Slide 4 of 5

Audit what your clients send

Audit what your clients send

Collectors and agents can attach dynamic labels you didn’t choose. Use the fewest labels test on whatever Alloy, Fluentd, or your Docker driver is applying. To see your streams and find high-cardinality labels, run:

Bash
logcli series '{}' --since=1h --analyze-labels

A label with thousands of unique values found in nearly every stream, such as a requestId, should be removed from labels and queried with a filter expression instead.

If many teams send logs and you can’t audit or change every client, apply the same approach you learned for metrics: route logs through gateway collectors your admin team owns, enforce label policy at that layer, and manage those gateway configurations centrally with Fleet Management.

Script

Even with a good strategy on paper, your collectors can work against you. Alloy, Fluentd, or your Docker driver can attach dynamic labels you never chose, so apply the fewest labels approach to whatever they’re sending.

The logcli command on this slide analyzes your streams and surfaces high-cardinality labels. Look for a label with thousands of unique values that appears in nearly every stream, something like a requestId. That’s a label to remove and query with a filter expression instead.

And if many teams send logs and you can’t audit or change every client, reuse the pattern from the metrics section. Route logs through gateway collectors your admin team owns, enforce label policy at that layer, and manage those gateway configurations centrally with Fleet Management.