View Categories

Connect Docker Container Logs to Claude with MCP

7 min read

MCP · Container Logs to Claude

Ask Claude about your Container Logs file, in plain English

Connect Claude, Claude Code, Cursor or any MCP client to Query Streams once. Claude reads the structure of your Container Logs file, writes the SQL, runs it read-only through the Agent that already sits with your data, and answers with the rows. No database password ever reaches the AI. About ten minutes, and the Free plan covers it.

About 10 minutes Claude, ChatGPT, Cursor + 11 more clients File stays where it is Read-only, always
Stuck at any point? Just ask us. Open Support in Query Streams (top-right menu → Support) and send us a message. Real people read it, and “I don’t know what this screen is asking for” is a perfectly good question.

What you’ll end up with

Container Logs iconA Claude that can answer questions about your Docker container logs with live, read-only queries over the tables the Agent builds from your files, and tell you which file each answer came from — without ever seeing a login or a file path, and without a firewall change: the Agent already inside your network reads the folder and sends back only the rows. Once the Agent is in place, connecting Claude takes about 90 seconds if you are comfortable with a settings screen. Like this:

Nova, the Query Streams assistant

Rather not wire up an AI client at all? On the Business plan, Nova is the assistant built into Query Streams itself. It has every tool Claude gets here, plus the ones Claude does not: it drafts and validates the SQL against your Schema Intelligence model, turns the answer into a chart, and saves the result as a query your team can run from Excel, Google Sheets or the REST API — no key, no connector, nothing to install. Use MCP when your people already live in Claude, Cursor or ChatGPT; use Nova when you want the answers inside the Portal.

Container Logs reads the log files Docker writes for each container and turns every line into a row in a SQL table that Claude can query. It is not Docker’s own MCP Toolkit. It does not run or manage containers; it only reads their docker container logs. The Agent tails each file as it grows, recognises rotated files so nothing is read twice, reads each .gz archive once, and backfills the last 30 days on first read.

WHERE THE FILES LIVEa computer or file share the Agent can openYour folderof filesfiles stay where they areQuery Streams Agentscans the folder, builds tablesin a local cache, runs the SQLSELECT only, enforced hereQuery StreamsMCP serverchecks key, permissions, rate limit · logs every callWHERE YOU ASKclaude.ai, Claude Desktop, Claude Code, Cursor, ChatGPTYour AI clientholds a key or a connection, never your files
Claude never opens your files. The Agent reads the folder on its own computer, keeps the rows in a local cache and runs the SQL Claude writes there. Only the rows a question needs travel back through Query Streams.

What you’ll need

A Query Streams account

MCP is on every plan, including Free. Free allows one key or one connected app, which is all this guide needs. Sign up at my.querystreams.com.

The Agent on a computer that can open the folder

Version 2.6.0 or later. The folder can be on that computer or on a file share it can reach. The Agent runs as a service, so type shares as \\server\share\folder, not as a mapped drive letter. New to the Agent? Install it on Windows, macOS or Linux.

MCP switched on for you

Creators, owners and admins have it from the start. Everyone else needs an admin to flip the MCP switch beside their name under Account → Access Control. Until then the MCP page says “MCP is disabled for your account”.

An AI client

Claude on the web, Claude Desktop or the Claude mobile apps connect with no key. Claude Code, Cursor, ChatGPT and about ten other tools work too; the Portal has a ready-made recipe for each.

Where does the work happen? On the computer that runs the Agent. It scans the folder, copies the rows into a local cache there, and runs the SQL Claude writes against that cache. The files themselves never leave that computer, and neither does anything Claude did not ask for.

Set it up in four steps

  1. Point the Agent at the folder

    In the portal open Data → Data Agents, find the Agent that can open the folder and click its Add connector button. Under the Files & Folders pill click the Container Logs card. The wizard then walks you through Folders, Check, Settings, Realm and Review:

    Folders
    Type the Root folders, one per line, as paths on the Agent’s computer. Scan subfolders is on, Max depth is 8. Include patterns starts with the right glob for this file type; add Exclude patterns if the folder holds files you do not want. A mapped drive letter shows an amber advisory: the Agent cannot see it, so use the \\server\share path instead.
    Check
    The Agent reads a sample of up to 64 files and shows what it will build. Nothing is created yet. Ready to create means every sampled file fits. An amber banner, “{n} of {m} file(s) will be set aside”, lists files that do not fit with Show which files and why; you can create the connector anyway and fix them later. If the folder mixes layouts, a blue panel offers Switch to one table per layout.
    Settings
    Scan interval (every hour by default, from every 5 minutes to daily) is how often the Agent looks for new, changed and vanished files. Watch folder for changes reacts within seconds on local disks. When a file vanishes is Drop its rows by default.
    Realm, Review
    Pick the Data Realm the rows count against, check the summary and click Create connector. The first scan starts right away; the connector’s Manifest tab shows what it built and any files it set aside.
    • Add the folder that holds your container logs under Root folders. Include patterns start as **/*-json.log, **/*.log and **/*.log.*.
    • Pick a Log type. The card ships Docker json-file, docker logs --timestamps exports and Portainer.
    • Table name is optional and defaults to events.
    • On Check, the Agent reads a sample and shows the file count, size, a row estimate and the tables it will build. Nothing is created yet. If the files do not look like the type you picked, the headline reads These files are not followed by that type, with the reason.
  2. See what tables you get

    Parsed lines land in fileset.events, or in the Table name you chose. The Agent keeps the rows in a local cache on the Agent computer and serves them as SQL. Every row says which file it came from in _source_file. The columns below come from the default Docker json-file log type.

    TableWhat it holds
    eventsOne row per log line: event_time, app (the container name), stream and message, plus image, compose_service and container_id.
    events_raw_linesLines that did not parse, kept in line with a reason such as no-grammar-match or undecodable. Nothing is dropped.
    filesEvery log file in the folder right now, with relative_path, size_bytes and modified_utc.
    files_eventsThe history of each file: appeared, modified, rotated, truncated and drift rows, timed by event_at.
    log_cursorsEach file’s read position and state. A set-aside file shows state parked with the reason in last_error.

    Every folder connector also gives Claude the same bookkeeping tables, all in the fileset schema:

    TableWhat it holds
    filesEvery file currently in the folder: path, name, extension, size, created and modified times. Ask “what is in this folder?” and Claude reads this.
    files_eventsThe change history: one row per file that appeared, was modified, vanished, or was set aside (drift), with the time in event_at and the reason in detail.
    directories, volumesFolder sizes and counts, and the disks or shares the roots live on.
    _source_file, _row_idTwo columns on every data row: which file the row came from, and a stable row id inside that file. Group by _source_file to compare files.
  3. Connect Claude

    Open Streams → Live → MCP. There are two ways in, and they end at the same place:

    Chat apps · no key

    claude.ai, Claude Desktop, ChatGPT

    In Claude, Query Streams is in the Anthropic Connectors Directory: browse connectors, click Connect. Elsewhere you paste one address into the app, https://mcp.querystreams.com/mcp, and connect from a chat. A Query Streams page opens, you pick the organization and the permissions, and click Approve connection. Nothing to copy, nothing to keep secret. The connection appears under Connected Apps and can be revoked there.

    Developer tools · a key

    Claude Code, Cursor, VS Code and friends

    On My Keys click Generate key. Give it a Key name such as “Claude Code on my laptop”, keep Read and Execute ticked, choose an Expiration (Never, 30 days, 90 days or 1 year) and click Generate key. Copy it, then Continue to install: the Connect tab shows the exact snippet for your tool with the key already filled in.

    Both ways use the same three permissions, which you choose on the consent screen or on the key:

    Read
    List connectors, browse tables and columns, read your saved queries and alert rules. Never returns row data.
    Execute
    Run read-only SQL and saved queries through your Agent and return the rows. Without it Claude can describe your data but not answer from it.
    Analyze
    Profile tables, discover relationships and queue a Schema Intelligence run. It spends Nova AI credits and data allowance, so the consent screen never pre-ticks it.

    Lost the key? Open My Keys: the eye icon shows it again and Copy full key copies it. Revoke it there if a laptop goes missing; every client using it fails on its next call, within about five minutes.

    Then pick the recipe for the Claude you use. The server address is the same everywhere: https://mcp.querystreams.com/mcp.

    Claude on the web, Claude Desktop and mobile no key

    1. Open Settings → Connectors and click Browse connectors. Query Streams is listed in the Anthropic Connectors Directory: find Query Streams and click Connect. (Or open the directory listing directly and click Connect there.)
    2. If your organization hides directory connectors, click Add custom connector instead. Name it Query Streams, paste https://mcp.querystreams.com/mcp, leave the OAuth fields empty, click Add, then in any chat click + → Browse connectors → Query Streams → Connect.
    3. A Query Streams tab opens. Sign in if asked, pick the organization, review Read and Execute, optionally Limit to specific connectors, and click Approve connection.
    4. Back in Claude you see “Connected to Query Streams”. The first time Claude uses a tool it asks; choose Always allow.

    If you do add it by hand in Claude Desktop, use Settings → Connectors → Add, not the in-chat Add marketplace option, which expects a git repository. Connectors sync to your Claude account, so the mobile apps and Desktop pick it up automatically. Menu names are Anthropic’s and can move.

    Claude Code key

    One command, with your key from My Keys:

    Terminal
    claude mcp add --transport http querystreams https://mcp.querystreams.com/mcp \
      --header "X-MCP-Key: qsmcp_PASTE_YOUR_KEY_HERE"

    That writes the current project’s .mcp.json. Add --scope user to have Query Streams in every project. Run /mcp inside Claude Code to see it connected.

    Cursor key

    Open Cursor Settings → MCP → Add New MCP Server, or edit .cursor/mcp.json at the root of your workspace:

    .cursor/mcp.json
    {
      "mcpServers": {
        "querystreams": {
          "url": "https://mcp.querystreams.com/mcp",
          "headers": {
            "X-MCP-Key": "qsmcp_PASTE_YOUR_KEY_HERE"
          }
        }
      }
    }

    Restart Cursor or run MCP: Restart Servers; a querystreams badge appears in the MCP status bar.

    Using something else? The Connect tab has ready-to-paste recipes for ChatGPT, VS Code, Visual Studio, OpenAI Codex CLI, Gemini CLI, Windsurf, Zed, Cline, Continue.dev and JetBrains AI, plus a Paste & merge tool that drops the querystreams entry into a config file you already have. Any client that speaks MCP over HTTP works: server https://mcp.querystreams.com/mcp, header X-MCP-Key (an Authorization: Bearer header with the same key also works).

  4. Ask your first question

    Start with something you can check by opening the folder, so you see Claude reach for the right table. Three that work well with your Docker container logs:

    “Which container log files are you reading, and when did each last change?”
    Claude queries fileset.files for relative_path, size_bytes and modified_utc, newest first.
    “How many stderr lines did each container write in the last hour?”
    Claude counts rows in fileset.events by app where stream is stderr, filtered on event_time.
    “Were any container log files rotated or set aside today?”
    Claude reads fileset.files_events for rotated and drift rows, ordered by event_at, and names each file.

    To confirm the wiring, ask “What Query Streams connectors do I have?”. Claude calls qs_list_connectors, and on My Keys the key’s Last used time updates within a few seconds.

That’s it. Drop a new file in the folder and, after the next scan, Claude can answer from it. The files never left the computer the Agent runs on, and nobody typed a password into an AI.

How new, changed and deleted files show up

New and changed files

On every Scan interval the Agent compares each file’s size and modified time with its ledger. A new file that fits is added; a changed file is re-read whole, so a table never holds two versions of one file. Turn on Watch folder for changes to react within seconds on a local disk.

Deleted files

A file that vanishes drops its rows, unless you chose Keep rows, mark deleted. If a share goes offline and most files vanish at once, the Agent keeps the last good inventory instead of deleting everything.

Set-aside files

A file that does not fit the layout, cannot be opened, or is locked is set aside: none of its rows load, and files_events records which file and why. It is retried automatically the next time it changes. There is no Rescan button.

What Claude sees

The data as of the last scan. No MCP tool triggers a scan, so ask “when was this last updated?” and Claude reads the latest event_at in files_events for you.

What Claude can do once connected

Claude sees nineteen small tools. You never call them yourself; Claude picks the right one for your question. In plain terms:

Understand your data

List connectors, databases and Agents. Read the tables and columns of your Container Logs file with descriptions, sample values and relationships when Schema Intelligence has run.

Profile and explore

Profile a column to see its real values before filtering on it. Discover joins between tables that never had a foreign key declared. (Analyze)

Use your saved queries

List the saved, parameterised queries your team trusts and run them with new values. Federated queries that span sources run server-side and come back already joined.

Run read-only SQL

Write and run a SELECT in the right dialect for Container Logs. Up to 1,000 rows and 60 seconds by default; Claude can ask for more, up to 50,000 rows and five minutes. (Execute)

Check alerts

List your alert rules, their current state and recent firings. Claude can draft a rule as a dry run; a person arms it on the Alerts page.

Improve the model

Check Schema Intelligence coverage per database and, with your agreement, queue a run so the next answers are better. (Analyze)

The tool names, if you want to recognise them in Claude’s replies
PermissionTools
Readqs_list_organizations qs_list_agents qs_list_connectors qs_get_si_status qs_get_connector_schema qs_get_table_schema qs_get_relationships qs_list_saved_queries qs_get_task_status qs_list_alert_rules qs_get_alert_state qs_list_recent_alerts
Analyzeqs_profile_table qs_discover_relationships qs_request_si_analysis qs_setup_si
Executeqs_run_query qs_run_saved_query qs_create_alert_rule (proposes only; never armed from Claude)

Why Schema Intelligence matters here

Every answer Claude receives is tagged with where the structure came from, and Claude adjusts how much it trusts what it sees.

TierWhat Claude seesResult
Schema IntelligenceDescriptions for every table and column, sample values, enum meanings, declared and discovered joins.Claude writes the right Container Logs SQL first time and explains the data in your business terms.
Captured schemaTable and column names, types, keys.Claude works, but infers meaning from names and may ask a follow-up.
Live schemaThe database is outside the connector’s capture selection, so structure is read live on each request (needs the Execute permission; SQL Server, MySQL and PostgreSQL).Queries still run. Claude explores with small selects when it needs more.

If a database matters, run Schema Intelligence on it once from Nova → Intelligence. The My Keys tab shows a coverage panel per connector. How Schema Intelligence works.

What the plans allow

MCP is on every plan, including Free, with no separate fee. What each plan sets is how many keys or connected apps you can hold and how many calls a minute Claude may make:

PlanKeys per userKeys per organizationCalls per minute
Free1130
Personal Core1160
Personal Plus1190
Business Core23120
Business Plus35150
Business Max510240
Enterprise Core525300
Enterprise Plus850450
Enterprise Max10100600

A connected app counts as a key. On top of the per-minute figure, any one key may run at most 10 queries a minute. A query returns up to 1,000 rows and runs for up to 60 seconds unless Claude asks for more, to a ceiling of 50,000 rows and five minutes. The rows Claude receives count against your Data Realm allowance, the same pool your Excel and Sheets queries use, and MCP is measured before compression, so a wide result costs more here than the same rows in a spreadsheet. Schema Intelligence runs started from Claude spend Nova AI credits, exactly as they do from the Portal. See the pricing page for the allowances.

Keeping it safe

Read-only, checked by the Agent

Only SELECT statements run. The check happens on the computer that runs the Agent, before your Container Logs file sees the SQL, so nothing Claude writes can change data.

No credentials in the AI

The Container Logs login stays on the Agent. Claude holds a Query Streams key or connection, which you can revoke from the MCP page; the change takes effect within about five minutes.

Everything is logged

Every tool call appears on the MCP Activity tab and every query in Query History as client type MCP, attributed to the person whose key or connection made it. The SQL text and the key itself are never written to the activity log.

What the AI provider receives

Table and column names, the Schema Intelligence descriptions including sample values, and the rows of the queries you ask for. Those go to the AI provider you connected, under its terms. Query Streams never sees your chat.

Good next moves

  • Turn on Watch folder for changes (near real-time) to pick up new lines within seconds on a local disk. The scheduled scan stays the guarantee.
  • Set Keep events for N days to control how much history stays in the cache. Container Logs keeps 30 days by default.
  • Open the Files dialog on the connector to see every log file the Agent is reading and why any is set aside.

When something doesn’t work

What you seeWhat it meansFix
Claude shows no Query Streams toolsThe connector was added but never connected from a chat, or the key was pasted into the wrong place.In Claude: + → Browse connectors → Query Streams → Connect. In a developer tool: restart it, then check Last used on My Keys.
MCP_KEY_REQUIRED or 401No key reached the server, usually a stray newline from copy and paste or the key in the wrong header.Copy the key again from My Keys and send it in the X-MCP-Key header.
MCP_USER_DISABLEDAn admin switched MCP off for your user.Ask them to turn the MCP switch back on under Account → Access Control.
MCP_SCOPE_REQUIRED or MCP_SCOPE_DENIEDThe key or connection lacks the permission for that action, usually Execute.Edit the key on My Keys and tick Execute, or reconnect the app and approve it.
MCP_KEY_ORG_LIMIT_EXCEEDEDYour plan’s key limit is used up. On Free that is one key or one connected app.Revoke one you no longer use, or move up a plan.
MCP_AGENT_NOT_CONNECTED or MCP_AGENT_NOT_REGISTEREDThe Agent that owns your Container Logs file is not connected right now.Open Data → Data Agents and start the Agent on its computer.
MCP_DATABASE_NOT_CAPTUREDThe database is outside the connector’s capture selection, so there is no stored schema or Schema Intelligence for it. Queries still work.Add it to the capture selection on the connector, then run Schema Intelligence if you want richer answers.
MCP_RATE_LIMITEDToo many calls a minute for your plan, or more than 10 query runs a minute on one key.Wait a moment. Schema Intelligence lets Claude answer in fewer calls.
MCP_QUERY_TIMEOUT or MCP_OUTPUT_TOO_LARGEThe query ran past its timeout or returned more than Claude can take in one reply.Ask for fewer rows or columns, or a date filter. Claude usually suggests this itself.
MCP_DATA_REALM_EXHAUSTEDYour organization’s data allowance for the period is used up.Wait for the allowance to reset or top it up from the Portal.
Read-only violationThe SQL was not a SELECT.By design. Nothing writes through MCP.

Questions people ask

How soon does a new container log line reach Claude?

On the next scan. The Agent checks the folder on the Scan interval, every hour by default. Turn on Watch folder for changes (near real-time) to react within seconds on a local disk. Claude answers from what the Agent has already cached, so it sees the data as of the last scan.

Are rotated and .gz log files read twice?

No. A rotated file is recognised by its first 4 KB and continues the same stream, so its lines are not counted again. Each .gz member is read once. .zip, .cab and .journal files are skipped. A half-written last line waits until it is complete.

What happens to a line that does not parse?

It is kept in events_raw_lines with a reason, such as no-grammar-match or undecodable. A whole file that cannot be read is set aside and listed in the connector’s Files dialog with the reason. Nothing is silently dropped.

Does Claude read my files?

No. The Agent reads them on its own computer and keeps the rows in a local cache there. Claude sends SQL to Query Streams, the Agent runs it against that cache, and only the rows the question needs travel back. Claude never opens a file and cannot change, move or delete one.

Do I need to open a port or run a VPN?

No. The Agent makes one outbound connection on port 443 and both requests and rows travel over it. If outbound HTTPS works, this works.

Can the folder be on a network share, or in OneDrive or Dropbox?

A share works as long as the Agent’s computer can open it; type it as \\server\share\folder, because the Agent runs as a service and cannot see drives mapped at your login, and add the share login on the folder’s row if it needs one. For a synced cloud folder, set it to keep files on this device; the Agent skips cloud placeholder files.

Does the Free plan really cover this?

Yes. Free is a plan you keep, not a trial that expires. MCP is included on every plan; Free allows one key or one connected app and 30 calls a minute. Folder connectors have no file cap of their own. See exactly what Free includes on the pricing page.

Which AI tools work besides Claude?

Anything that speaks MCP over HTTP: ChatGPT, Cursor, VS Code with Copilot, Visual Studio, OpenAI Codex CLI, Gemini CLI, Windsurf, Zed, Cline, Continue.dev and JetBrains AI all have a ready-made recipe on the Connect tab.

Still stuck? Open Support in Query Streams and tell us which step you are on and what you see. We will get you connected.
Updated on September 28, 2026

Powered by BetterDocs