The preset menu is grouped (HTTP/HTTPS, System, Applications, General) and
gains SSH/logins, sudo, kernel, systemd, firewall/fail2ban, Docker,
databases, log levels and IPv4 addresses.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Inconsolata Condensed (Inconsolata pinned at width 75, 0.4em per
character) is now the narrowest option. Ubuntu Mono moves from Bunny
Fonts to the built-in fonts, so it works offline too.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Settings > Interface > Log display gets a Density switch (Normal/Compact)
that tightens row padding and line height, and the font list gets Iosevka,
a narrow SIL OFL monospace font served from web/fonts (Latin subset,
13 KB per weight) so it works offline, unlike the Bunny Fonts ones.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Each tag gets a stable code (01-99) assigned by the server and stored in
tags.json; existing tags get one when the file is loaded. A fixed-width
Filters column shows the codes of the active tags found in each message
(room for 3, then 2 + "+N", all listed in the tooltip).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A '+ Preset…' menu in Settings > Filters adds groups of tags for status
codes, methods, probes, bots and TLS/proxy errors (nginx, Apache, Traefik,
Caddy, HAProxy). A regex group named hl colors only that part of a match,
and tags get an optional label shown in place of the pattern.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The local mode now shows a login page in the colors of the UI (light/dark theme, FR/EN)
with a signed session cookie and the log out button, like the OIDC mode. LOGIN_LOGO shows
a PNG mounted in the container on that page. SESSION_TTL applies to both modes
(OIDC_SESSION_TTL still works). HTTP Basic credentials are still accepted for scripts.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
AUTH_MODE=local keeps the HTTP Basic authentication (unchanged default);
AUTH_MODE=oidc logs in through an OpenID Connect provider with the
authorization code flow and PKCE, standard library only: discovery,
ID token signature (RS/PS/ES) and claims checks, signed session cookie
whose key is kept in DATA_DIR. The UI gets a log out button and reloads
into the login when the session ends.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
New source, off by default and switched in Settings > Sources, that
collects the system logs of the machine hosting the stack:
- reads the systemd journal files directly (pure Go reader, no
journalctl in the image), from /var/log/journal and /run/log/journal
mounted read-only under /host;
- falls back to following the text files of /var/log (syslog,
messages, *.log) on hosts without journald;
- positions saved in /data/hostlogs-state.json, HOST_LOGS_BACKFILL
read when the source is turned on;
- source_type "host", selectable in the Source filter;
- compose mounts and group_add (HOST_LOGS_GID, adm by default), docs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A small arrow button at the right end of the status bar, shown once the
page has scrolled 400 px, scrolls smoothly back to the top (instantly
when the system asks for reduced motion). Living in the fixed status bar,
it never covers a log row or the details panel, on desktop and phones.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The list gets a thin sticky header (received, message time, severity,
host, app, message). Dragging the edge of a header resizes the column,
a double-click returns it to the automatic width; widths are clamped per
column and remembered per browser (logstream.cols.*), and Settings >
Interface has a "Reset column widths" button.
The columns are defined once on a #table wrapper from --col-* variables;
the header and every row use subgrid, so all rows line up (host and app
widths no longer vary from row to row). The wrapper clips with
overflow: clip so that the header can stick under the top bar. Phones
keep the two-line layout without header.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The global "svg { stroke: currentColor; stroke-width: 2 }" rule for icons
also applied to the timeline SVG, which is stretched horizontally: each
bar got a ~45 px wide light outline and the whole timeline looked white.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The histogram above the list becomes a configurable timeline:
- Scale linear / sqrt (default) / log, height S/M/L, bars or area.
- Colors: stacked by severity (error+, warning, the rest), intensity
against the median of the window (calm, burst >3x, anomaly >10x), or
none; colors are CSS variables with light and dark values.
- Vertical graduations on round local times (hh:mm:ss, hh:mm, dd/mm).
- Tooltip: interval bounds, total and detail per severity.
- Division automatic (~100 intervals) or fixed (1 s to 1 day), capped at
300 intervals by the server; intervals aligned on the local time zone.
- Refresh off / 5 s / 15 s / 30 s / 1 min / at each new interval. In
live mode the last interval is incremented from the SSE stream and the
timeline reloads at each new interval; paused while the tab is hidden.
- Click a bar to zoom on its interval, drag to zoom on a selection: the
list, export and counters follow through new from/to parameters.
The timeline now runs on the server clock (bounds and "now" come from
/api/histogram): the axis was drawn from the browser clock and refreshed
every 30 s only, so a clock difference with the server or a hidden tab
left it behind the logs.
/api/histogram returns interval indexes with the count per severity; the
division logic lives in histogram.go with table-driven tests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- SyslogServer opens and closes the UDP/TCP listeners at runtime from the
configuration saved in /data/syslog.json; a busy port no longer stops
Logstream, the error is shown in Settings instead.
- Sources tab: syslog section with an on/off switch, UDP and TCP labels,
the live listening state and the published port (SYSLOG_PORT, passed as
SYSLOG_PUBLIC_PORT for display; the mapping stays in docker-compose).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- One label per container (project/service) in a single field, like
tag pickers: followed ones in the project color, a separator, then the
others in grey; a click switches a label. Excluded ones last, locked.
- Stopped containers hidden by default, shown dashed and still editable
with 'Show stopped containers'; filter box; enable/disable all apply to
the labels shown.
- Docker app names in the log list use their compose project color.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- docker.go follows every running container through the Docker API
(events + logs with follow), resumes after a restart from the last
position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
of history for new containers, strips terminal color codes and guesses
the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
project), enable/disable all, follow new containers automatically.
Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
are labelled logstream.exclude=true and never collected.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- GET /api/export.csv streams every stored log matching the filters
(newest first, up to EXPORT_MAX rows, 100000 by default) straight from
VictoriaLogs, with dates in the time zone chosen in Settings.
- Export button with two variants: CSV (comma, UTF-8) and CSV for Excel
(semicolon + BOM, formula injection neutralized).
- Store.QueryStream streams query results without buffering them.
- Mobile: filter bar keeps two selects per row, count next to Export.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Tabbed settings dialog (side navigation, 4-column tabs on mobile);
the last opened tab is remembered.
- Interface: theme System/Light/Dark (System follows the OS preference),
log font size (tiny, small, medium, large) and log font: system
monospace or 12 free monospace fonts loaded from Bunny Fonts, with a
live preview. Ligatures disabled in log rows.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- _time is now the reception time; the device timestamp moves to msg_time.
Devices with a wrong clock were indexed in the past and escaped time
ranges and the host list.
- Host/app lists also include values seen in displayed and live logs;
clicking a host or app cell filters on it.
- Severity badges err/crit and warning use the colors of the error and
warning tags; default tags are now pastel (old default colors migrated).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Reverse DNS (cached PTR lookups): IP hosts are stored with their name
in 'host' and the IP in 'host_ip'; older IP-only logs are resolved on
display and the host filter shows 'name (IP)'. RDNS / DNS_SERVER env.
- Settings > Danger zone: delete all logs (type PURGE to confirm) through
VictoriaLogs /delete/run_task; -delete.enable added to docker-compose.
ALLOW_PURGE env to disable it.
- Remove the custom YYYY-MM-DD - HH:MM:SS:mmm format; default is now the
usual French display DD/MM/YYYY HH:MM:SS.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Store a 'received' field (server clock) with every message
- New first column with the reception time
- Settings: time zone (browser, UTC, ~80 zones) and reception time
format (YYYY-MM-DD - HH:MM:SS:mmm by default, ISO 8601, 12h, epoch...)
- The chosen time zone applies to every date shown
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>