OnCallReady

Commands

logcli - Command-line client for Loki

logcli query '<LogQL>' [--since=1h] [--limit=30] [-o raw|jsonl]
logcli instant-query '<metric LogQL>'
logcli labels [name]

Options you will use

--since=1h
How far back to look.
--limit=30
Maximum lines (newest first).
-o raw
Only the log lines.
--addr / LOKI_ADDR
Default http://localhost:3100.
--addr=URL
Server address (default http://localhost:3100, or LOKI_ADDR).
--since=DURATION
Lookback window (default 1h).
--from=TIME
Start of the query, RFC3339.
--to=TIME
End of the query, RFC3339.
--limit=N
Limit on the number of entries to print (default 30; 0 = no limit).
-o, --output MODE
Output mode: default (timestamp, labels, line), raw (only the line) or jsonl.
-q, --quiet
Suppress query metadata.
--forward
Oldest first instead of newest first.
-t, --tail
Tail the logs (live).

Examples

$ logcli query '{unit="orders.service"} |= "ERROR"'

grep, but server-side and across every host

$ logcli query '{unit="orders.service"} | json | level="ERROR" | line_format "{{.traceId}} {{.message}}"'

parse structured logs and pull fields out

$ logcli instant-query 'sum by (unit) (count_over_time({job="systemd-journal"} |= "error" [5m]))'

turn logs into a number

Gotchas

Taught in

Try logcli in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.