Centralized Log Management

Learn Centralized Log Management. This module covers Setting up Loki, Shipping Logs with Promtail, Querying Logs with LogQL, Metrics from Logs, Smarter Labeling. You will master these essential Linux skills through hands-on labs and real-world challenges.

DevOps EngineerLinuxDevOps

Introduction

Loki stores log streams by labels, while Promtail discovers files and ships their lines into that store. This hands-on course builds a local pipeline and teaches you to query both individual events and numeric signals derived from logs.

You will run Loki, register it with Grafana, configure Promtail for system and application files, and explore streams with LogQL. Later exercises count and rate matching lines, group parsed JSON by level, unwrap numeric fields, and use labels without turning high-cardinality values into expensive indexes.

What You Will Learn

  • Download, start, and verify Loki and connect it to Grafana through the API
  • Configure Promtail file discovery, stream labels, positions, and the Loki push endpoint
  • Verify shipped logs with Loki’s range-query API and Grafana Explore
  • Select streams and filter lines by literal text or regular expression in LogQL
  • Convert logs into counts and per-second rates over time windows
  • Parse JSON, group rates by a field, and unwrap numeric values for aggregation
  • Add a low-cardinality environment label and explain what should remain a line filter
  • Trigger an application error spike and construct a one-minute LogQL detection query

Who This Course Is For

This intermediate course is for Linux administrators, DevOps practitioners, and observability learners who want practical experience building and querying a Loki-based log pipeline.

Prerequisites: Comfort with Linux shell commands, YAML, background processes, curl, log files, regular expressions, and basic Grafana navigation. Prior Loki or LogQL experience is not required.

Learning environment: A single Linux lab machine running Loki, Promtail, Grafana, logcli, and generated log files. Components run locally as lab processes, so the course demonstrates centralized-log concepts without a multi-host deployment.

Frequently Asked Questions

Will I collect logs from multiple servers?

No. Promtail, Loki, Grafana, and the log sources all run on one lab machine. You practice the same discovery, labeling, shipping, storage, and query boundaries used in a distributed pipeline, but not remote-agent rollout.

How much LogQL does the course cover?

It covers stream selectors, literal and regex filters, count_over_time, rate, JSON parsing, sum by, and unwrap with avg_over_time. Advanced parsers, binary operators, recording rules, alerts, and performance tuning are outside the scope.

Does the error-spike challenge create and detect a real incident?

It creates a trigger that makes the provided generator write ERROR lines to /var/log/app.log, then requires a valid one-minute count query saved to a file. It does not configure an alert or external notification from that query.

Teacher

labby
Labby
Labby is the LabEx teacher.