- Batches that fail go to /data/spool (SPOOL_MAX_MB, 1 GiB by default) and
are sent again oldest first; retries no longer block the store loop and
follow the shutdown context.
- Docker and host logs wait for room in a full queue instead of being
dropped; the Docker position only moves once a line is stored or spooled.
- Reverse DNS no longer holds up the syslog listeners, with an LRU cache
and a cap on concurrent lookups.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- docker.go follows every running container through the Docker API
(events + logs with follow), resumes after a restart from the last
position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
of history for new containers, strips terminal color codes and guesses
the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
project), enable/disable all, follow new containers automatically.
Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
are labelled logstream.exclude=true and never collected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>