Log Types
How It Works
Each agent ships logs directly to Victoria Logs over HTTP using the JSON Lines format.- Container logs are streamed from running containers, batched in groups of 1000, and flushed every 5 seconds. Log positions are tracked per container to prevent duplicates.
- HTTP logs are tailed from Traefik’s access log file on proxy nodes, batched in groups of 500.
- Build logs are captured during image builds and streamed in real time.
- Agent logs intercept the agent’s own stdout/stderr with automatic log level detection.
Configuration
Victoria Logs runs as a Docker container alongside the control plane.
The control plane exposes logs at
https://logs.<ROOT_DOMAIN> with basic auth. Agents write to the internal endpoint at http://victoria-logs:9428.
Accessing Logs
Logs are accessible from the web UI for each service, deployment, build, and server. The control plane queries Victoria Logs using LogSQL with filters forservice_id, deployment_id, server_id, and time ranges.
Searches run against Victoria Logs rather than only the entries currently loaded in the browser. Continuous service, request, and server log views default to the last 24 hours and support 1-hour, 6-hour, 24-hour, and 7-day ranges. These query ranges do not change the separate VL_RETENTION storage setting.