Unified log collection
Ingest from syslog TCP/UDP/TLS, webhooks, cloud APIs, and files. 200K+ events/sec on a single node — fewer appliances, lower cost.
The platform
logrok unifies log management and threat detection in one self-hosted platform. Everything below runs inside your environment, with no telemetry and no call-home.
Ingest from syslog TCP/UDP/TLS, webhooks, cloud APIs, and files. 200K+ events/sec on a single node — fewer appliances, lower cost.
Plain text, regex, Lucene query syntax, and natural-language AI search across billions of events.
Drag-and-drop topology builder for collection pipelines. Generate, deploy, and version configs visually — Git-backed.
Custom dashboards with live widgets. Alert rules on patterns, thresholds, or anomalies.
Automatically detect repetitive log patterns and classify, route, or suppress noise to surface actionable events.
25+ built-in detection rules with MITRE ATT&CK mapping, correlation logic, and a custom rule DSL.
AES-256-GCM at rest with per-tenant keys. Route to S3, Kafka, Splunk, Elasticsearch, Azure, GCP, Loki, Datadog, and more.
Append-only audit log of every platform action — non-repudiation for compliance and forensic review.
MFA-ready SSO with FIDO2, YubiKey, and CAC/PIV support. Defense-in-depth tenant isolation.
Events classified to OCSF v1.3 for vendor-neutral detection rules and data-lake federation.
AI, honestly
Classifies repetitive patterns as noise, useful, or unclassified, then routes or suppresses them.
Produces context briefs, ready-to-run queries, and response recommendations for an open finding.
Turns plain-language questions into queries over the log store.
A model evaluates per-source behaviour at run time to flag outliers — no data is shipped to a third party.
Exposes search, analyze, and summarize to AI tooling over the Model Context Protocol.
Detection runs in your environment. logrok ships no pretrained model that sends your data out, and runs fully offline in air-gapped deployments.
Architecture
REST API, web UI, and an AI agent interface. Pipelines, search, alerts, and automation.
High-performance log collector with config agents. Zero-touch pipeline deployment.
SQL analytics engine, config store with row-level security, SSO, and encrypted local storage.