Logs Cardinality

Log labels accumulate from two sources: the collection agent attaches some automatically, and users define more — some meaningful, some accidental, some that were useful once and no longer are. A label with unexpectedly high cardinality (many distinct values) is expensive to index and rarely worth keeping. The Cardinality page finds those labels so you can decide what to drop.

Access Cardinality

Click Logs in the top navigation, then Cardinality.

Reading the report

Show cardinality of labels matching

A filter builder — pick a label, an operator, and a value to scope the report to labels matching that condition, rather than every label in the system.

Total cardinality

The combined distinct-value count across every label currently shown.

Search labels

Filters the table below by label name.

Time range

Defaults to the last 5 minutes; adjust with the time picker.

limit to / top / bottom

Caps the table to the top or bottom N labels by value count (default 10), so a long tail of low-cardinality labels doesn’t bury the ones worth investigating.

The table lists, per label: Value count (1h) — distinct values seen in the preceding hour — and Value count for the currently selected time range. Sort by either to find the labels contributing the most cardinality right now versus over the last hour, and use that to decide which labels to relabel, drop, or stop emitting at the source — see Relabel for how to drop a label during ingestion.