Guides

Seq

Ship CLEF to Seq and query by event type.

Seq is the log server built around Serilog's event model: templates, properties, event types. logit speaks its format natively.

Run it#

docker run --name seq -d --restart unless-stopped -e ACCEPT_EULA=Y -p 5341:80 datalust/seq

Open http://localhost:5341.

Ship to it#

import { configure, consoleSink, seqSink } from '@unhingged/logit';

configure({
  sinks: [
    consoleSink(),
    seqSink({ serverUrl: 'http://localhost:5341', apiKey: process.env.SEQ_API_KEY, restrictedToMinimumLevel: 'info' }),
  ],
});

seqSink is the HTTP sink preset for Seq: CLEF, newline-delimited, POSTed to /ingest/clef with Content-Type: application/vnd.serilog.clef and the X-Seq-ApiKey header when a key is given. The batching options — batchSize, flushInterval, maxQueue, retries — are the HTTP sink's. Close the logger before the process exits so the last batch leaves.

What Seq sees#

Every event arrives as CLEF:

  • the message template, so Seq renders the message itself and groups by it;
  • @i, the event type — the same hash Serilog computes, so @EventType = 0xd582b83a style filters work;
  • @l as Debug, Warning, Error…, omitted for information;
  • @x with the stack and the cause chain;
  • @r renderings for formatted holes, so {Elapsed:0.0} shows as 83.2 while Elapsed stays 83.2000…;
  • @tr / @sp when the event has trace context;
  • every property, SourceContext included.

Queries#

SourceContext like 'app.db%'
StatusCode >= 500
Elapsed > 1000 and RequestPath like '/api/%'
@EventType = 0xd582b83a

Right-click a property in the event list to filter by it; "Find" on an event's type selects every event written with that template.

Not yet#

  • Durable shipping (a disk buffer that survives a restart) and remote level control (Seq's controlLevelSwitch) are on the roadmap. Today the queue is in memory, and the level is set with LOGIT_LEVEL or a LevelSwitch you flip yourself.