{"repo":"nano-rs/nano","free":true,"listed":false,"github":"https://github.com/nano-rs/nano","clone":"git clone https://github.com/nano-rs/nano.git","description":"Lightweight open-core SIEM in Rust — ClickHouse for logs, Postgres for state.","language":"Rust","stars":68,"topics":["clickhouse","log-management","observability","open-source","rust","security","siem","threat-detection"],"license":"AGPL-3.0","category":"security-tools","readme_excerpt":"A lightweight, opinionated SIEM. Search, detection, and triage for security analysts who want to ship signal — not babysit a data lake. Website · Docs · Discord · Hosted --- nano is built around a small set of beliefs: - The UDM is the contract. Logs land in 75+ explicit columns; ad-hoc fields go in ext . Searches stay fast because the schema does the work. - nPL beats SQL for hunting. A piped query language ( error stats count by src ip where count 10 ) keeps analyst muscle memory portable. - Detections have a lifecycle. Rules move Staging → Live → Alerting. Match counts and signals are visible at every step. - Restraint over decoration. 1px borders, 11–13px text, mono for IDs and timestamps. The UI is the same density a terminal user expects. This repository is the open-core engine, licensed under AGPL-3.0 . Hosted plans, the pivt AI assistant, Cases, incidents, and risk scoring are available from nano.rs. Install One command on any host with Docker: One command. 45 seconds. Working nano instance. ▶ Watch on YouTube The installer clones this repo to /nano , generates secrets, pulls the prebuilt images from ghcr.io/nano-rs , brings up the stack (postgres + clickhouse + api/search/jobs/web + vector + nginx), and walks you through creating the first admin account. Open http://localhost when it finishes. Prereqs: Docker, docker compose v2, git, openssl, curl. Minimum host: 2 vCPU, 4 GB RAM — the lowest stable spec, suitable for up to 10 GB/day of ingest. Below this, ClickHouse ","default_branch":null,"files":null,"tree":[],"storefront":"/r/nano-rs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nano-rs/nano/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}