Sign inSign up

k0lin/loglynx

By k0lin

•Updated 3 months ago

LogLynx — Fast, lightweight log analytics for Traefik and HTTP logs with real-time metrics.

Image
API management
Developer tools
Monitoring & observability
1

10K+

k0lin/loglynx repository overview

šŸ“š Important Documentation

⁠LogLynx

LogLynx is a small, fast log analytics service for HTTP access logs (including Traefik). It ingests logs, enriches them with GeoIP data, stores events in SQLite, and provides realtime dashboards and metrics via a web UI and SSE streams.

Key features

  • Lightweight: single binary, low resource usage.
  • Realtime metrics and server-sent events (SSE).
  • GeoIP enrichment (City/Country/ASN) using MaxMind DBs.
  • Simple SQLite storage — easy backups and portability.
  • Supports Traefik access logs and auto-discovery of log files.
  • Docker-ready with tags for dev, latest, and release versions.

Environment variables

You can configure the container via environment variables (these match the .env.example in this repo):

  • DB_PATH (default: loglynx.db) — path to the SQLite DB file inside the container.
  • DB_MAX_OPEN_CONNS (default: 10) — DB max open connections.
  • DB_MAX_IDLE_CONNS (default: 3) — DB max idle connections.
  • DB_CONN_MAX_LIFE (default: 1h) — DB connection max lifetime.
  • GEOIP_ENABLED (default: true) — enable GeoIP enrichment.
  • GEOIP_CITY_DB (default: geoip/GeoLite2-City.mmdb) — path to city DB.
  • GEOIP_COUNTRY_DB (default: geoip/GeoLite2-Country.mmdb) — path to country DB.
  • GEOIP_ASN_DB (default: geoip/GeoLite2-ASN.mmdb) — path to ASN DB.
  • TRAEFIK_LOG_PATH (default: traefik/logs/access.log) — path to Traefik access log inside the container.
  • LOG_AUTO_DISCOVER (default: true) — enable auto-discovery of logs in directories.
  • LOG_WATCH_INTERVAL (default: 5s) — poll interval for watching log dirs.
  • SERVER_HOST (default: 0.0.0.0) — bind address for web server.
  • SERVER_PORT (default: 8080) — web server port.
  • SERVER_PRODUCTION (default: false) — run Gin in Release mode when true.
  • METRICS_INTERVAL (default: 5s) — realtime metrics collection interval.
  • GEOIP_CACHE_SIZE (default: 10000) — cache size for GeoIP lookups.
  • BATCH_SIZE (default: 1000) — bulk insert batch size.
  • WORKER_POOL_SIZE (default: 4) — number of processing workers.
  • LOG_LEVEL (default: info) — application log level (trace, debug, info, warn, error, fatal).

Recommended volumes and ports

  • Persist the SQLite database by mounting a host volume to the DB path. Example: -v ./data:/data and set DB_PATH=/data/loglynx.db.
  • Mount GeoIP DBs into the container if you enable GeoIP enrichment. Example: -v ./geoip:/app/geoip.
  • Expose the web UI port (default 8080).

Quick start (Docker)

docker run -d \
  --name loglynx \
  -p 8080:8080 \
  -v $(pwd)/data:/data \
  -v $(pwd)/geoip:/app/geoip \
  -e DB_PATH=/data/loglynx.db \
  -e LOG_LEVEL=info \
  k0lin/loglynx:latest

Docker Compose example

services:
  loglynx:
    image: k0lin/loglynx:latest
    restart: unless-stopped
    ports:
      - 8080:8080
    volumes:
      - ./data:/data
      - ./geoip:/app/geoip
    environment:
      - DB_PATH=/data/loglynx.db
      - LOG_LEVEL=info
      - SERVER_PRODUCTION=false
⁠Deployment with docker compose on standard pangolin installation

This should be your pangolin installation in broad terms if you used the installer from the official documentation.

your-folder/
ā”œā”€ā”€ config/                    # Pangolin configuration
│   └── traefik/ 
│   │  └── logs/
│   │     └── access.log       # Traefik access log
│   ā”œā”€ā”€ logs/       
│   ā”œā”€ā”€ letsencrypt/     
│   ā”œā”€ā”€ db/      
│   ā”œā”€ā”€ config.yml
│   ā”œā”€ā”€ GeoLite2-City.mmdb     # optional
│   ā”œā”€ā”€ GeoLite2-ASN.mmdb      # optional
│   └── GeoLite2-Country.mmdb  # optional
ā”œā”€ā”€ loglynx-data/                      # database for loglynx service   
ā”œā”€ā”€ GeoLite2-Country_20251024/ # MaxMind license
└──  docker-compose.yml 

This is the deployment of Docker Compose, which will also contain services such as Pangolin, Traefik, etc. The example configuration is set up using the Pangolin configuration described above.

#other service related to pangolin

loglynx:
    image: k0lin/loglynx:latest
    container_name: loglynx
    restart: unless-stopped
    ports:
      - "8080:8080"
    volumes:
      - ./loglynx-data:/data
      - ./config:/app/geoip                 
      - ./config/traefik/logs:/traefik/logs
    environment:
      - DB_PATH=/data/loglynx.db
      - GEOIP_ENABLED=true  #if the geolite database are installed
      - GEOIP_CITY_DB=/app/geoip/GeoLite2-City.mmdb  #only if GEOIP_ENABLED is set to true, It is not mandatory to set all three, even just one is fine (obviously it will work with limited functionality)
      - GEOIP_COUNTRY_DB=/app/geoip/GeoLite2-Country.mmdb  #(only if GEOIP_ENABLED is set to true), It is not mandatory to set all three, even just one is fine (obviously it will work with limited functionality)
      - GEOIP_ASN_DB=/app/geoip/GeoLite2-ASN.mmdb  #(only if GEOIP_ENABLED is set to true), It is not mandatory to set all three, even just one is fine (obviously it will work with limited functionality)
      - TRAEFIK_LOG_PATH=/traefik/logs/access.log
      - LOG_LEVEL=info
      - SERVER_PRODUCTION=false
      # There are several configurable environment variables to optimize program startup (check the wiki).

The dashboard will be available at http://localhost:8080

Healthcheck (suggested)

You can add a Docker healthcheck to ensure the web UI responds:

HEALTHCHECK --interval=30s --timeout=5s --start-period=30s \
  CMD curl -f http://localhost:8080/health || exit 1

Tags and versioning

  • dev — pushed for every main branch push (useful for testing).
  • latest — pushed on release publish and points to the newest stable release.
  • <tag> or v1.2.3 — release-specific tags created from GitHub releases.
  • commit SHA — optionally pushed for traceability.

Notes and best practices

  • GeoIP DBs: the project expects MaxMind GeoLite2 DBs. Check MaxMind licensing and download/update them regularly.
  • Back up the SQLite DB regularly if you need persistence beyond container lifecycle.
  • For production, set SERVER_PRODUCTION=true and choose an appropriate LOG_LEVEL.
  • If you change the DB path inside the container, make sure the host volume maps and permissions are correct.

Security

  • Avoid exposing the admin UI publicly without a reverse proxy and authentication.

Contact & license

See the project README.md and LICENSE for usage and licensing details.

Tag summary

Content type

Image

Digest

sha256:063917b0d…

Size

17.2 MB

Last updated

4 months ago

docker pull k0lin/loglynx