github VictoriaMetrics/VictoriaLogs v1.53.0

5 hours ago

Released at 2026-10-01

Update note 1: the /internal/force_merge, /internal/force_flush, /internal/log_new_streams and /internal/partition/* HTTP endpoints now require the POST method for security reasons, in order to prevent GET-based SSRF attacks. Update any scripts or automation calling these endpoints via GET to use POST. See #1635.

Update note 2: requests to /select/vmalert/-/reload and other /select/vmalert/* paths ending with /config or /reload now require the -httpAuth.* credentials for security reasons. Previously, such requests were proxied to vmalert without checking the credentials. Add the credentials to any scripts calling these paths. See VictoriaMetrics#11548.

  • SECURITY: upgrade Go builder from Go1.26.5 to Go1.27.1. See the list of issues addressed in Go1.26.6, Go1.27 release notes and the list of issues addressed in Go1.27.1.

  • SECURITY: deletion API: restrict the /delete/run_task endpoint to the POST method only in order to prevent some SSRF-based log deletion attacks. See #1635.

  • FEATURE: support for accepting HTTP requests over Unix domain socket via -httpListenAddr=unix:/path/to/socket command-line flag. The socket file permissions are determined by the umask of the process. See these docs and #1618.

  • FEATURE: deletion API: add the -deleteAuthKey command-line flag for protecting the /delete/* endpoints with a dedicated authKey. This allows restricting who can delete logs independently of -httpAuth.*. See #1749.

  • FEATURE: cluster version: apply -search.logSlowQueryDuration to vlstorage nodes too, so slow queries are logged, along with the waitDuration, by the vlstorage node which executed them and not only by the coordinating vlselect node. See #1712. Thanks to @shraddhaag for the pull request #1740.

  • FEATURE: cluster version: optimize queries, which return the limited number of log entries with the biggest timestamps on the selected time range. Web UI usually executes such queries. See #1602.

  • FEATURE: dashboards/cluster, dashboards/single, and dashboards/vlagent: add Fsync avg duration panel to the Troubleshooting section of the single-node, cluster, and vlagent dashboards. This panel shows average fsync latency to help identify slow storage persistence. See VictoriaMetrics#10432.

  • FEATURE: dashboards/cluster and dashboards/single: add Compression ratio time series panel to the Storage section of the single-node dashboard and to the vlstorage section of the cluster dashboard. It shows how the compression ratio changes over time, so it is easy to see how changes such as new stream fields or log parsing at ingestion affect the needed disk space. See #1738.

  • FEATURE: web UI: add an option to customize the favicon color. This makes it easier to distinguish between different installations opened in multiple browser tabs. See #1634.

  • FEATURE: web UI: improve field action usability in the expanded log entry view by removing the rarely used Copy action, exposing Exclude for quick access and moving action icons closer to field values. See #1663.

  • FEATURE: web UI: add a Back action to the Hits chart for restoring the previous time range after zooming or panning the chart. See #1535.

  • FEATURE: web UI: persist the Hits chart visibility preference in browser local storage. See #1559.

  • FEATURE: web UI: show the selected time zone UTC offset next to the date/time controls and allow opening time zone settings from it.

  • FEATURE: web UI: hide the Stacked toggle on the Hits chart when Group by is set to none. See #1629.

  • FEATURE: web UI: visually distinguish stream fields in expanded log entries and active filters, and automatically use stream filters for include and exclude actions on stream fields. See #1607.

  • FEATURE: web UI: improve the Stream fields sidebar with search across field names and loaded values, sorting by hits or name, selected items pinned to the top, and an Any value option inside expanded fields. See #1236.

  • FEATURE: web UI: move auto-refresh settings from the header to the Execute button dropdown. See #11343.

  • FEATURE: web UI: add incremental loading for slow hits queries, showing progress and allowing users to narrow the time range before loading completes. See #1645.

  • FEATURE: querying: add waitDuration to the slow query log line emitted according to -search.logSlowQueryDuration, so it is easy to tell whether a slow query spent its time waiting for a free concurrency slot or actually executing. See #1683.

  • FEATURE: docs/integrations: add integration with Logchef, a query and UI layer that uses VictoriaLogs as datasource.

  • FEATURE: Kubernetes Collector: add a new field output_stream that indicates whether CRI log lines are from stdout or stderr, allowing logs to be quickly filtered by output stream at query time. See #1790

  • FEATURE: web UI: prefix each displayed field value with its field name in the Group view, so multi-field rows stay readable. The _msg field is shown without a prefix. See #1632.

  • BUGFIX: hide values passed to -pushmetrics.header in startup logs, /metrics and /flags, since they can contain sensitive HTTP headers such as Authorization. See VictoriaMetrics#11545.

  • BUGFIX: security: make the -deleteAuthKey, -logNewStreamsAuthKey and -partitionManageAuthKey command-line flags override -httpAuth.* as documented. Previously, requests to /delete/*, /internal/log_new_streams and /internal/partition/* had to pass both the authKey and the -httpAuth.* credentials. See #1764.

  • BUGFIX: Loki data ingestion: properly ignore structured metadata with empty values in protobuf requests. Previously, valid requests containing structured metadata with empty values were rejected. See #1757.

  • BUGFIX: metrics: prevent vl_streams_created_total from decreasing when an old daily partition is removed. The metric now increases until restart, so Prometheus increase() no longer reports false spikes after old partitions are deleted. See #1461.

  • BUGFIX: syslog data ingestion and unpack_syslog pipe: prevent a panic when an incomplete RFC5424 structured data parameter ends immediately after =. This could occur both when ingesting syslog messages and when parsing already stored messages with unpack_syslog. See #1786.

  • BUGFIX: syslog data ingestion: rename the misspelled vl_udp_reqests_total metric to vl_udp_requests_total, so it matches the docs.

  • BUGFIX: cluster version (vlinsert): now drains buffered logs to vlstorage nodes on graceful shutdown instead of dropping them, bounded by the new -insert.drainTimeout command-line flag (default 5s). See #1572.

  • BUGFIX: cluster version: evenly spread rerouted data across available vlstorage nodes. Previously, healthy nodes adjacent to unavailable nodes in the -storageNode list could receive much more data, resulting in uneven resource usage. See #1548.

  • BUGFIX: cluster version: properly cancel queries already running on vlstorage when the corresponding query is canceled or times out on vlselect. Previously, vlstorage could fail to detect the disconnected vlselect, causing these queries to continue running and waste CPU and disk IO. See #1672.

  • BUGFIX: data ingestion and querying: properly handle logs containing duplicate stream field names. Previously, v1.52.0 could panic when ingesting such logs in single-node VictoriaLogs, drop them during ingestion in VictoriaLogs cluster, or panic when querying such data written by earlier releases. See #1603 and #1604.

  • BUGFIX: LogsQL: fix week_range[Sun,Sun] filter when it is used inside the filter pipe. Previously, it could fail to match rows on Sunday. See #1335.

  • BUGFIX: LogsQL: properly execute queries returning the last N logs (such as queries ending with | sort by (_time desc) limit N) when they contain pipes writing to the _time field, such as math ... as _time, replace (...) at _time or extract "<_time>". Previously such queries could fail with the missing _time field in the query results error or return logs in the wrong order when they were executed on wide time ranges. See #1727.

  • BUGFIX: LogsQL: fix sort by (_time) limit N returning logs out of order when the query pipeline included pipes like unpack_json that overwrite _time. See #1360.

  • BUGFIX: LogsQL: fix a crash when the math pipe contains a quoted constant such as "2025-01-01T00:00:00Z", and the query is executed with the limit query arg (the web UI always sets it) or via live tailing.

  • BUGFIX: web UI: prevent long group-by values from overflowing group headers. See #1663.

  • BUGFIX: web UI: render only inline Markdown links with explicit http or https destinations, such as [text](https://example.com), as clickable links in log messages. Bare URLs, autolinks, reference-style links, links using other schemes, and images are rendered as plain text. See #1470.

  • BUGFIX: web UI: prevent manually entered time ranges from shifting after Apply when using non-UTC time zones.

  • BUGFIX: web UI: fix bar chart tap, pan, and pinch-to-zoom interactions on mobile devices.

  • BUGFIX: web UI: fix the Table view to show all logs when All is selected for Rows per page. Previously, the table showed no rows in this case. See #1661.

  • BUGFIX: web UI: show a dash placeholder for a log entry that has none of the selected display fields in the Group view, instead of dumping the whole entry. See #1653.

  • BUGFIX: web UI: display the systemd-compatible notice, crit, alert, and emerg log level labels instead of collapsing them into info and fatal. See #1543.

  • BUGFIX: web UI: keep the query autocomplete details panel open when interacting with it, so documentation links open and description text remains selectable. See #1810.

  • BUGFIX: File Collector: ignore permission denied error when trying to find a rotated log file from previous runs during startup. Previously, vlagent failed with non-zero error code if it couldn't open a file in the same directory as log file. See #1796.

  • BUGFIX: File Collector: properly set the file field for logs collected from multiple files matching the same -fileCollector.glob when -fileCollector.extraFields is set. Previously, depending on the number of extra fields, logs from one file could be stored with the file field and the log stream of another file. See #1818.

  • BUGFIX: File Collector: incomplete last log lines are no longer joined with the first line of the rotated file. They are dropped with a warning instead. This matches the behavior of other log collectors. See #1819.

  • BUGFIX: File Collector: drop the incomplete last log line with a warning when the log file is deleted. Previously, vlagent treated this case as a bug and panicked. See #1552.

Don't miss a new VictoriaLogs release

NewReleases is sending notifications on new releases.