Logs Cardinality
Log labels accumulate from two sources: the collection agent attaches some automatically, and users define more — some meaningful, some accidental, some that were useful once and no longer are. A label with unexpectedly high cardinality (many distinct values) is expensive to index and rarely worth keeping. The Cardinality page finds those labels so you can decide what to drop.
Reading the report
- Show cardinality of labels matching
-
A filter builder — pick a label, an operator, and a value to scope the report to labels matching that condition, rather than every label in the system.
- Total cardinality
-
The combined distinct-value count across every label currently shown.
- Search labels
-
Filters the table below by label name.
- Time range
-
Defaults to the last 5 minutes; adjust with the time picker.
- limit to / top / bottom
-
Caps the table to the top or bottom N labels by value count (default 10), so a long tail of low-cardinality labels doesn’t bury the ones worth investigating.
The table lists, per label: Value count (1h) — distinct values seen in the preceding hour — and Value count for the currently selected time range. Sort by either to find the labels contributing the most cardinality right now versus over the last hour, and use that to decide which labels to relabel, drop, or stop emitting at the source — see Relabel for how to drop a label during ingestion.