Files
composes/docs/alloy/duplicate-journal-and-syslog-lines.md
tiennm99 198329c008 docs: move service issue notes from READMEs into docs/<service>
Service READMEs now cover only what the service is and how to deploy it.
Known issues, log noise and troubleshooting move to docs/<service>/, named
after the service directory, so editing them never redeploys the service.
Drop alloy's validate workflow, which never ran from a subdirectory.
2026-10-04 09:46:08 +07:00

440 B

Duplicate journal and syslog lines

Applies to alloy/compose.yml.

Symptom

The same log line arrives in Loki twice: once from loki.source.journal, once from loki.source.file.

Cause

Where rsyslog mirrors journald into /var/log/syslog — the Debian and Ubuntu default — the journal and file pipelines both ship it.

Fix

Drop one source on those hosts. On systemd-only stacks the file-based one is the redundant one.