- Documentation
- Learning Hub
- Section 4 of 5 Apply labeling strategy to logs
Audit what your clients send
Slide 4 of 5
Audit what your clients send
Collectors and agents can attach dynamic labels you didn’t choose. Use the fewest labels test on whatever Alloy, Fluentd, or your Docker driver is applying. To see your streams and find high-cardinality labels, run:
logcli series '{}' --since=1h --analyze-labelsA label with thousands of unique values found in nearly every stream, such as a requestId, should be removed from labels and queried with a filter expression instead.
If many teams send logs and you can’t audit or change every client, apply the same approach you learned for metrics: route logs through gateway collectors your admin team owns, enforce label policy at that layer, and manage those gateway configurations centrally with Fleet Management.