loki-tail-mcp
Provides tools for querying and analyzing logs from Grafana Loki, including tailing container logs, raw LogQL range and instant queries, listing containers/labels/values, discovering log patterns, and ranking log volume.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@loki-tail-mcpWhat is the proxy service saying?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
loki-tail-mcp
An MCP server for Grafana Loki, designed around how LLMs actually query logs: compact output, hard row caps, and a fuzzy container-name rescue that turns the classic empty-result-because-wrong-name failure into an auto-corrected retry or an actionable suggestion list. Built on the Python MCP SDK (FastMCP); runs as a local stdio server or a containerized Streamable HTTP service with bearer auth.
Tools
Tool | Notes |
| "What is service X saying?" — the primary tool. Accepts approximate names: service vocabulary ( |
| Raw LogQL range query — multi-container correlation ( |
| Instant query at a point in time (metric queries). |
| Durable container names (ephemeral CI/batch names hidden). |
| Raw label discovery. |
| Log pattern mining — thousands of lines → ranked recurring templates with counts. Requires the server-side pattern ingester ( |
| Rank containers by log bytes over a window — "which service suddenly got noisy". |
| Fields Loki can auto-extract from a stream (name/type/cardinality/parser) — discover |
The name-resolution design
Matching always runs against live label values, never a hardcoded
list, so it survives renames. Resolution tries, in order: exact match →
alias vocabulary → substring both ways → typo distance (difflib). A
unique candidate is tailed automatically and flagged; multiple candidates
become a ranked suggestion list. Auto-generated container names
(docker/podman adjective_noun, hex-suffixed batch workers) are filtered
out of discovery and suggestions but stay queryable via raw LogQL.
The built-in alias vocabulary covers the common self-hosted stack
(vpn→gluetun, proxy→traefik, movies→radarr, …). Entries whose
targets don't exist in your fleet are inert; extend with your own via
LOKI_ALIASES.
Related MCP server: Loki MCP Server
Quick start (stdio)
// e.g. Claude Desktop claude_desktop_config.json / Claude Code .mcp.json
{
"mcpServers": {
"loki": {
"command": "uv",
"args": ["run", "--project", "/path/to/loki-tail-mcp", "loki-tail-mcp", "--stdio"],
"env": { "LOKI_URL": "http://your-loki-host:3100" }
}
}
}stdio mode has no network surface and skips bearer auth — the client owns the process.
HTTP mode (container)
The bundled Containerfile builds a Streamable HTTP server at /mcp
(stateless — restarts never strand client sessions). HTTP mode refuses
to start without MCP_BEARER_TOKEN; clients authenticate with
Authorization: Bearer <token>.
podman build -t loki-tail-mcp . # or: docker build -t loki-tail-mcp .
podman run -d --name loki-tail-mcp -p 8325:8325 \
-e LOKI_URL=http://your-loki-host:3100 \
-e MCP_BEARER_TOKEN=some-long-random-token \
loki-tail-mcploki_tail_mcp.healthcheck does a full HTTP round-trip to /mcp (the 401
counts as alive); wire it to your container healthcheck. Terminate TLS at
a reverse proxy — the server itself speaks plain HTTP.
Configuration
Env var | Default | Purpose |
|
| Loki base URL. |
| (empty) | Sent as |
| (empty) |
|
|
| Upstream request timeout (s). |
|
| Row caps — Loki will happily return millions of rows; an MCP client will happily feed them to an LLM. Neither is what you want. |
| (empty) | Extra vocabulary merged over the built-ins: |
| (built-ins) | Comma-separated regexes marking names as ephemeral; replaces the defaults when set. |
|
| HTTP listen port. |
| (empty) | Required in HTTP mode; server refuses to start without it. Not used in |
Testing
# Full suite — mocked HTTP + pure resolution logic, no Loki needed
uv run --extra test pytest tests/ -vLicense
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceAn MCP server that enables querying logs and metrics from Graylog, Prometheus, and InfluxDB 2.x. It provides tools for executing Lucene log searches, PromQL queries, and Flux queries directly within MCP-compatible clients.Last updatedMIT
- AlicenseBqualityDmaintenanceAn MCP server for querying Grafana Loki directly with a discovery-first workflow — labels, values, series, and LogQL queries without requiring Grafana.Last updated55MIT
- Alicense-qualityDmaintenanceThis MCP server enables natural-language querying of Grafana logs by automatically detecting log sources and service labels. It provides read-only access to log data with intelligent caching for efficient repeat queries.Last updated50MIT
- FlicenseBqualityDmaintenanceA log analysis MCP server that enables tailing, searching, filtering, and summarizing logs from local files and Docker containers.Last updated7
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Local-first RAG engine with MCP server for AI agent integration.
An MCP server giving access to Grafana dashboards, data and more.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/snickery/loki-tail-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server