Skip to main content
HealOps queries VictoriaLogs using LogsQL to retrieve structured log evidence — correlating recent application errors, request anomalies, and stream-level events with the alert under investigation.

Prerequisites

  • A reachable VictoriaLogs instance (e.g. http://vmlogs:9428)
  • LogsQL knowledge for any custom queries you want HealOps to run

Setup

Option 1: Environment variables

Add to your .env:

Option 2: Persistent store

Verify

Expected output:

How it works in investigations

When VictoriaLogs is configured, the victoria_logs_query tool becomes available to the investigation agent. It runs LogsQL queries against /select/logsql/query and returns structured rows — defaulting to a wildcard match over the past hour, but the agent narrows the query based on alert context (service, level, trace ID, time window). Typical agent uses:
  • Pull recent error-level logs for the affected service to surface stack traces
  • Filter by request ID or trace ID to follow a single failing transaction across services
  • Compare log volume in the incident window against a known-good baseline to spot regressions

Troubleshooting