---
tags:
- observability
- l1
- flashcard-deck
- loki
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Loki](../../../../library/portal/topics.md) | **Domain:** Observability
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
loki/a1c2e3f4b5d6	loki	easy	loki, architecture	How does Loki differ from Elasticsearch in its indexing approach?	Loki indexes only labels (metadata), not the full log content. This makes it much cheaper to operate than Elasticsearch, which indexes all log text.\n\nRemember: Loki indexes labels only. Query content with LogQL filter expressions.	training/library/topics/log-pipelines/primer.md
loki/b2d3f4a5c6e7	loki	easy	loki, logql, querying	How do you select a log stream in LogQL?	Using a stream selector with labels in curly braces, e.g., {app="nginx", namespace="production"}.\n\nRemember: LogQL: label matchers + pipelines. |= contains, != not, |~ regex.\n\nExample: {app="nginx", namespace="production"} |= "error" selects nginx logs in production containing error.\n\nName origin: Loki is named after the Norse trickster god — lighter than Elasticsearch, just as Loki is lighter than Thor.	training/library/topics/observability-deep-dive/primer.md
loki/c3e4a5b6d7f8	loki	easy	loki, promtail, collection	What is Promtail and what role does it play in the Loki ecosystem?	Promtail is a log collection agent that ships log entries to Loki. It tails log files, attaches labels, and forwards them to Loki for indexing and storage.\n\nRemember: Loki = "Prometheus for logs." Indexes labels, not content. Lightweight.\n\nFun fact: Grafana Labs created it. Same label approach as Prometheus.	training/library/topics/log-pipelines/primer.md
loki/d4f5b6c7e8a9	loki	medium	loki, logql, filtering	How do you filter logs by content in LogQL?	Use pipe operators: |= for contains, != for not contains, |~ for regex match, !~ for not regex match. Example: {app="nginx"} |= "error" != "healthcheck".\n\nRemember: LogQL: label matchers + pipelines. |= contains, != not, |~ regex.	training/library/topics/observability-deep-dive/primer.md
loki/e5a6c7d8f9b0	loki	medium	loki, logql, parsing	How do you parse structured fields from logs in LogQL?	Use parser stages: | json for JSON logs, | logfmt for logfmt, or | pattern with a template. After parsing, you can filter on extracted fields, e.g., {app="nginx"} | json | status >= 400.\n\nRemember: LogQL: label matchers + pipelines. |= contains, != not, |~ regex.	training/library/topics/log-pipelines/primer.md
loki/f6b7d8e9a0c1	loki	medium	loki, logql, metrics	How do you derive metrics from logs using LogQL?	Use metric functions on log queries: count_over_time({app="nginx"} |= "error" [5m]) counts matching log lines, rate() computes per-second rate, and sum by (label) aggregates across streams.\n\nRemember: LogQL: label matchers + pipelines. |= contains, != not, |~ regex.	training/library/topics/observability-deep-dive/primer.md
loki/a7c8e9f0b1d2	loki	medium	loki, labels, design	Why should you keep label cardinality low in Loki?	High-cardinality labels (e.g., request_id, user_id) create too many unique streams, which bloats Loki's index and degrades query performance. Use a small set of bounded labels like namespace, app, and environment.\n\nGotcha: High cardinality kills Loki. ~10-15 values per label max. No request IDs.	training/library/topics/observability-deep-dive/primer.md
loki/b8d9f0a1c2e3	loki	hard	loki, logql, aggregation	How would you find the top error paths from Nginx logs in the last hour using LogQL?	sum by (path) (count_over_time({app="nginx"} | json | status >= 500 [1h])) — this parses JSON, filters for 5xx status codes, counts over one hour, and groups by the path field.\n\nRemember: LogQL: label matchers + pipelines. |= contains, != not, |~ regex.	training/library/topics/observability-deep-dive/primer.md
loki/c9e0a1b2d3f4	loki	hard	loki, retention, storage	How does Loki's storage architecture handle log retention?	Loki stores log chunks in object storage (S3, GCS) and indexes in a key-value store (BoltDB, DynamoDB). Retention is configured per-tenant with compaction rules that delete chunks older than the retention period.\n\nRemember: Loki indexes labels only. Query content with LogQL filter expressions.	training/library/topics/log-pipelines/primer.md
loki/d0f1b2c3e4a5	loki	hard	loki, alerting, ruler	How do you create alert rules in Loki using the Loki Ruler?	Define LogQL metric queries in alert rule YAML groups, similar to Prometheus alert rules. Example: sum(rate({namespace="app"} |= "level=error" [5m])) > 1 with a for duration and severity labels. The Loki Ruler evaluates these and sends to Alertmanager.\n\nRemember: Loki indexes labels only. Query content with LogQL filter expressions.	training/library/topics/log-pipelines/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- Incident Simulator (18 scenarios) *(CLI)* (Exercise Set, L2) — Loki
- [Interview: Loki Logs Disappeared](../../../../library/interview-scenarios/04-loki-logs-disappeared.md) (Scenario, L2) — Loki
- Lab: Loki No Logs *(CLI)* (Lab, L2) — Loki
- [Log Pipelines](../../../../library/topics/log-pipelines/index.md) (Topic Pack, L2) — Loki
- [LogQL Drills](../../../../library/drills/logql_drills.md) (Drill, L2) — Loki
- [Observability Architecture](../../../../library/guides/observability.md) (Reference, L2) — Loki
- [Observability Deep Dive](../../../../library/topics/observability-deep-dive/index.md) (Topic Pack, L2) — Loki
- [Observability Drills](../../../../library/drills/obs_drills.md) (Drill, L2) — Loki
- [Runbook: Log Pipeline Backpressure / Logs Not Appearing](../../../../library/runbooks/observability/log-pipeline-backpressure.md) (Runbook, L2) — Loki
- [Runbook: Loki No Logs](../../../../library/runbooks/observability/loki_no_logs.md) (Runbook, L2) — Loki

<!-- wiki:related:end -->
