Loki 는 Grafana Labs 의 로그 저장소다. 본문을 색인하지 않고 라벨만 색인해 Elasticsearch 보다 가볍다. 질의는 LogQL 로 하고 화면은 Grafana 에서 본다.
수집기였던 Promtail 은 2026-03-02 에 EOL 됐다.[1] 새 수집기는 Grafana Alloy 이고, alloy convert --source-format=promtail 로 기존 Promtail 설정을 변환할 수 있다. 아래 Promtail 설정은 이미 돌리고 있는 것을 위해 남겨 둔다.
| 요소 | 역할 | 현행 |
|---|---|---|
| Loki | 저장 · 질의. HTTP 3100, gRPC 9096 | 3.7.8[2] |
| Grafana Alloy | 수집 · 전송 (OpenTelemetry Collector 배포판) | GitHub 릴리스 참조 |
| Promtail | 옛 수집기 | EOL (마지막 3.5.x) |
object_store 로 둔다.tsdb + v13 이다. boltdb-shipper + v11 은 지난 형식이다.GitHub 릴리스에서 바이너리와 버전에 맞는 샘플 설정을 받는다.
LOKI_VER=3.7.8
mkdir -p /opt/loki && cd /opt/loki
curl -L -o loki.zip https://github.com/grafana/loki/releases/download/v${LOKI_VER}/loki-linux-amd64.zip
unzip loki.zip && chmod +x loki-linux-amd64
curl -L -O https://raw.githubusercontent.com/grafana/loki/v${LOKI_VER}/cmd/loki/loki-local-config.yaml
샘플 설정(loki-local-config.yaml) 의 뼈대는 아래와 같다. 저장 경로 /tmp/loki 는 재부팅 때 지워지므로 운영에서는 /var/lib/loki 같은 곳으로 바꾼다.
auth_enabled: false
server:
http_listen_port: 3100
grpc_listen_port: 9096
common:
instance_addr: 127.0.0.1
path_prefix: /tmp/loki
storage:
filesystem:
chunks_directory: /tmp/loki/chunks
rules_directory: /tmp/loki/rules
replication_factor: 1
ring:
kvstore:
store: inmemory
schema_config:
configs:
- from: 2020-10-24
store: tsdb
object_store: filesystem
schema: v13
index:
prefix: index_
period: 24h
ruler:
alertmanager_url: http://localhost:9093
# 사용 통계 전송을 끄려면
analytics:
reporting_enabled: false
보존 기간을 두려면 compactor 와 limits_config.retention_period 를 넣는다.
compactor:
working_directory: /var/lib/loki/compactor
retention_enabled: true
delete_request_store: filesystem
limits_config:
retention_period: 168h
실행
./loki-linux-amd64 -config.file=loki-local-config.yaml
systemd 유닛 /etc/systemd/system/loki.service
[Unit]
Description=Grafana Loki
After=network-online.target
[Service]
User=loki
ExecStart=/opt/loki/loki-linux-amd64 -config.file=/opt/loki/loki-local-config.yaml
Restart=always
[Install]
WantedBy=multi-user.target
sudo firewall-cmd --permanent --add-port=3100/tcp
sudo firewall-cmd --reload
curl -s http://localhost:3100/ready
curl -s http://localhost:3100/metrics | head -5
Grafana 에 데이터 소스로 붙일 때는 http://<loki>:3100 을 준다. Grafana 데이터 소스 관리 를 본다.
Alloy 는 GitHub 릴리스(grafana/alloy) 또는 Grafana 패키지 저장소에서 설치한다. 파일을 읽어 Loki 로 보내는 최소 설정(config.alloy) 이다.
local.file_match "logs" {
path_targets = [{ "__path__" = "/var/log/log_dir/*.log", "job" = "recent_logs" }]
}
loki.source.file "logs" {
targets = local.file_match.logs.targets
forward_to = [loki.write.default.receiver]
}
loki.write "default" {
endpoint {
url = "http://<LOKI_HOST>:3100/loki/api/v1/push"
}
}
기존 Promtail 설정은 변환기로 옮긴다.
alloy convert --source-format=promtail --output=config.alloy promtail-config.yml
alloy run config.alloy
Promtail 은 2026-03-02 EOL 이다. 아래는 EOL 전에 쓰던 설정 기록이다. 새로 올리지 않는다.
$PROMTAIL_HOME/promtail -config.file=promtail-config.yml
server:
http_listen_port: 9080
grpc_listen_port: 0
positions:
filename: /tmp/positions.yaml
clients:
- url: http://<LOKI_HOST>:3100/loki/api/v1/push
scrape_configs:
- job_name: recent_logs
static_configs:
- targets:
- localhost
labels:
job: recent_logs
__path__: /var/log/log_dir/*.log
pipeline_stages:
- match:
selector: '{job="recent_logs"}'
stages:
- timestamp:
source: time
format: RFC3339Nano
action_on_failure: skip
- filter:
expression: "time() - .time < 600" # 최근 10분 이내의 로그만 수집
지난 Loki 설정(boltdb-shipper · v11 · table_manager) 은 3.x 에서 지원이 끊긴 항목이 있어 그대로 쓰지 않는다. 새 스키마로 옮길 때는 schema_config.configs 에 새 날짜부터 tsdb · v13 항목을 추가하는 방식으로 이어 붙인다.
Promtail EOL 2026-03-02 — 2026-09-20 확인. https://grafana.com/docs/loki/latest/send-data/promtail/ ↩︎
최신 버전 Loki 3.7.8 (2026-09-17) — 2026-09-20 확인. https://github.com/grafana/loki/releases ↩︎