MCP Connector

Query Loki Logs with LogQL

MCP server for querying Grafana Loki logs with LogQL, via logcli or automatic HTTP API fallback.

Works with grafanaloki

90
Spark score
out of 100
Updated May 2025
Version 1.0.0
Models
universal

Add to Favorites

Why it matters

Empower AI assistants to query and analyze logs stored in Grafana Loki using LogQL. This connector automatically falls back to the HTTP API if the logcli tool is unavailable.

Outcomes

What it gets done

01

Query Loki logs using LogQL syntax with filtering.

02

Retrieve all values for a specific log label.

03

Fetch all available log labels.

04

Configure authentication via environment variables or files.

Install

Add it to your toolbox

Run in your project directory:

curl -fsSL https://spark.entire.vc/get/vb-simple-loki-mcp | bash

Capabilities

Tools your agent gets

query-loki

Query logs from Loki with filtering options using LogQL syntax

get-label-values

Get all values for a specific label

get-labels

Get all available labels

Overview

Simple Loki MCP Server

An MCP server for querying Grafana Loki logs with LogQL, using logcli when available and automatically falling back to the Loki HTTP API otherwise. Use to have Claude query and analyze Loki logs during debugging or incident response. Requires a reachable Loki instance and, if secured, matching auth configured via env vars or config file.

What it does

Simple Loki MCP Server is an MCP interface for querying Grafana Loki logs using logcli, letting AI assistants access and analyze log data directly. It exposes three tools: query-loki (runs a LogQL query with optional from/to timestamps, result limit, batch size, output format - default, raw, or jsonl - a quiet flag to suppress query metadata, and forward for chronological ordering), get-label-values (retrieves all values for a specified label), and get-labels (retrieves all available labels, no parameters).

{
  "mcpServers": {
    "simple-loki": {
      "command": "npx",
      "args": ["-y", "simple-loki-mcp"],
      "env": {
        "LOKI_ADDR": "https://loki.sup.band"
      }
    }
  }
}

Configuration works via environment variables (LOKI_ADDR, LOKI_USERNAME/LOKI_PASSWORD for basic auth, LOKI_TENANT_ID, LOKI_BEARER_TOKEN or LOKI_BEARER_TOKEN_FILE, LOKI_CA_FILE/LOKI_CERT_FILE/LOKI_KEY_FILE for TLS, LOKI_ORG_ID for multi-org setups, LOKI_TLS_SKIP_VERIFY, LOKI_CONFIG_PATH, and DEBUG) or a logcli-config.yaml file located at a custom path, the current working directory, or the home directory.

The server automatically detects whether logcli is installed and available: if so, it uses logcli for all queries with its full CLI functionality; if not, it falls back to the Loki HTTP API directly with no additional configuration needed, using the same authentication parameters and producing response formatting consistent with the CLI output. Both modes apply a default limit of 1000 logs per query. This automatic fallback means the server works the same way whether or not logcli is installed in the environment.

When to use - and when NOT to

Use this connector when you want Claude to query and analyze logs stored in Grafana Loki - running LogQL queries with time-range filtering, browsing available labels and their values, or investigating logs during debugging or incident response.

It requires access to a Loki server instance and, unless the instance is open, one of the supported authentication methods (basic auth, bearer token, TLS client cert, or multi-tenant org ID) configured via environment variables or a config file. Installing logcli is optional - the server works via HTTP API fallback without it, though logcli use yields the CLI tool's full functionality.

Capabilities

query-loki: run LogQL queries with time range, limit, batch size, output format, and ordering control. get-label-values: list all values for a given label. get-labels: list all available labels.

How to install

Install automatically via Smithery (npx -y @smithery/cli install @ghrud92/simple-loki-mcp --client claude), or configure directly with npx and the LOKI_ADDR environment variable in an MCP client's config. For development, clone the repository, run npm install, and npm run build; requires Node.js v16+ and TypeScript, with logcli optional in PATH.

Who it's for

DevOps, SRE, and platform engineers who want Claude to query and analyze Grafana Loki logs directly during debugging or incident response.

Source README

Simple Loki MCP Server

smithery badge

Loki MCP Server is a Model Context Protocol (MCP) interface for querying Grafana Loki logs using logcli. The server enables AI assistants to access and analyze log data from Loki directly.

Loki Server MCP server

Features

  • Query Loki logs with full LogQL support
  • Get label values and metadata
  • Authentication and configuration support via environment variables or config files
  • Provides formatted results in different output formats (default, raw, JSON lines)
  • Automatic fallback to HTTP API when logcli is not available in the environment

Prerequisites

  • Node.js v16 or higher
  • TypeScript
  • (Optional) Grafana Loki logcli installed and accessible in your PATH. If logcli is not available, the server will automatically use the Loki HTTP API instead
  • Access to a Loki server instance

Installation

Installing via Smithery

To install Simple Loki MCP Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @ghrud92/simple-loki-mcp --client claude

for MCP

{
  "mcpServers": {
    "simple-loki": {
      "command": "npx",
      "args": ["-y", "simple-loki-mcp"],
      "env": {
        "LOKI_ADDR": "https://loki.sup.band"
      }
    }
  }
}

npm

  1. Clone the repository:
git clone https://github.com/ghrud92/loki-mcp.git
cd loki-mcp
  1. Install dependencies:
npm install
  1. Build the project:
npm run build

Available MCP Tools

query-loki

Query logs from Loki with filtering options.

Parameters:

  • query (required): Loki query string (LogQL)
  • from: Start timestamp (e.g. "2023-01-01T12:00:00Z")
  • to: End timestamp (e.g. "2023-01-01T13:00:00Z")
  • limit: Maximum number of logs to return
  • batch: Batch size for query results
  • output: Output format ("default", "raw", or "jsonl")
  • quiet: Suppress query metadata
  • forward: Display results in chronological order

get-label-values

Retrieve all values for a specific label.

Parameters:

  • label (required): Label name to get values for

get-labels

Retrieve all available labels.

No parameters required.

Configuration

You can configure Loki access using:

Environment Variables

  • LOKI_ADDR: Loki server address (URL)
  • LOKI_USERNAME: Username for basic auth
  • LOKI_PASSWORD: Password for basic auth
  • LOKI_TENANT_ID: Tenant ID for multi-tenant Loki
  • LOKI_BEARER_TOKEN: Bearer token for authentication
  • LOKI_BEARER_TOKEN_FILE: File containing bearer token
  • LOKI_CA_FILE: Custom CA file for TLS
  • LOKI_CERT_FILE: Client certificate file for TLS
  • LOKI_KEY_FILE: Client key file for TLS
  • LOKI_ORG_ID: Organization ID for multi-org setups
  • LOKI_TLS_SKIP_VERIFY: Skip TLS verification ("true" or "false")
  • LOKI_CONFIG_PATH: Custom path to config file
  • DEBUG: Enable debug logging

Note: When the client is using the HTTP API mode (when logcli is not available), the same configuration parameters are used to authenticate and connect to the Loki server.

Config Files

Alternatively, create a logcli-config.yaml file in one of these locations:

  • Custom path specified by LOKI_CONFIG_PATH
  • Current working directory
  • Your home directory (~/.logcli-config.yaml)

Example config file:

addr: https://loki.example.com
username: user
password: pass
tenant_id: mytenant

Usage

Start the server:

npm start

For development:

npm run dev

Implementation Details

Automatic Fallback to HTTP API

The server will automatically check if logcli is installed and available in the environment:

  1. If logcli is available, it will be used for all queries, providing the full functionality of the CLI tool
  2. If logcli is not available, the server will automatically fall back to using the Loki HTTP API:
    • No additional configuration is needed
    • The same authentication parameters are used for the HTTP API
    • Response formatting is consistent with the CLI output
    • Default limit of 1000 logs per query is applied in both modes

This automatic detection ensures that the server works seamlessly in different environments without manual configuration.

Development

# Run linter
npm run lint

# Fix linting issues
npm run lint:fix

# Run tests
npm run test

FAQ

Common questions

Discussion

Questions & comments · 0

Sign In Sign in to leave a comment.