- Batches that fail go to /data/spool (SPOOL_MAX_MB, 1 GiB by default) and
are sent again oldest first; retries no longer block the store loop and
follow the shutdown context.
- Docker and host logs wait for room in a full queue instead of being
dropped; the Docker position only moves once a line is stored or spooled.
- Reverse DNS no longer holds up the syslog listeners, with an LRU cache
and a cap on concurrent lookups.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New source, off by default and switched in Settings > Sources, that
collects the system logs of the machine hosting the stack:
- reads the systemd journal files directly (pure Go reader, no
journalctl in the image), from /var/log/journal and /run/log/journal
mounted read-only under /host;
- falls back to following the text files of /var/log (syslog,
messages, *.log) on hosts without journald;
- positions saved in /data/hostlogs-state.json, HOST_LOGS_BACKFILL
read when the source is turned on;
- source_type "host", selectable in the Source filter;
- compose mounts and group_add (HOST_LOGS_GID, adm by default), docs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>