ANYIT
KO Contact us
R&D/LOGTREE
LOGTREE v7.9.3

The SIEM platform you run
with Local AI

One stack for collection, storage, analysis and evidence.

logtree — log explorer LIVE 3s
show only traffic to port 443 from blocked external IPs
Conditions set by AI action = DENY dst_port = 443 time = 1h
18,402 matchesTime · source · severity · origin
14:02:11 fw-edge-01 CRITICAL 203.0.113.44 → 10.20.3.8:443 DENY tcp
14:02:11 fw-edge-01 WARNING 198.51.100.7 → 10.20.3.8:443 rate limit
14:02:10 waf-dmz-02 CRITICAL 203.0.113.44 → SQLi blocked 942100
DESIGN PRINCIPLES

Four principles behind LogTree

01

One pipeline, one owner

Collection, search, visualisation and retention live in one product, so ownership is clear and licensing stays simple.

02

Search anyone can run

Ask in plain language and it searches. Logs become a team asset once the people doing the work can query them.

03

Evidence in its original form

The raw text is sealed with SHA-256 and kept alongside, so integrity can be proven immediately in audit or investigation.

04

Predictable retention cost

Retention policy is set per source — regulated logs kept long, high-volume logs kept short — so you pay for what you need.

A one-way pipeline in ten containers

INGEST
BUFFER
INDEX
STORE
STAGE 01
Collector
GO · UDP/TCP :514

Syslog arrives on a single port, lands in Kafka verbatim, and is written to raw archive segments at the same time.

STAGE 02
Kafka
DURABLE BUFFER

Logs survive an indexer restart; processing resumes from the offset.

STAGE 03
Indexer
GO · PARSE + ALERT

Parser rules extract fields, alert rules are evaluated on ingest, and writes go out in batches.

STAGE 04
ClickHouse
COLUMNAR STORE

Columnar storage and compression keep aggregation and search in seconds even at hundreds of millions of rows.

A structure that improves with scale

Ingest throughput
50K EPS

Sustained on a single node; scales linearly as nodes are added.

Search response
<1 sec

p95 for filtered queries over 100 million records.

Storage compression
1/10

Against raw size, with columnar compression plus zstd archives.

Detection latency
At ingest

The indexer evaluates alert rules on the stream itself.

※ Figures are internal measurements on a reference configuration (single node, local NVMe). Actual results vary; we verify with a PoC before adoption.

Storage

One tenth of the original

Raw logs100%
Columnar + zstd10%

Per-source retention policies keep high-volume, low-value logs short and regulated logs long — the whole set is not retained for the same period.

Integrity chain

Each day's seal locks the day before

07-30
seq 410
27ab…5d10
07-31
seq 411
9f3c…a7e1
08-01
seq 412
c5e2…40bd
08-02
seq 413
awaiting seal
SHA-256AES-256DAILY 03:00no gaps
Adopted

PoC results in four weeks

WEEK 1
Requirements

Target devices, expected EPS, retention period and regulatory requirements are confirmed, and a sizing proposal follows.

WEEK 2
Install & integrate

Offline installation in the closed network, then real device logs are connected and parser rules set.

WEEK 3
Measured validation

Throughput, search response, compression ratio and seal verification are measured in your own environment.

WEEK 4
Report & handover

Results and a TCO comparison are delivered as a report, and the same setup moves into operation.

Please feel free to contact us — we will respond promptly.
Technical 1660-3389 · Sales 053-600-8822 · support@anyit.net
Request consulting