1) systemd logs (binary data stored at /var/log/journal)
2) docker logs (from various containers running on the host)
Any hints on getting this working? I don't see this covered in the docs (https://docs.lnav.org/en/latest/formats.html).
journalctl -o json | lnavUntil now I thought logview.el[0] is the bee's knees, but now I can feel feature envy set in. There are some seriously powerful ideas listed on the lnav page, and it's also the first time I saw SQLite virtual tables used in the wild.
--
It works by uploading a stub that is an "actually portable executable" to the remote over ssh. lnav then talks to the stub to sync files back to the local host. I don't know the scale of the hosts or files, but if they're not too big, it might work fine.
Seems to be packaged quite widely https://repology.org/project/lnav/versions
$ multitail /var/log/install.log -I /var/log/system.log
You get a view with the tail from one file followed by the tail from the other, they are not collated by timestamp. In contrast, if you do the same thing in lnav: $ lnav /var/log/install.log /var/log/system.log
You will get a single view with all of the log messages from both files and they're sorted by their timestamps. Here is all of what lnav is doing: * Monitoring files/directories for updates
* Decompressed files/archives
* Detected the log format for each file
* Created SQLite vtables that provide access to log messages
* Built an index of all the log messages in all the files so
you can jump to a certain point in time or to the
next/previous error message.
* Display all log messages with syntax highlightingI second the above, just one pain point with multitail to add. I often page/search/filter in the scrollback buffer (I typoed "bugger" - Freudian slip?) and in multitail the scrollback is a separate window with a frame and everything, which is a pain (copying whole lines using mouse includes the frame, ugh). The filtering/searching being a separate pain.
One thing I used in multitail and not sure if I migrated wholly to lnav was log file syntax highlighting using regexes.
* powerful filtering (including with regex)
* smooth scrolling of millions of rows of data
* support for csv, text, xml, json, Excel and other formats
* available for Window and Mac