Cost is the argument against Splunk and control is the argument against Cribl. AI is the third, and the difference there is not a feature comparison, it is where the model runs. Plain-English querying shipped in Phase 7 and stays an option rather than a replacement for writing a query: every generated query compiles through the same IR and executor as a hand-written one, with the same tenant scoping, cost guardrails and audit logging. The model suggests, it does not get a private path to the data. AI-assisted analysis and explanation is the end state and is not built. Authoring answers "how do I ask this"; the valuable question is "what does this mean" -- what changed in a result set, why an alert fired and what preceded it, summarising an incident from the records around it. Recorded on the status page as an end-state goal rather than a numbered phase, because it is a property the product keeps rather than a thing to finish and tick off. Local is the non-negotiable part, and it is worth stating as position rather than as a bullet: the default runs qwen2.5-coder through Ollama on the customer's own hardware, Apache-2.0 weights chosen so Phase 6's licence work survives contact with the model, and the cloud adapter is opt-in and off by default. Logs are the most sensitive unstructured data most organisations hold -- credentials in stack traces, customer identifiers, internal topology -- so an assistant that reads them is either running where the data already is, or it is a data-egress decision wearing a helpful interface. The constraint it imposes is stated too, because it bounds what can be promised: a 7B model on a customer's hardware will not match a frontier model, and the honest claim is not that it is as clever but that it is good enough at a bounded task and runs somewhere you control. Analysis features have to be designed to that budget rather than assuming an API is one call away.
Open-core, Kubernetes-native log aggregation and observability.
Built to match Splunk on capability while winning on cost-per-GB,
with honest multi-tenant RBAC and a modern language stack.
Positioned against Cribl too — see positioning
for why that is a different claim, and what it means we still have to build.
Licensed AGPLv3 in its entirety — including
enterprise/. See Licensing.
What it does
Logs flow from a statically-linked Rust edge agent through Redpanda into a Go ingest pipeline, landing in ClickHouse for analytics and Tantivy for full-text search. One query language spans both stores, compiling to a single execution plan:
service=api | where status>=500 | stats count by host | sort -count
message:"connection refused" | stats count by host
Raw ClickHouse SQL stays available as an escape hatch and compiles to the same IR, so performance doesn't depend on which syntax you write.
On top of that sit dashboards, an alerting evaluator with threshold and
absence rules, a CLI (cairnobsctl), a Terraform provider, and AI-assisted
query authoring that runs against a self-hosted Ollama model by default — no
cloud dependency.
Architecture
| Component | Stack |
|---|---|
| Edge agent | Rust, musl static target |
| Transport | Redpanda (Kafka API) |
| Ingest / parse | Go |
| Analytical store | ClickHouse |
| Full-text index | Tantivy (Rust) |
| Control plane / API | Go, gRPC + REST gateway |
| Control-plane metadata | PostgreSQL |
| Frontend | SvelteKit + TypeScript |
| Deployment | Kubernetes Operator (kubebuilder), Helm, docker-compose |
PostgreSQL is scoped strictly to control-plane config — dashboards, panels, alert rules and state, notification targets, delivery log — because those need row-level locking and transactional read-modify-write that ClickHouse's MergeTree family doesn't provide. Log data itself never touches it.
Full spec: docs/architecture.md. Read it before
changing any component; the storage/query split in particular is deliberate.
Repository layout
Monorepo, one top-level directory per component, each with its own README.md,
unit tests, and Dockerfile.
agent/ Rust edge agent (Linux + Windows)
transport/ Redpanda topics and schemas
ingest/ Go ingest and parse pipeline
storage/ ClickHouse schema and migrations
search/ Tantivy full-text index service
api/ Control plane, query compiler, RBAC
alerting/ Rule evaluator and notification delivery
metadata/ PostgreSQL schema and migrations
web/ SvelteKit frontend
cli/ cairnobsctl
proto/ gRPC service definitions
terraform/ Terraform provider
enterprise/ SSO, multi-tenancy, per-tenant provisioning
deploy/ Helm charts and Kubernetes operator
docs/ Architecture, design docs, per-phase runbooks
hack/ Development scripts
enterprise/ stays a separate module that core never imports from. Since the
Phase 6 relicensing that boundary is architectural rather than legal — it keeps
core buildable and deployable standalone, and keeps tenant resolution
server-side.
Running locally
docker compose up
The web UI comes up on http://localhost:3000 and the API on :8080;
alerting is on :8081 and enterprise auth on :8082. The agent connects to
ingest over mTLS gRPC on :4317. search is reachable only on the compose
network — it publishes no host port.
COMPOSE_PROFILES in .env selects the query-serving binary — single-tenant
(default) or enterprise for the multi-tenant path. They're mutually
exclusive, the same choice Helm's enterprise.enabled flag makes for a real
cluster. Override per invocation:
COMPOSE_PROFILES=enterprise docker compose up
Kubernetes deployment via the Helm chart in deploy/.
Status
Built in phases; each has a runbook in docs/ recording how it was verified.
Full per-phase detail is in docs/status.md.
| Phase | Scope | Status |
|---|---|---|
| 0 | Agent → Redpanda → ingest → ClickHouse, queryable end-to-end | Shipped |
| 1 | Windows Event Log + journald, SQL and full-text paths | Shipped |
| 2 | Unified query language across both stores | Shipped |
| 3 | Dashboards, alert rules, notification delivery | Shipped |
| 4 | RBAC, tenant isolation, audit logging, per-tenant ClickHouse | Shipped |
| 5 | Frontend redesign and design system | Shipped |
| 6 | License compliance audit and remediation | Shipped |
| 7 | AI-assisted query authoring | Shipped |
Phase 4 is shipped, and the environment that proved it is gone. Every
control the phase defines was verified against real infrastructure at least
once — a docker-compose stack with real ClickHouse and Postgres, a local kind
cluster, and both SSO protocols against a real Auth0 tenant — finding eight
bugs that no amount of Docker-free testing could have caught. The prototype
VPS was retired on 2026-09-04, so that verification is a record rather than
something you can re-run: see
docs/phase-4-runbook.md.
Two limits worth stating plainly. SSO has been tried against one IdP, not two,
and no production-grade cluster has run this. And demo.cairnobs.org is not
evidence for any of it — the demo runs the single-tenant profile, so it
exercises the OSS path and says nothing about RBAC or tenant isolation.
The Windows agent code (EvtSubscribe, ETW, service registration) has never
run on real Windows — no Windows toolchain existed in the build environment.
ETW additionally sits behind a feature flag, since it needs elevated
privileges. Details in agent/README.md.
Terraform provider coverage is partial by necessity: dashboards and panels have
full CRUD, while alert rules and notification targets are create/destroy only,
because alerting exposes no PUT /rules/{id} or PUT /targets/{id} to
update against. Tenant and RBAC resources are disclosed future work —
terraform/README.md accounts for exactly what exists.
Contributing
- Conventional commits. Every change should be a logically complete, independently revertible unit.
- Rust:
cargo clippy --all-targets -- -D warningsmust pass. - Go:
go vetandgolangci-lint, no globals for shared state. - Every UI action must map to a documented REST/gRPC call — no UI-only logic. The CLI and Terraform provider are first-class, not afterthoughts.
- Prefer boring, well-understood dependencies. This is infrastructure software; operators need to trust it.
Licensing
Copyright (C) 2026 Coffey Labs.
AGPLv3, no exceptions — see LICENSE. enterprise/ was under a
commercial-license stub from Phase 4 through Phase 5; Phase 6 relicensed it to
match core. The full record and its business-model consequences are in
docs/compliance/license-audit-report.md.
The default AI deployment uses qwen2.5-coder (Apache-2.0) via Ollama,
chosen specifically to keep that license purity intact. The cloud adapter is
pluggable, opt-in, and off by default.