Skip to content

What do you use for log aggregation on 1GB RAM?

VPS Hosting by lucgone 24 replies 2.8K views
4 #1

Hello! Since 2 days I try to install something for log aggregation on my small VPS, it is possible to do that with only 1GB RAM? I have make test with Elastic but it is very very heavy, OOM killer come every time lol. My budget is tight, I use OVHcloud 1GB plan for small project. I search something lightweight, maybe Loki? Or other? I have see Vector but I am not sure if it is for aggregation or only ship logs. Mdr this is confusing for me

My setup: 3 VPS total, all debian, I want central place for nginx and application logs. Not need fancy dashboard, just search and filter. Thank you for advice!

Vive la résistance... électrique
#2

Loki is perfect for this

#3

Loki with boltdb shipper and no Grafana will run on 512MB! Swap is your friend! I run this on a toaster at work!

Seriously though disable the indexer or limit it! Defaults are for people with money! Which is not us! 💀

#4

Loki single binary is a steal at that footprint ngl. But have you checked if OVHcloud charges extra for egress? Some deals aren't deals when you factor log volume — https://www.ovhcloud.com/en/vps/.

I ran promtail + loki on 512MB with 2GB swap for 6 months. Was fine. Not blazing, but fine.

airgapped, encrypted, faraday'd, still worried
#5

Bro loki very very possible with swap. Gan I run on 768MB before, cheap cheap setup. You need add swap 2GB or 3GB. Then set memory limit in config. Also disable unnecessary thing. Dont use grafana if no need, just query with logcli. I help you if stuck bro...

# /etc/systemd/system/loki.service.d/override.conf
[Service]
MemoryMax=700M
#6

You said 1GB. Is that 1GB with burst or dedicated? Because if it's KVM with dedicated 1GB you can probably run loki + promtail + lightweight query frontend. But if it's OpenVZ with oversold memory, forget it.

I run loki on a 64GB box at work, barely touches 4GB with 50K logs/sec. Humblebrag but relevant—your constraint is I/O not RAM probably. Check if OVHcloud gives you NVMe or spinning rust. That matters more than the RAM.

#7

You didn't finish your setup line. How many VPS are sending logs?

airgapped, encrypted, faraday'd, still worried
7 #8

Ah yes sorry! 3 VPS total, all send logs to central. 2 are OVHcloud in Gravelines, 1 is Hetzner in Helsinki. All 1GB RAM. So central Loki receive from 3 sources. I will try with swap 3GB and MemoryMax like surabayacandle say. OVHcloud give NVMe on this plan I think? At least it feel fast.

Vive la résistance... électrique
#9
lucgone said:
OVHcloud give NVMe on this plan I think?

OVHcloud VPS in Gravelines is KVM with NVMe since 2022. I have same plan, confirmed. But check your Hetzner egress to OVHcloud, that is not free bandwidth. Hetzner charge 1 EUR per TB over limit, OVHcloud incoming is free but outgoing from Hetzner is not. For logs maybe fine, but calculate this.

#10

3 senders changes things. Promtail on each node will use 50-100MB resident. Loki itself with boltdb-shipper and filesystem storage, single binary, maybe 400-600MB with light query load. You are cutting it close but doable.

I would not run Grafana on same 1GB box though — https://grafana.com. Use logcli from your laptop or another machine.

airgapped, encrypted, faraday'd, still worried

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft