logcli - Command-line client for Loki
logcli query '<LogQL>' [--since=1h] [--limit=30] [-o raw|jsonl]
logcli instant-query '<metric LogQL>'
logcli labels [name]
Options you will use
--since=1h- How far back to look.
--limit=30- Maximum lines (newest first).
-o raw- Only the log lines.
--addr / LOKI_ADDR- Default http://localhost:3100.
--addr=URL- Server address (default http://localhost:3100, or LOKI_ADDR).
--since=DURATION- Lookback window (default 1h).
--from=TIME- Start of the query, RFC3339.
--to=TIME- End of the query, RFC3339.
--limit=N- Limit on the number of entries to print (default 30; 0 = no limit).
-o, --output MODE- Output mode: default (timestamp, labels, line), raw (only the line) or jsonl.
-q, --quiet- Suppress query metadata.
--forward- Oldest first instead of newest first.
-t, --tail- Tail the logs (live).
Examples
$ logcli query '{unit="orders.service"} |= "ERROR"'grep, but server-side and across every host
$ logcli query '{unit="orders.service"} | json | level="ERROR" | line_format "{{.traceId}} {{.message}}"'parse structured logs and pull fields out
$ logcli instant-query 'sum by (unit) (count_over_time({job="systemd-journal"} |= "error" [5m]))'turn logs into a number
Gotchas
- Labels select STREAMS (cheap, indexed); line filters and parsers scan CONTENT. Keep labels low-cardinality: never a trace id or user id as a label.
Taught in
Try logcli in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.