Cairn OBS is an open-core, Kubernetes-native log aggregation platform: ship, search, visualize and alert on logs, with no feature held back for a paid tier. AGPLv3, the whole thing.
- One query language, two engines — pipe syntax for the common case and raw SQL as an escape hatch, both compiling to the same plan across ClickHouse and Tantivy.
- Dashboards — multi-panel dashboards from saved queries: line and bar charts, single-stat, heatmaps, top-N, on the same engine as the search bar.
- Alerting — threshold and absence conditions on an interval, delivered to Slack, a webhook or PagerDuty, with every delivery attempt logged.
- Cross-platform agent — one statically linked Rust binary: journald or files on Linux, Event Log and ETW on Windows.
- Access control — role-based access, OIDC and SAML single sign-on, and append-only audit logging.
- AI-assisted queries — plain-English questions turned into queries, with fix suggestions and autocomplete, self-hosted via Ollama by default.
More: cairnobs.org · Source
Questions go in Support; design and contributions in Development.