Four principles behind LogTree
One pipeline, one owner
Collection, search, visualisation and retention live in one product, so ownership is clear and licensing stays simple.
Search anyone can run
Ask in plain language and it searches. Logs become a team asset once the people doing the work can query them.
Evidence in its original form
The raw text is sealed with SHA-256 and kept alongside, so integrity can be proven immediately in audit or investigation.
Predictable retention cost
Retention policy is set per source — regulated logs kept long, high-volume logs kept short — so you pay for what you need.
A structure that improves with scale
Sustained on a single node; scales linearly as nodes are added.
p95 for filtered queries over 100 million records.
Against raw size, with columnar compression plus zstd archives.
The indexer evaluates alert rules on the stream itself.
※ Figures are internal measurements on a reference configuration (single node, local NVMe). Actual results vary; we verify with a PoC before adoption.
One tenth of the original
Per-source retention policies keep high-volume, low-value logs short and regulated logs long — the whole set is not retained for the same period.
Each day's seal locks the day before
PoC results in four weeks
Target devices, expected EPS, retention period and regulatory requirements are confirmed, and a sizing proposal follows.
Offline installation in the closed network, then real device logs are connected and parser rules set.
Throughput, search response, compression ratio and seal verification are measured in your own environment.
Results and a TCO comparison are delivered as a report, and the same setup moves into operation.