The histogram above the list becomes a configurable timeline:
- Scale linear / sqrt (default) / log, height S/M/L, bars or area.
- Colors: stacked by severity (error+, warning, the rest), intensity
against the median of the window (calm, burst >3x, anomaly >10x), or
none; colors are CSS variables with light and dark values.
- Vertical graduations on round local times (hh:mm:ss, hh:mm, dd/mm).
- Tooltip: interval bounds, total and detail per severity.
- Division automatic (~100 intervals) or fixed (1 s to 1 day), capped at
300 intervals by the server; intervals aligned on the local time zone.
- Refresh off / 5 s / 15 s / 30 s / 1 min / at each new interval. In
live mode the last interval is incremented from the SSE stream and the
timeline reloads at each new interval; paused while the tab is hidden.
- Click a bar to zoom on its interval, drag to zoom on a selection: the
list, export and counters follow through new from/to parameters.
The timeline now runs on the server clock (bounds and "now" come from
/api/histogram): the axis was drawn from the browser clock and refreshed
every 30 s only, so a clock difference with the server or a hidden tab
left it behind the logs.
/api/histogram returns interval indexes with the count per severity; the
division logic lives in histogram.go with table-driven tests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- docker.go follows every running container through the Docker API
(events + logs with follow), resumes after a restart from the last
position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
of history for new containers, strips terminal color codes and guesses
the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
project), enable/disable all, follow new containers automatically.
Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
are labelled logstream.exclude=true and never collected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>