Installing Grafana Loki and Promtail on Fedora Server: Centralized Logging, Way Lighter than ELK

Fedora tutorial - IT technology blog
Fedora tutorial - IT technology blog

The Nightmare of SSHing into Every Server to Grep Logs at 2 AM

About six months ago, our infrastructure hit the 15-node Fedora Server milestone. That’s when the nightmare began. Every time an application threw a 500 error in the middle of the night, the all-too-familiar debugging ritual kicked off: launch the terminal, SSH into each node one by one, and run journalctl -u app.service -f or strain our eyes running grep through endless lines in /var/log/nginx/access.log.

This approach works fine when managing one or two machines. But once you scale to dozens of servers, manual debugging makes it dangerously easy to miss error correlations across different services. Our team considered the ELK stack (Elasticsearch, Logstash, Kibana). However, Elasticsearch alone easily eats up 4GB to 8GB of JVM heap memory just waiting to index logs. On a fleet of small VPS instances, that’s an unacceptable luxury.

After six months of running it in production, the Loki + Promtail + Grafana trio completely solved our problem: lightweight configuration, minimal RAM usage, and instant log queries.

How Do Loki and Promtail Work?

Grafana Loki inherits its core design philosophy from Prometheus. Rather than full-text indexing every log message like Elasticsearch does, Loki only indexes metadata (labels). The raw log payloads are compressed into gzip/snappy chunks and written directly to local disk or object storage.

The Three Core Components

  • Promtail: A background agent running on each Fedora node. It tails log files in /var/log/ or reads directly from the systemd journal, attaches labels (such as host=fedora-node-01, job=systemd-journal), and ships them via HTTP POST to Loki.
  • Loki: The central node that receives data streams from Promtail, compresses chunks, stores them, and handles queries using the LogQL language.
  • Grafana: The visualization dashboard that connects to Loki as a data source to search, trace errors, and plot frequency graphs.

Because it only indexes labels, Loki’s resource footprint is remarkably low. Our setup reliably digests 4 to 5 million log lines daily, yet Loki hovers comfortably between 320MB and 380MB of RAM.

Hands-on: Deploying the Logging Stack on Fedora Server

Fedora Server offers modern kernels, robust systemd support, and very up-to-date packages. If you already have metrics configured with a production-ready monitoring stack, adding centralized logging completes your full observability pipeline. Here is the complete step-by-step setup from scratch.

Step 1: Install Grafana

Add the official Grafana repository to Fedora:

sudo tee /etc/yum.repos.d/grafana.repo << 'EOF'
[grafana]
name=grafana
baseurl=https://rpm.grafana.com
repo_gpgcheck=1
enabled=1
gpgkey=https://rpm.grafana.com/gpg.key
sslverify=1
sclcacert=/etc/pki/tls/certs/ca-bundle.crt
EOF

sudo dnf install -y grafana
sudo systemctl daemon-reload
sudo systemctl enable --now grafana-server

Verify that it is listening on port 3000:

sudo ss -tulpn | grep 3000

Step 2: Install Loki and Promtail Binaries

Grafana provides standalone Linux binary builds on GitHub. We download the binaries directly into /usr/local/bin/ for centralized management with systemd:

LOKI_VERSION="v3.0.0"
sudo dnf install -y unzip curl

# Download and extract Loki binary
curl -fsSL -o /tmp/loki.zip "https://github.com/grafana/loki/releases/download/${LOKI_VERSION}/loki-linux-amd64.zip"
sudo unzip -q -o -d /usr/local/bin/ /tmp/loki.zip
sudo chmod 755 /usr/local/bin/loki-linux-amd64
sudo ln -sf /usr/local/bin/loki-linux-amd64 /usr/local/bin/loki

# Download and extract Promtail binary
curl -fsSL -o /tmp/promtail.zip "https://github.com/grafana/loki/releases/download/${LOKI_VERSION}/promtail-linux-amd64.zip"
sudo unzip -q -o -d /usr/local/bin/ /tmp/promtail.zip
sudo chmod 755 /usr/local/bin/promtail-linux-amd64
sudo ln -sf /usr/local/bin/promtail-linux-amd64 /usr/local/bin/promtail

Step 3: Configure Loki Server

Create a dedicated system user loki to enhance security and avoid running processes as root:

sudo useradd --system --no-create-home --shell /sbin/nologin loki || true
sudo mkdir -p /etc/loki /var/lib/loki
sudo chown -R loki:loki /var/lib/loki

Create the configuration file /etc/loki/loki-config.yaml:

sudo tee /etc/loki/loki-config.yaml << 'EOF'
auth_enabled: false

server:
  http_listen_port: 3100
  grpc_listen_port: 9096

common:
  instance_addr: 127.0.0.1
  path_prefix: /var/lib/loki
  storage:
    filesystem:
      chunks_directory: /var/lib/loki/chunks
      rules_directory: /var/lib/loki/rules
  replication_factor: 1
  ring:
    kvstore:
      store: inmemory

schema_config:
  configs:
    - from: 2024-01-01
      store: tsdb
      object_store: filesystem
      schema: v13
      index:
        prefix: index_
        period: 24h

limits_config:
  reject_old_samples: true
  reject_old_samples_max_age: 168h
EOF

Create the systemd service for Loki:

sudo tee /etc/systemd/system/loki.service << 'EOF'
[Unit]
Description=Loki service
After=network.target

[Service]
Type=simple
User=loki
Group=loki
ExecStart=/usr/local/bin/loki -config.file=/etc/loki/loki-config.yaml
Restart=on-failure
LimitNOFILE=65536

[Install]
WantedBy=multi-user.target
EOF

sudo systemctl daemon-reload
sudo systemctl enable --now loki

Step 4: Configure Promtail to Read systemd Journal and Log Files

Promtail on Fedora can hook directly into journald without requiring an intermediary rsyslog setup.

To grant Promtail permission to read journals and log files, add the promtail user to the systemd-journal and adm groups:

sudo useradd --system --no-create-home --shell /sbin/nologin promtail || true
sudo usermod -aG systemd-journal,adm promtail
sudo mkdir -p /etc/promtail /var/lib/promtail
sudo chown -R promtail:promtail /var/lib/promtail

Create the scrape configuration file /etc/promtail/promtail-config.yaml:

sudo tee /etc/promtail/promtail-config.yaml << 'EOF'
server:
  http_listen_port: 9080
  grpc_listen_port: 0

positions:
  filename: /var/lib/promtail/positions.yaml

clients:
  - url: http://127.0.0.1:3100/loki/api/v1/push

scrape_configs:
  - job_name: system
    static_configs:
      - targets:
          - localhost
        labels:
          job: varlogs
          host: fedora-server
          __path__: /var/log/*.log

  - job_name: journal
    journal:
      max_age: 12h
      labels:
        job: systemd-journal
        host: fedora-server
    relabel_configs:
      - source_labels: ['__journal__systemd_unit']
        target_label: 'unit'
      - source_labels: ['__journal_priority_keyword']
        target_label: 'level'
EOF

Start the Promtail service:

sudo tee /etc/systemd/system/promtail.service << 'EOF'
[Unit]
Description=Promtail service
After=network.target

[Service]
Type=simple
User=promtail
Group=promtail
ExecStart=/usr/local/bin/promtail -config.file=/etc/promtail/promtail-config.yaml
Restart=on-failure

[Install]
WantedBy=multi-user.target
EOF

sudo systemctl daemon-reload
sudo systemctl enable --now promtail

Step 5: Configure Firewalld

Fedora Server enables firewalld by default. Open port 3000 for Grafana and port 3100 for Loki (if you need to ingest logs from remote servers):

sudo firewall-cmd --permanent --add-port=3000/tcp
sudo firewall-cmd --permanent --add-port=3100/tcp
sudo firewall-cmd --reload

Step 6: Query Logs in Grafana Using LogQL

Access http://<Fedora-Server-IP>:3000 in your browser. If you prefer secure domain access instead of raw IPs, you can configure automatic HTTPS and reverse proxy. Log in with the default credentials admin / admin and set a new password.

  1. Go to Connections > Data sources > select Add data source > click Loki.
  2. In the URL field, enter http://127.0.0.1:3100 and click Save & test (Grafana will show a green confirmation badge upon a successful connection).
  3. Open the Explore menu, select Loki as the Data source, and start writing queries.

Here are a few practical LogQL queries that come in handy during daily operations:

# Filter all logs from systemd-journal containing the string "error" (case-insensitive)
{job="systemd-journal"} |=? "error"

# Filter errors specifically from the SSH service
{unit="sshd.service", level="err"}

# Calculate the rate of HTTP 500 errors from Nginx logs in 5-minute windows
sum(rate({job="varlogs"} |= " 500 " [5m])) by (host)

Lightweight, Stable, and Perfect for Small-to-Medium Production

Switching from manual SSH troubleshooting to Loki + Promtail cut our incident tracing time from over 20 minutes down to under 2 minutes. On a modest Fedora VPS with 2 vCPUs and 2GB RAM (costing around $5–$6/month), both Grafana and Loki run smoothly without breaking a sweat or risking memory exhaustion.

Share: