SiftLog Platform
Always-on log correlation daemon for distributed infrastructure. One stream. Every source. The failure in seconds.
What it does
SiftLog Platform (siftlogd) reads from your existing log infrastructure — Loki, CloudWatch, Elasticsearch, Datadog, Google Cloud Logging, and local files — merges every source into a single time-ordered stream, and runs three signal detectors continuously. When something breaks at 3am, you read 9 lines instead of 61,000.
Three signals
- Cascade Detection. Identifies the origin service and propagation order of downstream failures, including trace ID correlation across services.
- Anomaly Detection. Tracks per-service error rates against a rolling baseline and flags degradation before it triggers your alerting thresholds.
- Silence Detection. A service that stops logging is often the most important signal. SiftLog tracks expected event volume and flags services that go quiet.
Zero infrastructure changes
No agents. No sidecars. No schema requirements. SiftLog reads from the log aggregation layer you already have. Deploy in minutes as a single self-contained binary with no runtime dependencies.
Supported sources
- Local log files (glob patterns, tail mode)
- Grafana Loki
- AWS CloudWatch Logs
- Elasticsearch / OpenSearch
- Datadog Logs API
- Google Cloud Logging
Platform binaries
- Windows 64-bit
- Linux amd64
- Linux arm64
- macOS Intel
- macOS Apple Silicon
SiftLog Platform
Always-on log correlation daemon. Cascade, anomaly, and silence detection across every log source in your infrastructure.