Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add loki.enrich component #2882

Open
wants to merge 21 commits into
base: main
Choose a base branch
from
Open

Add loki.enrich component #2882

wants to merge 21 commits into from

Conversation

v-zhuravlev
Copy link
Contributor

@v-zhuravlev v-zhuravlev commented Mar 2, 2025

PR Description

This PR adds a new loki.enrich component that enriches Loki logs with labels from discovery.* components.
The component matches a label from incoming logs against a label from discovered targets, and copies specified labels from the matched target to the log entry.

Features:

  • Copy selected labels from matched targets to logs
  • Support for any discovery component (file, DNS, HTTP, etc.)

Example use cases to ensure bets logs-metrics correlation:

  • Enrich Network devices syslog messages with device metadata(as labels) from IP address management (IPAM)/Data center infrastructure management(DCIM) like Netbox (https://github.com/FlxPeters/netbox-plugin-prometheus-sd). It could be same labels as used by prometheus.exporter.snmp or other metric scrapers.
  • Ensure metrics and logs use same labelset (gathered from same discovery.* component) even if metrics are scraped from prometheus endpoints and logs are received via loki.source.api.

Notes to the Reviewer

  • loki.enrich forwards logs unchanged if no match is found
  • loki.enrich should work with any discovery.* component. Best combined with discovery.relabel to rename hidden labels if present.
  • The integration test demonstrates:
    • Sample log pushed via HTTP API and then additional labels added using file-based discovery sample

PR Checklist

  • CHANGELOG.md updated
  • Documentation added
  • Tests updated
  • Config converters updated

Copy link
Contributor

github-actions bot commented Mar 2, 2025

💻 Deploy preview deleted.

@v-zhuravlev v-zhuravlev changed the title Add loki.enricher component (WIP) Add loki.enrich component (WIP) Mar 3, 2025
@v-zhuravlev v-zhuravlev changed the title Add loki.enrich component (WIP) Add loki.enrich component Mar 4, 2025
@v-zhuravlev v-zhuravlev marked this pull request as ready for review March 4, 2025 22:54
@v-zhuravlev v-zhuravlev requested review from clayton-cornell and a team as code owners March 4, 2025 22:54
@v-zhuravlev v-zhuravlev requested a review from wildum March 4, 2025 23:05
@v-zhuravlev v-zhuravlev closed this Mar 5, 2025
@v-zhuravlev v-zhuravlev reopened this Mar 5, 2025
@v-zhuravlev
Copy link
Contributor Author

Similar functionality, but not applicable to syslog as of now: https://grafana.com/docs/alloy/latest/reference/stdlib/array/#arraycombine_maps

@v-zhuravlev v-zhuravlev mentioned this pull request Mar 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant