Logstrm¶
The lean data plane for security telemetry¶
Logstrm is a high-performance, declarative log router built for teams that need to control SIEM ingestion cost without adding another heavyweight runtime to the production path.
It ingests security and network events, evaluates routing rules, removes unnecessary fields, masks sensitive values, enriches records locally, and delivers compact batches to downstream systems such as Microsoft Sentinel and Elasticsearch.
-
:material-cash-minus: Reduce Sentinel cost
Apply field-level filtering before ingestion. Logstrm is designed to reduce Sentinel-bound volume by up to 40% in representative security telemetry workloads; validate the saving against your own event mix and retention policy.
-
:material-speedometer: Ultra-lightweight routing
A single Go binary provides ingestion, routing, transformation, batching, retry and observability without a JVM or Node.js runtime.
-
:material-code-braces: Declarative operations
Version-controlled YAML and Expr conditions let platform and security engineers change behavior through reviewable configuration rather than custom scripts.
-
:material-shield-check: Safe egress
Keep only the fields required downstream, mask PII with RE2-compatible rules, and persist delivery failures through the bounded dead-letter queue.
Where Logstrm fits¶
Logstrm is the data plane between log producers and security platforms. The optional Manager is the control plane for configuration history, rollout and rollback. They can be operated independently, which makes it possible to start with one local process and grow into a Kubernetes deployment.
Start here¶
- Follow the Quickstart using the release package supplied for your organization.
- Read Architecture to understand the Data Plane/Control Plane boundary.
- Use the YAML specification as a configuration reference and adapt it to your enabled connectors.
- Review the benchmark results and their limitations before using them for capacity planning.