Query Loki Logs with LogQL
MCP server for querying Grafana Loki logs with LogQL, via logcli or automatic HTTP API fallback.
Why it matters
Empower AI assistants to query and analyze logs stored in Grafana Loki using LogQL. This connector automatically falls back to the HTTP API if the logcli tool is unavailable.
Outcomes
What it gets done
Query Loki logs using LogQL syntax with filtering.
Retrieve all values for a specific log label.
Fetch all available log labels.
Configure authentication via environment variables or files.
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/vb-simple-loki-mcp | bash Capabilities
Tools your agent gets
Query logs from Loki with filtering options using LogQL syntax
Get all values for a specific label
Get all available labels
Overview
Simple Loki MCP Server
An MCP server for querying Grafana Loki logs with LogQL, using logcli when available and automatically falling back to the Loki HTTP API otherwise. Use to have Claude query and analyze Loki logs during debugging or incident response. Requires a reachable Loki instance and, if secured, matching auth configured via env vars or config file.
What it does
Simple Loki MCP Server is an MCP interface for querying Grafana Loki logs using logcli, letting AI assistants access and analyze log data directly. It exposes three tools: query-loki (runs a LogQL query with optional from/to timestamps, result limit, batch size, output format - default, raw, or jsonl - a quiet flag to suppress query metadata, and forward for chronological ordering), get-label-values (retrieves all values for a specified label), and get-labels (retrieves all available labels, no parameters).
{
"mcpServers": {
"simple-loki": {
"command": "npx",
"args": ["-y", "simple-loki-mcp"],
"env": {
"LOKI_ADDR": "https://loki.sup.band"
}
}
}
}
Configuration works via environment variables (LOKI_ADDR, LOKI_USERNAME/LOKI_PASSWORD for basic auth, LOKI_TENANT_ID, LOKI_BEARER_TOKEN or LOKI_BEARER_TOKEN_FILE, LOKI_CA_FILE/LOKI_CERT_FILE/LOKI_KEY_FILE for TLS, LOKI_ORG_ID for multi-org setups, LOKI_TLS_SKIP_VERIFY, LOKI_CONFIG_PATH, and DEBUG) or a logcli-config.yaml file located at a custom path, the current working directory, or the home directory.
The server automatically detects whether logcli is installed and available: if so, it uses logcli for all queries with its full CLI functionality; if not, it falls back to the Loki HTTP API directly with no additional configuration needed, using the same authentication parameters and producing response formatting consistent with the CLI output. Both modes apply a default limit of 1000 logs per query. This automatic fallback means the server works the same way whether or not logcli is installed in the environment.
When to use - and when NOT to
Use this connector when you want Claude to query and analyze logs stored in Grafana Loki - running LogQL queries with time-range filtering, browsing available labels and their values, or investigating logs during debugging or incident response.
It requires access to a Loki server instance and, unless the instance is open, one of the supported authentication methods (basic auth, bearer token, TLS client cert, or multi-tenant org ID) configured via environment variables or a config file. Installing logcli is optional - the server works via HTTP API fallback without it, though logcli use yields the CLI tool's full functionality.
Capabilities
query-loki: run LogQL queries with time range, limit, batch size, output format, and ordering control. get-label-values: list all values for a given label. get-labels: list all available labels.
How to install
Install automatically via Smithery (npx -y @smithery/cli install @ghrud92/simple-loki-mcp --client claude), or configure directly with npx and the LOKI_ADDR environment variable in an MCP client's config. For development, clone the repository, run npm install, and npm run build; requires Node.js v16+ and TypeScript, with logcli optional in PATH.
Who it's for
DevOps, SRE, and platform engineers who want Claude to query and analyze Grafana Loki logs directly during debugging or incident response.
Source README
Simple Loki MCP Server
Loki MCP Server is a Model Context Protocol (MCP) interface for querying Grafana Loki logs using logcli. The server enables AI assistants to access and analyze log data from Loki directly.
Features
- Query Loki logs with full LogQL support
- Get label values and metadata
- Authentication and configuration support via environment variables or config files
- Provides formatted results in different output formats (default, raw, JSON lines)
- Automatic fallback to HTTP API when
logcliis not available in the environment
Prerequisites
- Node.js v16 or higher
- TypeScript
- (Optional) Grafana Loki logcli installed and accessible in your PATH. If
logcliis not available, the server will automatically use the Loki HTTP API instead - Access to a Loki server instance
Installation
Installing via Smithery
To install Simple Loki MCP Server for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @ghrud92/simple-loki-mcp --client claude
for MCP
{
"mcpServers": {
"simple-loki": {
"command": "npx",
"args": ["-y", "simple-loki-mcp"],
"env": {
"LOKI_ADDR": "https://loki.sup.band"
}
}
}
}
npm
- Clone the repository:
git clone https://github.com/ghrud92/loki-mcp.git
cd loki-mcp
- Install dependencies:
npm install
- Build the project:
npm run build
Available MCP Tools
query-loki
Query logs from Loki with filtering options.
Parameters:
query(required): Loki query string (LogQL)from: Start timestamp (e.g. "2023-01-01T12:00:00Z")to: End timestamp (e.g. "2023-01-01T13:00:00Z")limit: Maximum number of logs to returnbatch: Batch size for query resultsoutput: Output format ("default", "raw", or "jsonl")quiet: Suppress query metadataforward: Display results in chronological order
get-label-values
Retrieve all values for a specific label.
Parameters:
label(required): Label name to get values for
get-labels
Retrieve all available labels.
No parameters required.
Configuration
You can configure Loki access using:
Environment Variables
LOKI_ADDR: Loki server address (URL)LOKI_USERNAME: Username for basic authLOKI_PASSWORD: Password for basic authLOKI_TENANT_ID: Tenant ID for multi-tenant LokiLOKI_BEARER_TOKEN: Bearer token for authenticationLOKI_BEARER_TOKEN_FILE: File containing bearer tokenLOKI_CA_FILE: Custom CA file for TLSLOKI_CERT_FILE: Client certificate file for TLSLOKI_KEY_FILE: Client key file for TLSLOKI_ORG_ID: Organization ID for multi-org setupsLOKI_TLS_SKIP_VERIFY: Skip TLS verification ("true" or "false")LOKI_CONFIG_PATH: Custom path to config fileDEBUG: Enable debug logging
Note: When the client is using the HTTP API mode (when
logcliis not available), the same configuration parameters are used to authenticate and connect to the Loki server.
Config Files
Alternatively, create a logcli-config.yaml file in one of these locations:
- Custom path specified by
LOKI_CONFIG_PATH - Current working directory
- Your home directory (
~/.logcli-config.yaml)
Example config file:
addr: https://loki.example.com
username: user
password: pass
tenant_id: mytenant
Usage
Start the server:
npm start
For development:
npm run dev
Implementation Details
Automatic Fallback to HTTP API
The server will automatically check if logcli is installed and available in the environment:
- If
logcliis available, it will be used for all queries, providing the full functionality of the CLI tool - If
logcliis not available, the server will automatically fall back to using the Loki HTTP API:- No additional configuration is needed
- The same authentication parameters are used for the HTTP API
- Response formatting is consistent with the CLI output
- Default limit of 1000 logs per query is applied in both modes
This automatic detection ensures that the server works seamlessly in different environments without manual configuration.
Development
# Run linter
npm run lint
# Fix linting issues
npm run lint:fix
# Run tests
npm run test
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.