What Cairn OBS does

Cairn OBS is an open-core, Kubernetes-native log aggregation platform: ship, search, visualize and alert on logs, with no feature held back for a paid tier. AGPLv3, the whole thing.

  • One query language, two engines — pipe syntax for the common case and raw SQL as an escape hatch, both compiling to the same plan across ClickHouse and Tantivy.
  • Dashboards — multi-panel dashboards from saved queries: line and bar charts, single-stat, heatmaps, top-N, on the same engine as the search bar.
  • Alerting — threshold and absence conditions on an interval, delivered to Slack, a webhook or PagerDuty, with every delivery attempt logged.
  • Cross-platform agent — one statically linked Rust binary: journald or files on Linux, Event Log and ETW on Windows.
  • Access control — role-based access, OIDC and SAML single sign-on, and append-only audit logging.
  • AI-assisted queries — plain-English questions turned into queries, with fix suggestions and autocomplete, self-hosted via Ollama by default.

More: cairnobs.org · Source

Questions go in Support; design and contributions in Development.