---
title: "Setting Up a Lightweight Log Storage / Query / Analysis Service (Seq Log Server) on QNAP Docker Station — Using .NET Core + NLog as an Example"
description: "How to set up a lightweight Seq log server on QNAP Docker Station, using .NET Core + NLog as an example, with structured log search, SQL query support, and reporting features."
canonical_url: "https://blog.markkulab.net/en/post/seq-log-server"
author: "Mark Ku"
author_url: "https://blog.markkulab.net/en/author/mark-ku"
site: "Mark Ku's Tech Notes"
date_published: "2021-12-24 01:01:01 +0800"
category: ".NET Core"
tags: ["seq", "log server", "nlog", "net core", "docker", "qnap"]
language: "en"
license: "CC BY 4.0"
license_url: "https://creativecommons.org/licenses/by/4.0/"
attribution: "when reusing or quoting, credit the author and link back to the original"
---

# Setting Up a Lightweight Log Storage / Query / Analysis Service (Seq Log Server) on QNAP Docker Station — Using .NET Core + NLog as an Example

## Setting Up a Lightweight Log Storage / Query / Analysis Service (Seq Log Server) on QNAP Docker Station — Using .NET Core + NLog as an Example

## The Problem
As the number of websites and distributed services grows, debugging gets harder when logs are scattered across servers and containers. Tracking issues becomes painful, and the root cause is often hard to find. This is why introducing a log aggregation service really matters.

## Evaluation
Common log aggregation options include ELK, Exceptionless, Seq, and Splunk. We used ELK at my previous company. ELK is feature-rich, but for a small team it's overkill to maintain — it also demands a lot more system resources. Personally, after using all of them, I prefer Seq's query interface.

## Let's Set Up the Seq Log Server

### Create > Search > seq > Click "datalust\seq" > Install
![QNAP Container Station Docker Hub search highlighting datalust/seq image](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/vOKFKGb.png)

### Set the environment variable to ACCEPT_EULA=Y
![QNAP Docker container setup, ACCEPTEULA environment variable set to Y](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/4GMQUf2.png)

If you don't have a QNAP NAS, you can also install via Docker.
```
docker run --name seq -e ACCEPT_EULA=Y -p 8900:80 -p 5341:5341 datalust/seq
```

### Once the SEQ container is running, click the link icon (highlighted in red) to enter the admin UI.
![QNAP Container Station showing highlighted link icon for seq-1 container](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/FXjmVRc.png)

## Next, create an API key for NLog to write logs
### After entering the admin UI > click the account avatar > API KEYS
![Seq admin UI dropdown menu with API keys option highlighted](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/jcHdzJT.png)

### ADD API KEY > enter a name for the API key
![Seq API key creation form with SHOP title and Ingest permissions](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/iljGFAT.png)

### Copy the generated API key into NLog's config file
![UI dialog showing new Seq Log Server API key token](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/HLthY8U.png)
(This token has been revoked.)

## Open your .NET Core project and install the NLog extensions
```
NLog.Extensions.Logging // Skip logging from all Microsoft components
NLog.Targets.Seq
```

## nlog.config configuration
```
<?xml version="1.0" encoding="utf-8"?>

<nlog xmlns="http://www.nlog-project.org/schemas/NLog.xsd"
      xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
      autoReload="true"
      throwConfigExceptions="true"
      internalLogToConsole="true"
      internalLogLevel="Info" internalLogFile="D:\temp\nlog-internal.log"
	  >

  <!--加載ASP.NET Core插件-->
  <extensions>
    <add assembly="NLog.Web.AspNetCore" />
    <add assembly="NLog.Extensions.Logging" />
    <add assembly="NLog.Targets.Seq" />
  </extensions>

  <variable name="log-root" value="Log" />
  <variable name="log-daily" value="${log-root}/${date:format=yyyy-MM}/${shortdate}" />
  <!-- the targets to write to -->
  <targets>
     <target name="seq" xsi:type="BufferingWrapper" bufferSize="1000" flushTimeout="2000">
      <target xsi:type="Seq" serverUrl="http://{your seq server url}/" apiKey="{api key}">
        <property name="ThreadId" value="${threadid}" as="number" /> 
        <property name="MachineName" value="${machinename}" />
        <property name="Environment" value="${aspnet-environment}" />
        <property name="Logger" value="${logger}" />
        <property name="IP" value="${aspnet-request-ip}" />
        <property name="Url" value="${aspnet-request-url:IncludeHost=true:IncludePort=true:IncludeQueryString=true:IncludeScheme=true}" />
        <property name="Code" value="${aspnet-response-statuscode}" />
        <property name="TraceId" value="${aspnet-TraceIdentifier:ignoreActivityId=true}" />
        <property name="ActivityId" value="${activityid}" />
        <property name="RequestHeaders" value="${aspnet-request-headers:HeaderNames=Host,Referer,Origin,Authorization}" />
        <property name="RequestQueryString" value="${aspnet-request-querystring}" />
        <property name="RequestBody" value="${aspnet-request-posted-body}" />
        <property name="ClientIP" value="${aspnet-request-ip}" />
		<property name="Custom" value="${gdc:item=Custom}" />        
        <property name="CorrelationId" value="${aspnet-TraceIdentifier}" />
        <property name="AppName" value="Shop" />
      </target>
    </target>
  </targets>

  <!-- rules to map from logger name to target -->
  <rules>
    <!--跳過所有級別的Microsoft組件的日誌記錄-->
    <logger name="Microsoft.*" minlevel="Trace" final="true" />
	<!--跳过所有级别的CorrelationId组件的Info 層級下的 Log-->
    <logger name="CorrelationId.*" minlevel="Trace" maxlevel="Info" final="true" />
    <logger name="*" minlevel="Info" writeTo="seq" />
  </rules>
</nlog>
```

## Once your sites and services start up, the log server will start receiving logs written by NLog from your .NET Core apps.

![Seq log server dashboard showing a timeline of system events](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/veeXaaX.png)

### View error details
![Seq log server UI displaying detailed error logs and signal filters](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/6g5ZVQd.png)

### Filter by error level
![Seq log server displaying error events with 'Errors' filter selected](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/gPPpqsk.png)

### Keyword search
![Seq log server UI displaying InvalidOperationException errors with 'Errors' filt](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/wnB6q8d.png)

### Stats / report logs
![Seq log server dashboard showing event graphs, error count, and distinct types](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/xBzg0p6.png)

### Even cooler — you can query logs with SQL
![Seq log server dashboard showing a message filter and error exceptions](https://blog.markkulab.net/content/markku/posts/seq-log-server/images/anX4XtQ.png)

```
Common Seq query examples

LIKE query
@Message like '%notify%'

Query Error level logs
@Level = 'Error'

Find logs related to 'shop'
app = 'shop'

Count logs by level
select count(1) from stream group by @Level

Query notify-related logs
select datepart( @Timestamp,'day',8h) as GMT8_Day,datepart( @Timestamp,'hour',8h)  as GMT8_Hour,  datepart( @Timestamp,'minute',8h)  as GMT8_Minute,ToIsoString(@Timestamp) as GMT0,  @Level, ToHexString(@EventType) as EventType,  @Message, @Exception, @Properties
from stream where @Message like 'notify%' 
order by GMT0 desc 

```

## Wrap-up
Seq log server packs in a lot of features while staying lightweight. It's easy to configure, has low maintenance overhead, and is a great fit for small teams.

## Bonus — Frontend logs can also be sent to a Seq server via seq-logging.
[Frontend package on GitHub](https://github.com/datalust/seq-logging)

---

## About this article and its author

Originally published on [Mark Ku's Tech Notes](https://blog.markkulab.net/en/post/seq-log-server)

License: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — when reusing or quoting, credit the author and link back to the original

### About the author

**[Mark Ku](https://blog.markkulab.net/en/author/mark-ku)** — Software Solution Provider

- 10+ years senior software engineer, now an AI Builder
- Focused on large-platform architecture — North-American e-commerce, AI SaaS subscription billing
- Combining AI Agents and automation to build evolvable product foundations

### Free tools built by the author

All of these are free to use:

- [Free PDF Sign Tool](https://blog.markkulab.net/en/tools/pdf-sign): Online PDF sign tool — draw, type, or upload a signature, then drag, resize, and download. Everything runs in your browser; nothing is uploaded.
- [VS Code Refactory](https://blog.markkulab.net/en/tools/refactory): Refactory is a VS Code refactoring extension: 34 actions plus a 37-rule code-smell inspection layer with a Code Health dashboard, across 18 languages, backed by 534 tests. It learns your repo's conventions: where interfaces live, where DI is registered, whether 'use client' belongs. It ranks files by git churn × complexity so you know what to fix first, and hands any smell to the Claude Code already on your machine. Free to use, and your source never leaves your computer.
- [DB-Kit Database Manager](https://blog.markkulab.net/en/tools/db-kit): DB-Kit is a lightweight, cross-platform database manager built with Tauri + Rust + React. Manage MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, MongoDB, Redis, Kafka, Elasticsearch and RabbitMQ from one consistent interface: passwords encrypted in the OS keychain, SSH tunnels, full CRUD, a visual query builder, stacked multi-statement result sets, cross-connection data transfer and compare/sync, Excel / CSV import & export, visualized execution plans, ER diagrams, scheduled backups, SQL stress testing with p50–p99 latency percentiles, a 15-rule SQL review engine, Kafka message browsing with monitoring & alerts, a bilingual UI (Traditional Chinese / English), a built-in AI assistant (natural-language SQL, AI review and tuning advice) and the dbk CLI. Free and open source (MIT), with installers for Windows, macOS and Linux.
- [VS Code Super Mermaid](https://blog.markkulab.net/en/tools/super-mermaid): Super Mermaid is a VS Code extension for beautiful Mermaid diagrams out of the box: auto-colored live preview, mouse pan & zoom, high-res PNG / SVG export, 21 templates and multiple themes. Free and open source (MIT).
- [React Super Mermaid](https://blog.markkulab.net/en/tools/react-super-mermaid): react-super-mermaid is an open-source React component library: render beautiful Mermaid diagrams with a single <MermaidViewer>, with built-in colorful / sketch themes, pan & zoom, in-diagram search, and high-res SVG / PNG export. Lightweight, SSR-safe, fully typed. Free and open source (MIT).
- [Jira / Confluence Super Mermaid](https://blog.markkulab.net/en/tools/jira-super-mermaid): An Atlassian Forge app: write Mermaid syntax directly inside a Jira issue or a Confluence page and get flowcharts, sequence diagrams, state machines and Gantt charts. 11 diagram types, SVG / PNG export, light and dark themes, full CJK support. Runs on Atlassian: your diagrams live in your own site and the app calls no third-party service. Free, coming soon to the Atlassian Marketplace.
- [Mermaid Live Preview](https://blog.markkulab.net/en/tools/mermaid-preview): Write Mermaid in your browser, see it render instantly, and share the whole diagram as a single link. No sign-up, nothing uploaded to a server, and mermaid.live share links work as-is.
- [React Intl Phone Number](https://blog.markkulab.net/en/tools/react-intl-phone-number): react-intl-phone-number is an open-source React component: framework-agnostic and antd-free, with E.164 in/out, a searchable flag / country-code dropdown, configurable validation levels (strict / mobile-strict / loose), themeable CSS, and i18n — phone logic powered by google-libphonenumber. Lightweight and fully typed. Free and open source (MIT).
- [Uptime Kuma Cluster](https://blog.markkulab.net/en/tools/uptime-kuma-cluster): Turn single-node Uptime Kuma into a highly available cluster: OpenResty + Lua smart load balancing, shared MariaDB state, health checks and automatic failover, plus cluster-management REST APIs. One Docker Compose command to start. Free and open source (MIT).
- [Special Education](https://blog.markkulab.net/en/education): Learning materials crafted for special education students

### Daily podcasts

- [Mark's Tech Insights — Daily AI News](https://blog.markkulab.net/en/category/tech-news): Daily curated AI and tech trends. Catch the latest developments via audio summaries — covering AI applications, software architecture, DevOps, and engineering practice. — RSS: https://blog.markkulab.net/feed.xml
- [AI股市蝦聊](https://blog.markkulab.net/en/category/ai-stock-chat): Every trading day, an AI-analyzed take on the Taiwan stock market, delivered as a two-host conversation covering the session and the next-day outlook. — RSS: https://blog.markkulab.net/ai-stock-chat/feed.xml
- [開源好物週報](https://blog.markkulab.net/en/category/open-source-weekly): A weekly two-host pick of free open-source tools surfaced from real Hacker News, GitHub, and Reddit buzz — what pain they solve and the fastest way to get started. — RSS: https://blog.markkulab.net/open-source-weekly/feed.xml

### Newsletter

[Subscribe to the newsletter](https://blog.markkulab.net/en/subscribe) — Be the first to know about new posts. No spam, unsubscribe anytime.
