Manage
Update, back up, and run your LogNorth server, set up its apps and alerts, and choose how long it keeps logs.
Everything here works from your computer, or from the LogNorth web app. These pages assume the install line or Chasen. On a server of the older installer, see Move to Chasen.
From your computer
Section titled “From your computer”Install the Chasen CLI and log in to the server once:
curl -fsSL https://chasenhq.com/cli | shchasen add server root@203.0.113.5Then:
| Command | What it does |
|---|---|
chasen -a lognorth status |
The version, the state, the last backup, and the replica |
chasen -a lognorth logs |
The logs of the LogNorth container |
chasen -a lognorth backups |
The backups of the database |
chasen -a lognorth restore |
Brings a backup back |
chasen -a lognorth rollback |
Goes back to the version before |
chasen -a lognorth restart |
Restarts LogNorth |
On the server itself, the same commands run as sudo chasen-server status lognorth. See the Chasen docs.
Updates
Section titled “Updates”LogNorth updates itself each night, after a backup of its database. The old version keeps running if the new one does not start. To update now, run the install line again on the server:
curl -fsSL lognorth.com/install | sudo bashNew versions come on a weekly train, as release candidates first. To see how, or to run the candidates on your server, read Releases and updates.
Backups
Section titled “Backups”Give the server a bucket in any S3-compatible storage:
chasen bucketThen a live replica copies each change of the database to it as it happens, about a second behind. Chasen also takes a checked snapshot every hour and before each deploy, and sends it there too. Without a bucket, the snapshots stay on the server, and they die with it.
To save a copy of the data on your computer: chasen -a lognorth download.
A forgotten password
Section titled “A forgotten password”chasen -a lognorth ssh/app/lnctl reset-password you@example.comchasen ssh opens a shell in the LogNorth container. lnctl asks for the new password.
Apps and keys
Section titled “Apps and keys”Create one app for each app and environment on the Apps page. Each app has its own key, which starts with lgn-: your SDK sends with it. Revoke a key on the same page, and create a new one.
The agent key, for MCP and north, is in Settings > Developer. It starts with lgn-agent- and only reads.
Uptime
Section titled “Uptime”Paste an app’s URL when you create it, or click [edit] on its uptime line on the Apps page. LogNorth pings it every minute and alerts after 3 failed pings in a row, and again when it answers.
A ping fails on a 5xx answer, on no answer within 5 seconds, or on a connection, DNS, or TLS error. Any 2xx, 3xx, or 4xx answer counts as up. If a firewall must let the pings in, they come from your LogNorth server with this user agent:
LogNorth Uptime/1.0 (+https://lognorth.com)The pings run on your LogNorth server, so run it on a different box than the apps it watches.
Status pages
Section titled “Status pages”A status page shows the uptime of a product’s apps to anyone, without an account. Make one page per product, for example one for your shop and one for your blog.
- Open Settings > Status pages and create a page. Its name makes its address: “Shop” answers at
/status/shop. - On the Apps page, click [edit] on an app’s uptime line and pick the page under status page. An app is on one page at most, and on none until you pick one.
For each app, the page shows:
- The state now: up, failing, or down.
- One bar per day for the last 90 days, and the percent of pings that were up. Phones show the last 30 days.
- The uptime since the first ping, to 3 decimals.
- Each outage of the last 30 days. An outage is 3 or more failed pings in a row, the same as the down alert.
The page shows the app’s name. It never shows the URL that LogNorth pings. Times are in UTC.
Its own domain
Section titled “Its own domain”A page can also answer at a domain of its own, like status.shop.com. Each page has its own domain, so one LogNorth server can serve the status pages of all your products.
-
In Settings > Status pages, click [edit] on the page and enter the domain. The page then shows the DNS record to add and the Chasen command.
-
At your DNS provider, add a CNAME record for the domain. Its target is the domain LogNorth runs on, for example
logs.shop.com. -
Send the domain to LogNorth in your proxy. On Chasen, run this in the folder of your LogNorth deploy:
chasen domains add status.shop.comChasen gets the HTTPS certificate.
On its domain, the page answers at /. Every other path goes back to /, so the dashboard and the login never answer there. A page can’t take the domain LogNorth itself runs on.
Notes on outages
Section titled “Notes on outages”Sign in, open the page at /status/<name> on your LogNorth domain, and click + add a note under an outage. Your login works only on the LogNorth domain, so you post notes there. Visitors see them on the page’s own domain too. Write what happened and what you did. Visitors see the note under the outage. To delete a note, hover it and click delete.
How long the data stays
Section titled “How long the data stays”LogNorth keeps each ping for 30 days. Before it deletes a day of pings, it stores one row per app for that day: the pings, the failures, and the minutes down. It keeps these rows for good. So the bars go back 90 days, and each app also shows its uptime since its first ping, to 3 decimals: 99.991% since mar 4. Outages and their notes need the pings, so they stay for 30 days.
Visitors get a copy of the page that is at most 1 minute old. When you are signed in, you always get the current page.
The status pages run on your LogNorth server. If that server goes down, the pages go down too.
Alerts
Section titled “Alerts”Choose one channel in Settings > Alerts, then click Test notification.
| Channel | What it needs |
|---|---|
| ntfy.sh | A topic URL, for example https://ntfy.sh/lognorth-abc123. Install the ntfy app and subscribe to the same topic. No account |
| Your SMTP server: host, port (587 or 465), username, password, from, and to | |
| Telegram | A bot token from @BotFather and the chat ID |
| Webhook | A URL, and a token for the Authorization header if your endpoint wants one |
Critical alerts arrive at once, at most one an hour for each endpoint. Warnings go to a daily digest. Every alert ends with a command like /lognorth:investigate /checkout for your coding agent.
Quiet hours, in the same settings, stop alerts during the night. LogNorth still records everything.
To stop the alerts of one issue, mute it on the issue’s page.
Webhook
Section titled “Webhook”LogNorth sends each alert as one POST:
POST <your URL>Authorization: Bearer <token>Content-Type: application/json
{ "source": "lognorth", "title": "[shop-prod] Spike on /checkout", "message": "8% errors, normally 1%. ... /lognorth:investigate /checkout", "text": "<title>\n\n<message>", "sent_at": "2026-09-24T14:05:00Z"}text holds the title and the message in one field, so a Slack or Mattermost incoming webhook shows it as it is. Any 2xx answer counts as delivered.
Grok Bot
Section titled “Grok Bot”A Grok Bot routine can start on each alert and investigate it:
- In Grok Bot, create a routine. Add a Webhook trigger. Grok gives you a URL and a key.
- Write the routine’s instruction, for example: “A LogNorth alert arrived. Use the LogNorth connector to find the cause: list_alerts, endpoint_timeline, search_logs, get_event. Post a short summary with the cause and the fix.”
- In LogNorth, open Settings > Alerts, choose Webhook, and paste the URL and the key as the token. Click Test notification.
For the investigation, the bot needs the LogNorth tools. Add https://logs.yoursite.com/mcp as a custom connector at grok.com/connectors. See MCP.
Retention
Section titled “Retention”Choose how long to keep events in Settings > Data: 7 days, 30 days, 90 days (the default), 6 months, 1 year, or forever. LogNorth deletes older events every 10 minutes.
An event takes about 0.3 KB. 20,000 events a day for a year is about 2 GB, so a small server holds years of logs for most apps.