LogLynx ā Fast, lightweight log analytics for Traefik and HTTP logs with real-time metrics.
10K+
š Important Documentation
- Traefik Setup Guideā - Recommended Traefik configuration for optimal LogLynx performance and complete field capture (for the pangolin quick installationā no additional configuration is required for Traefik).
- Deduplication Systemā - Learn how LogLynx prevents duplicate log entries and handles various scenarios (log rotation, crashes, re-imports)
LogLynx is a small, fast log analytics service for HTTP access logs (including Traefik). It ingests logs, enriches them with GeoIP data, stores events in SQLite, and provides realtime dashboards and metrics via a web UI and SSE streams.
Key features
dev, latest, and release versions.Environment variables
You can configure the container via environment variables (these match the .env.example in this repo):
DB_PATH (default: loglynx.db) ā path to the SQLite DB file inside the container.DB_MAX_OPEN_CONNS (default: 10) ā DB max open connections.DB_MAX_IDLE_CONNS (default: 3) ā DB max idle connections.DB_CONN_MAX_LIFE (default: 1h) ā DB connection max lifetime.GEOIP_ENABLED (default: true) ā enable GeoIP enrichment.GEOIP_CITY_DB (default: geoip/GeoLite2-City.mmdb) ā path to city DB.GEOIP_COUNTRY_DB (default: geoip/GeoLite2-Country.mmdb) ā path to country DB.GEOIP_ASN_DB (default: geoip/GeoLite2-ASN.mmdb) ā path to ASN DB.TRAEFIK_LOG_PATH (default: traefik/logs/access.log) ā path to Traefik access log inside the container.LOG_AUTO_DISCOVER (default: true) ā enable auto-discovery of logs in directories.LOG_WATCH_INTERVAL (default: 5s) ā poll interval for watching log dirs.SERVER_HOST (default: 0.0.0.0) ā bind address for web server.SERVER_PORT (default: 8080) ā web server port.SERVER_PRODUCTION (default: false) ā run Gin in Release mode when true.METRICS_INTERVAL (default: 5s) ā realtime metrics collection interval.GEOIP_CACHE_SIZE (default: 10000) ā cache size for GeoIP lookups.BATCH_SIZE (default: 1000) ā bulk insert batch size.WORKER_POOL_SIZE (default: 4) ā number of processing workers.LOG_LEVEL (default: info) ā application log level (trace, debug, info, warn, error, fatal).Recommended volumes and ports
-v ./data:/data and set DB_PATH=/data/loglynx.db.-v ./geoip:/app/geoip.8080).Quick start (Docker)
docker run -d \
--name loglynx \
-p 8080:8080 \
-v $(pwd)/data:/data \
-v $(pwd)/geoip:/app/geoip \
-e DB_PATH=/data/loglynx.db \
-e LOG_LEVEL=info \
k0lin/loglynx:latest
Docker Compose example
services:
loglynx:
image: k0lin/loglynx:latest
restart: unless-stopped
ports:
- 8080:8080
volumes:
- ./data:/data
- ./geoip:/app/geoip
environment:
- DB_PATH=/data/loglynx.db
- LOG_LEVEL=info
- SERVER_PRODUCTION=false
This should be your pangolin installation in broad terms if you used the installer from the official documentation.
your-folder/
āāā config/ # Pangolin configuration
ā āāā traefik/
ā ā āāā logs/
ā ā āāā access.log # Traefik access log
ā āāā logs/
ā āāā letsencrypt/
ā āāā db/
ā āāā config.yml
ā āāā GeoLite2-City.mmdb # optional
ā āāā GeoLite2-ASN.mmdb # optional
ā āāā GeoLite2-Country.mmdb # optional
āāā loglynx-data/ # database for loglynx service
āāā GeoLite2-Country_20251024/ # MaxMind license
āāā docker-compose.yml
This is the deployment of Docker Compose, which will also contain services such as Pangolin, Traefik, etc. The example configuration is set up using the Pangolin configuration described above.
#other service related to pangolin
loglynx:
image: k0lin/loglynx:latest
container_name: loglynx
restart: unless-stopped
ports:
- "8080:8080"
volumes:
- ./loglynx-data:/data
- ./config:/app/geoip
- ./config/traefik/logs:/traefik/logs
environment:
- DB_PATH=/data/loglynx.db
- GEOIP_ENABLED=true #if the geolite database are installed
- GEOIP_CITY_DB=/app/geoip/GeoLite2-City.mmdb #only if GEOIP_ENABLED is set to true, It is not mandatory to set all three, even just one is fine (obviously it will work with limited functionality)
- GEOIP_COUNTRY_DB=/app/geoip/GeoLite2-Country.mmdb #(only if GEOIP_ENABLED is set to true), It is not mandatory to set all three, even just one is fine (obviously it will work with limited functionality)
- GEOIP_ASN_DB=/app/geoip/GeoLite2-ASN.mmdb #(only if GEOIP_ENABLED is set to true), It is not mandatory to set all three, even just one is fine (obviously it will work with limited functionality)
- TRAEFIK_LOG_PATH=/traefik/logs/access.log
- LOG_LEVEL=info
- SERVER_PRODUCTION=false
# There are several configurable environment variables to optimize program startup (check the wiki).
The dashboard will be available at http://localhost:8080
Healthcheck (suggested)
You can add a Docker healthcheck to ensure the web UI responds:
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s \
CMD curl -f http://localhost:8080/health || exit 1
Tags and versioning
dev ā pushed for every main branch push (useful for testing).latest ā pushed on release publish and points to the newest stable release.<tag> or v1.2.3 ā release-specific tags created from GitHub releases.Notes and best practices
SERVER_PRODUCTION=true and choose an appropriate LOG_LEVEL.Security
Contact & license
See the project README.md and LICENSE for usage and licensing details.
Content type
Image
Digest
sha256:063917b0dā¦
Size
17.2 MB
Last updated
4 months ago
docker pull k0lin/loglynx