get an optional label shown in place of the pattern.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The local mode now shows a login page in the colors of the UI (light/dark theme, FR/EN)
with a signed session cookie and the log out button, like the OIDC mode. LOGIN_LOGO shows
a PNG mounted in the container on that page. SESSION_TTL applies to both modes
(OIDC_SESSION_TTL still works). HTTP Basic credentials are still accepted for scripts.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
AUTH_MODE=local keeps the HTTP Basic authentication (unchanged default);
AUTH_MODE=oidc logs in through an OpenID Connect provider with the
authorization code flow and PKCE, standard library only: discovery,
ID token signature (RS/PS/ES) and claims checks, signed session cookie
whose key is kept in DATA_DIR. The UI gets a log out button and reloads
into the login when the session ends.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New source, off by default and switched in Settings > Sources, that
collects the system logs of the machine hosting the stack:
- reads the systemd journal files directly (pure Go reader, no
journalctl in the image), from /var/log/journal and /run/log/journal
mounted read-only under /host;
- falls back to following the text files of /var/log (syslog,
messages, *.log) on hosts without journald;
- positions saved in /data/hostlogs-state.json, HOST_LOGS_BACKFILL
read when the source is turned on;
- source_type "host", selectable in the Source filter;
- compose mounts and group_add (HOST_LOGS_GID, adm by default), docs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The "Color tags" bullet repeated under "Host names" (and its French
counterpart) duplicated Settings > Filters; it is removed from both files.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
README.fr.md is a full French translation of README.md (same sections,
code blocks and commands unchanged, same image and links). Each README
starts with a link to the other language.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
docs/logstream-schema-logique.{png,excalidraw} become
docs/architecture.{png,excalidraw}; the README image and source link
follow.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replaces the diagram with the corrected version 2 (title without commit
hash, Query with the from/to zoom bounds, Histogram box linked to the API
and VictoriaLogs, arrow labels on a white background), and adds a
Timeline bullet to the README legend.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Title without the commit hash (the hand-drawn font turned "32593b9" into
"3259369"); the subtitle dates the diagram instead.
- New Histogram (histogram.go) box: API -> histogram -> VictoriaLogs (stats).
- Query mentions the from/to range (zoom); the web UI mentions the
timeline, columns and live view.
- Multi-segment arrows drawn straight, routed between the containers.
- PNG regenerated from the .excalidraw source (Excalidraw 0.18 renderer).
- README: histogram.go in the Search flow.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Adds the logical diagram of the project (PNG and its editable Excalidraw
source in docs/) and an Architecture section after the introduction,
with a short description of the data flows.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A small arrow button at the right end of the status bar, shown once the
page has scrolled 400 px, scrolls smoothly back to the top (instantly
when the system asks for reduced motion). Living in the fixed status bar,
it never covers a log row or the details panel, on desktop and phones.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The list gets a thin sticky header (received, message time, severity,
host, app, message). Dragging the edge of a header resizes the column,
a double-click returns it to the automatic width; widths are clamped per
column and remembered per browser (logstream.cols.*), and Settings >
Interface has a "Reset column widths" button.
The columns are defined once on a #table wrapper from --col-* variables;
the header and every row use subgrid, so all rows line up (host and app
widths no longer vary from row to row). The wrapper clips with
overflow: clip so that the header can stick under the top bar. Phones
keep the two-line layout without header.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The global "svg { stroke: currentColor; stroke-width: 2 }" rule for icons
also applied to the timeline SVG, which is stretched horizontally: each
bar got a ~45 px wide light outline and the whole timeline looked white.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The histogram above the list becomes a configurable timeline:
- Scale linear / sqrt (default) / log, height S/M/L, bars or area.
- Colors: stacked by severity (error+, warning, the rest), intensity
against the median of the window (calm, burst >3x, anomaly >10x), or
none; colors are CSS variables with light and dark values.
- Vertical graduations on round local times (hh:mm:ss, hh:mm, dd/mm).
- Tooltip: interval bounds, total and detail per severity.
- Division automatic (~100 intervals) or fixed (1 s to 1 day), capped at
300 intervals by the server; intervals aligned on the local time zone.
- Refresh off / 5 s / 15 s / 30 s / 1 min / at each new interval. In
live mode the last interval is incremented from the SSE stream and the
timeline reloads at each new interval; paused while the tab is hidden.
- Click a bar to zoom on its interval, drag to zoom on a selection: the
list, export and counters follow through new from/to parameters.
The timeline now runs on the server clock (bounds and "now" come from
/api/histogram): the axis was drawn from the browser clock and refreshed
every 30 s only, so a clock difference with the server or a hidden tab
left it behind the logs.
/api/histogram returns interval indexes with the count per severity; the
division logic lives in histogram.go with table-driven tests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- SyslogServer opens and closes the UDP/TCP listeners at runtime from the
configuration saved in /data/syslog.json; a busy port no longer stops
Logstream, the error is shown in Settings instead.
- Sources tab: syslog section with an on/off switch, UDP and TCP labels,
the live listening state and the published port (SYSLOG_PORT, passed as
SYSLOG_PUBLIC_PORT for display; the mapping stays in docker-compose).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- docker-compose: victoria-logs v1.52.0 and docker-socket-proxy v0.5.0,
the versions running on sandbox.
- Dockerfile: golang 1.27.1-alpine3.24 and alpine 3.24.2 (Go 1.23 and
Alpine 3.20 no longer receive security fixes).
- README: pinned versions and how to update them.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- One label per container (project/service) in a single field, like
tag pickers: followed ones in the project color, a separator, then the
others in grey; a click switches a label. Excluded ones last, locked.
- Stopped containers hidden by default, shown dashed and still editable
with 'Show stopped containers'; filter box; enable/disable all apply to
the labels shown.
- Docker app names in the log list use their compose project color.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- docker.go follows every running container through the Docker API
(events + logs with follow), resumes after a restart from the last
position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
of history for new containers, strips terminal color codes and guesses
the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
project), enable/disable all, follow new containers automatically.
Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
are labelled logstream.exclude=true and never collected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- GET /api/export.csv streams every stored log matching the filters
(newest first, up to EXPORT_MAX rows, 100000 by default) straight from
VictoriaLogs, with dates in the time zone chosen in Settings.
- Export button with two variants: CSV (comma, UTF-8) and CSV for Excel
(semicolon + BOM, formula injection neutralized).
- Store.QueryStream streams query results without buffering them.
- Mobile: filter bar keeps two selects per row, count next to Export.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>