Grafana Loki alert rule max_lines truncation behavior unspecified
0 reputation · 20 Feb 2024, 21:02 UTC
When configuring a Loki-based alert rule in Grafana, the max_lines parameter limits the number of log lines returned for evaluation. The goal is to determine which subset of lines is kept when the actual result set exceeds this limit, as this decides whether critical error messages are included in the alert condition.
The truncation strategy—whether Grafana retains the earliest lines, the latest lines, or some other selection—is not documented, creating uncertainty about alert reliability and consistency across environments.
- Does Grafana keep the earliest or latest log lines when the result exceeds
max_lines? - Is the truncation order consistent across different Loki query types and alert evaluation intervals?
- Can users influence which lines are kept by adding explicit sort or limit clauses in the Loki query?