Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Grafana Loki is a horizontally scalable log aggregation system that indexes a log stream’s labels—not the full text of every log line—and stores the lines in compressed chunks. During a query, labels narrow the streams Loki must inspect, then LogQL can filter the matching log content. This design keeps the index comparatively small, but makes careful label selection central to a useful and efficient Loki setup.

What Grafana Loki is—and what its design means

Loki is a log aggregation system inspired by Prometheus. It is designed to scale horizontally and can serve multiple tenants. Its defining trade-off is to index metadata labels that identify log streams rather than index every word in every log line. The log content remains searchable: Loki first uses a label selector to find candidate streams, then scans relevant log data and applies further LogQL filters.

That separation of index and log data can reduce index size and storage cost compared with indexing full log contents. It also means that broad or poorly chosen labels can make queries less selective, while an attempt to turn every changing value into a label can create excessive stream cardinality. The Loki overview describes the system and its design.

How Loki organizes and searches logs

Streams, labels, and entries

A log stream is a set of log entries that share the same label set. Every stream needs at least one label. Labels typically identify relatively stable aspects of the source, such as an application or environment. Loki does not require log lines to follow one fixed schema when they are ingested.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Dell PowerEdge R730xd Server 24B SFF 2U, 2X Intel Xeon E5-2690 v4 2.6Ghz (28-cores Total), 128GB DDR4 RAM, 4X 1.2TB 10K SAS 2.5” 12Gb/s HDD, H730P 2GB RAID, NIC 10Gb + I350 1Gb (Renewed)
  • Dell PowerEdge R730xd 24B SFF 2U Server
  • 2x Intel Xeon E5-2690 v4 2.6Ghz 14-Core (28-cores Total)
  • 128GB DDR4 RAM – 4x 1.2TB 10K SAS 2.5” 12Gb/s
  • Dell H730P mini 2GB 12Gb/s RAID
  • 2x 750W PSU - 2x 10Gb SFP+ 2x 1Gb (RJ45) NIC

For example, a stream might have labels identifying a service and environment, while individual entries contain changing request details. A query can select streams using those labels and then filter their lines for a term or other LogQL condition. The label guide explains streams and label design.

Why cardinality matters

Cardinality rises when a label can take many distinct values. Labels that change for nearly every request—such as request IDs, user IDs, or similarly unique values—can create many distinct label sets and streams. Prefer labels with a small, useful set of values for source identification and query scoping.

Rank #2
Dell Optiplex 7050 SFF Desktop PC Intel i7-7700 4-Cores 3.60GHz 32GB DDR4 1TB SSD WiFi BT HDMI Duel Monitor Support Windows 11 Pro Excellent Condition(Renewed)
  • Model: Dell OptiPlex 7050 Small Form Factor (SFF)
  • Processor: Intel Core i7-7700 3.60 GHz
  • Memory: 32GB DDR4 Ram
  • Storage: 1TB Solid State Drive (SSD) Fast Boot + Storage
  • Operating System: Windows 11 Pro (64-bit)

When a frequently searched value is high-cardinality, use structured metadata rather than making it a stream label. This keeps the label set focused while retaining useful searchable fields. The right boundary depends on how logs are queried, but a practical test is whether a value identifies a source category or mostly identifies one event.

Index, chunks, and query path

Loki keeps a relatively small index for labels and stores log entries separately in compressed chunks. A query uses its label selector to identify candidate streams; Loki then reads the relevant chunks and evaluates content filters. Consequently, a query that begins with useful labels can limit the data that needs inspection, while a content filter does not mean Loki maintains a full-text index of all lines.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Hewlett Packard Enterprise ProLiant MicroServer Gen11 Tower Server with Intel Xeon 6315P, 16GB DDR5, 4LFF Bays, 180W PSU (P86811-005)
  • 2.80 GHz processor speed ensures efficient operation with consistent reliability
  • Intel Xeon 2.80 GHz processor provides enterprise-grade performance with built-in security and remote management capabilities
  • Quad-core (4 Core) processor core helps server process data quickly and reliably for maximum productivity
  • 1 processors supported for faster processing and improved access to data, optimizing performance under heavy loads
  • With 16 GB memory, you can multitask between applications seamlessly, keeping productivity high and response times quick

From log collection to Grafana

A common setup uses Grafana Alloy to discover or tail logs, add labels or transform records, and push the resulting log data to Loki. Loki ingests and stores the data and evaluates LogQL queries. Grafana can connect to Loki as a data source for exploration and visualization. Alloy is one possible collection component, not a mandatory part of Loki.

  1. Collect: Configure a log agent, such as Alloy, to discover or tail the files or sources you need.
  2. Prepare: Apply source-oriented, low-cardinality labels and transformations; keep frequently searched high-cardinality values in structured metadata.
  3. Send and store: Push logs to Loki, where they are organized into streams and persisted as chunks with a separate index.
  4. Query: In Grafana or another Loki client, use a LogQL label selector to choose streams, then add filters to inspect their log lines.
  5. Explore: Use Grafana to examine query results and build visualizations where useful.

Grafana’s Loki tutorial walks through a common collection and query flow, while the getting-started guide links to the product’s introductory material.

Rank #4
HPE Hewlett Packard Enterprise ProLiant MicroServer Gen11 Tower Server, Intel Pentium Gold G7400 Processor, 16GB Memory, 1TB HDD Storage, External 180W US Power Supply Smart Choice P74439-005
  • MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
  • READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
  • WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
  • INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
  • EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance

What Loki components do

Loki can run its functions together or distribute them among processes. The component names describe roles in the write path, read path, and supporting work; a deployment does not necessarily run each as an independently managed service.

Component or group Role
Distributor Part of the write path: receives incoming log data and routes it into the ingestion system.
Ingester Builds streams into chunks and flushes them to backing storage. The component documentation also describes its write-ahead log and replication behavior.
Query Frontend and Querier Part of the read path: coordinate and execute queries against stored log data.
Query Scheduler, Index Gateway, Compactor, and Ruler Additional components used for query scheduling, index access, compaction, and rule-related work, depending on the deployment arrangement.

These roles and their relationships are described in Grafana’s Loki components reference. The component mix is an architectural choice rather than a checklist that every installation must expose separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
HP Z4 G4 Workstation, Intel Xeon W-2133 (6-Core) up to 3.9GHz, 64GB DDR4, 512GB NVMe M.2 SSD + 2TB HDD, Nvidia Quadro P400 2GB, USB 3.1, Windows 11 Pro (Renewed)
  • HP Z4 G4 Workstation Tower
  • Intel Xeon W-2133 6-Core 3.6GHz (3.9GHz Turbo)
  • 64GB DDR4 Memory - Nvidia Quadro P400 2GB
  • 512GB NVMe M.2 SSD (boot) + 2TB HDD (storage)
  • Windows 11 Pro 64-bit
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Deployment modes: one process or separated components

Loki supports single-binary mode, arrangements that group components into read, write, and backend targets, and microservices mode, where components run separately. These choices trade operational simplicity against independent scaling and separation of read and write capacity.

Arrangement Operational shape When to consider it
Single binary Components run together, reducing the number of parts to configure and operate. Learning, local evaluation, or a deployment whose requirements fit a combined process.
Grouped targets Components are organized into read, write, and backend targets. When separating broad workload responsibilities is useful without operating every component individually.
Microservices Components run separately, allowing more granular operational separation and scaling. When workload and operational requirements justify the additional component complexity.

There is no universally best mode without knowing the workload, operating capacity, and Loki version. Grafana’s current local quickstart demonstrates Simple Scalable Deployment (SSD), but marks SSD deprecated and scheduled for removal in Loki 4.0. Treat it as a quickstart example, not a default recommendation for a new production design; consult the current components reference for deployment guidance.

Storage choices and version-sensitive guidance

Loki separates its label index from compressed log chunks. Object stores such as Amazon S3, Google Cloud Storage, and Azure Blob Storage are examples of backing storage. Filesystem storage can be useful for local development. Grafana’s Helm storage guidance recommends object storage for production deployments, while noting that single-binary installations can use filesystem storage.

Index-store guidance is version-dependent: Grafana recommends TSDB for Loki 2.8 and newer, and current storage documentation describes BoltDB as deprecated. Check the documentation for the Loki version and deployment method you are actually running rather than treating either recommendation as timeless. See Loki storage documentation and storage configuration for Helm.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical decisions before you deploy

  • Choose labels for source identity: Use stable, low-cardinality labels to select relevant streams; put frequently searched high-cardinality values in structured metadata.
  • Plan storage for the context: Filesystem storage can suit local development or a single-binary setup; production Helm deployments are directed toward object storage in Grafana’s current guidance.
  • Match deployment mode to operations: A combined process minimizes component separation; grouped targets or microservices can separate responsibilities when workload demands justify the added complexity.
  • Verify version-specific guidance: Confirm the supported index store, storage configuration, and recommended deployment mode against the documentation for your Loki release, especially before adopting an older quickstart pattern.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.