Log sources

Connect the places your logs come from. Each source has its own token, its own retention and its own reception stats, so you can tell at a glance which service stopped sending.

Log sources list showing six sources, including an HTTP JSON API, a Vercel drain, two OpenTelemetry services, an AWS CloudWatch source and a syslog source, with their last line, lines in 24 hours, volume and rejected count
Log sources with their platform, type, last line received and volume over 24 hours

Overview

A source is a token plus a retention. Anything that holds the token can send lines to Hyperping: an OpenTelemetry SDK or collector, an HTTP client, rsyslog, or a hosting platform's log drain. Create one source per service and environment, such as api-production and api-staging, so you can revoke, filter and size them separately.

  • Your app already uses OpenTelemetry and you want its logs next to your monitors.
  • You deploy on Vercel, Heroku, Render, Fly.io, Railway, Cloudflare Workers, Supabase or Netlify and want the platform to push its logs.
  • Your Lambdas and ECS tasks log to CloudWatch.
  • Your servers already run rsyslog or Vector.

Prerequisites

  • A paid plan. Logs is in Alpha on paid plans and not yet available for EU-only accounts. See Logs.
  • An owner, admin or member role to create or revoke sources.

Create a source

Go to LogsSourcesNew source

New source form with a grid of platforms (Vercel, Heroku, Render, Fly.io, Railway, Cloudflare Workers, AWS CloudWatch, Supabase, Netlify), protocols (OpenTelemetry, HTTP JSON, Syslog over TLS) and fields for name, description, retention and rate cap
Creating an HTTP JSON source: pick a platform or a protocol, then name it and choose its retention
  1. Pick where the logs come from

    Under Connect a platform, choose your hosting platform. Under Other, choose OpenTelemetry, HTTP JSON or Syslog over TLS to send them yourself.

  2. Name it

    Fill in Name (it shows in the list and in the explorer's filters) and, optionally, a Description of what sends to it and who owns it.

  3. Choose a retention

    Pick 3, 7, 14 or 30 days in Retention. The default is 7 days; Vercel suggests 3.

  4. Create it and copy the token

    Click Create source (or Create and connect for a platform). Copy the token right away with Copy token: it is shown only once, and Hyperping only keeps its fingerprint.

  5. Send your first lines

    The panel shows the setup for the type you picked, with your token already filled in, and waits for the first line. Use Send a test log to check the pipeline end to end, then Open live tail or Search this source.

Endpoints and authentication

ProtocolEndpoint
HTTP JSONPOST https://logs.hyperping.com/
OpenTelemetry (OTLP/HTTP)POST https://logs.hyperping.com/v1/logs
Syslog over TLSlogs.hyperping.com:6514

HTTP requests authenticate with the source token in an Authorization: Bearer <token> header. Tokens start with hpl_. Syslog carries the token in the structured data of each message, as in the rsyslog example below.

The endpoint answers 202 Accepted once the lines are durably stored, so a client that retries on any other answer won't lose lines.

Send logs yourself

Pick the tab that matches your stack. Replace the token placeholder with your source token, ideally from an environment variable.

curl -X POST https://logs.hyperping.com/ \
  -H "Authorization: Bearer $HYPERPING_LOGS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"message":"Hello from curl","level":"info","service":"my-app"}'
  • OpenTelemetry: OTLP over HTTP, protobuf or JSON, gzip accepted. gRPC is not supported. Traces and metrics sent to the same endpoint are accepted but not stored. The environment variables work with any OpenTelemetry SDK (Node.js, Python, Go, Java, .NET, Ruby).
  • Vector: the http sink batches lines as a JSON array and retries on failure.
  • rsyslog: RFC 5424 over TLS. The token travels in the structured data and is not stored with the line. The disk queue covers network cuts.

HTTP JSON format

Send one JSON object, an array of objects, or NDJSON (one object per line). Gzip and deflate request bodies are accepted. Hyperping reads the standard fields under their usual names and keeps everything else as attributes, searchable with attr.<key>. Nested objects are flattened with dots: in the example below, status_code is searchable as attr.http.status_code:504.

[
  {
    "timestamp": "2026-10-03T14:16:32.609Z",
    "level": "error",
    "message": "Timeout after 5000ms calling inventory-service",
    "service": "checkout",
    "environment": "production",
    "host": "api-prod-2",
    "trace_id": "4bf92f3577b34da6a3ce929d0e0e4736",
    "order_id": "ord_8f2K1x",
    "http": { "method": "POST", "path": "/api/checkout", "status_code": 504 }
  }
]
FieldKeys recognized
Timetimestamp, time, @timestamp, ts, dt, datetime, date
Messagemessage, msg, @message, log, text
Levellevel, severity, level_name, lvl, levelname, log.level, loglevel, severity_text
Serviceservice, service.name, app, application
Environmentenvironment, env, deployment.environment
Hosthost, hostname, host.name
Trace and spantrace_id, span_id

The format is compatible with Logtail (Better Stack) HTTP payloads, so a JSON shipper already pointed at Logtail only needs a new URL and token.

Connect a platform

Platform sources point the platform's own log drain at Hyperping. After you create one, the panel lists the exact values to paste, the steps in the platform's dashboard, and a curl command to check the token first.

PlatformHow it connects
VercelLog drain (Team Settings → Drains) to https://logs.hyperping.com/vercel, JSON format, with the token in a custom Authorization header. Drains need a Vercel Pro or Enterprise team.
HerokuHTTPS drain added with the Heroku CLI, or a telemetry drain on Fir.
RenderLog stream (Integrations → Observability → Log Streams) to logs.hyperping.com:6514 with the token.
Fly.ioThe fly-log-shipper app with an HTTP sink.
RailwayA Locomotive sidecar sending JSON to https://logs.hyperping.com/.
Cloudflare WorkersWorkers OpenTelemetry export to /v1/logs, or a Workers Logpush job.
AWS CloudWatchA CloudFormation stack that subscribes your log groups to a Firehose stream, launched from the panel or with the AWS CLI.
SupabaseLog drain (Project Settings → Log Drains) to https://logs.hyperping.com/.
NetlifyLog drain to https://logs.hyperping.com/, NDJSON format.
heroku drains:add "https://x:<your-source-token>@logs.hyperping.com/heroku" -a <your-app>

Lines from a platform carry its name: search them with platform:vercel, or use the Platform drains view. DigitalOcean App Platform can't forward logs to a custom endpoint, so it isn't supported.

Manage a source

Click a source in the list to open it.

Source detail with last line, lines, volume and rejected counts over 24 hours, Send a test log and View logs buttons, and settings for description, retention and rate cap
A source opened: reception stats for the last 24 hours, settings, and the latest ingestion errors
  • Last line, Lines, 24 h, Volume, 24 h and Rejected, 24 h show what the source received. The list updates every minute; a green dot means a line arrived in the last 5 minutes.
  • Send a test log sends a line through the source; View logs opens the explorer filtered on it.
  • Settings edits the Description, the Retention and the Rate cap. A new retention applies to new lines, within about a minute; lines already stored keep theirs.
  • Latest ingestion errors lists refused requests over the last 7 days, with the reason.
  • About shows the Source ID. Search a source's lines with source:<ID>.

Revoke a source

Under Danger zone, click Revoke…. Anything sending with its token is refused with a 401 within a minute. Lines already stored stay searchable until their retention ends.

Limits

LimitValue
Sources per project50 active
Retention3, 7, 14 or 30 days, per source
Request body10 MiB compressed, 32 MiB decompressed (413 above)
MessageTruncated at 64 KiB
Attributes128 per line, values truncated at 16 KiB, keys at 256 characters
TimestampsFrom 48 hours in the past to 10 minutes in the future; others are clamped
RatePer project, by plan, with a daily volume cap. Above it the endpoint answers 429 with a Retry-After header

Troubleshooting

The source stays on "Waiting for the first log"

Run the curl command from the panel with the same token. A 401 means the token is wrong or revoked. If curl works, the problem is in your app's configuration: check the endpoint path (/v1/logs for OpenTelemetry, / for JSON) and that the exporter is enabled.

Requests answer 415

The content type isn't supported. Send JSON, NDJSON or OTLP (protobuf or JSON), and set Content-Type accordingly.

The Rejected count goes up

Open the source and read Latest ingestion errors. The usual reasons are Rate limited, Daily cap reached, Request too large, Malformed request and Timestamp out of range.

Lines arrive without a level or service

Hyperping didn't find them under a recognized key. Rename the field in your logger, or set OTEL_SERVICE_NAME with OpenTelemetry. The raw value stays available as an attribute meanwhile.

Next steps