{"repo":"turbot/tailpipe","free":true,"listed":false,"github":"https://github.com/turbot/tailpipe","clone":"git clone https://github.com/turbot/tailpipe.git","description":"select * from logs; Tailpipe is an open source SIEM for instant log insights, powered by DuckDB. Analyze millions of events in seconds, right from your terminal.","language":"Go","stars":578,"topics":["duckdb","tailpipe","aws","azure","detections","devops","forensics","gcp","incident-response","log-analysis"],"license":"AGPL-3.0","category":"deployment-docker-iac","readme_excerpt":"&nbsp; &nbsp; &nbsp; select from logs; Tailpipe is the lightweight , developer-friendly way to query logs. Cloud logs, SQL insights . Collects logs from cloud, container and application sources. Query and analyze your data instantly with the power of SQL, right from your terminal. Fast, local, and efficient . Runs locally, powered by DuckDB's in-memory analytics and Parquet's optimized storage. An ecosystem of prebuilt intelligence . MITRE ATT&CK-aligned queries, prebuilt detections, benchmarks, and dashboards, all open source and community-driven. Built to build with . Define detections as code, extend functionality with plugins and write custom SQL queries. Demo time! Watch on YouTube → Documentation See the documentation for: - Getting started - It's just SQL! - Managing Tailpipe - CLI commands Plugins and query examples are on the Tailpipe Hub. Prebuilt detection benchmarks are on the Powerpipe Hub. Getting Started Install Tailpipe from the downloads page: Install a plugin from the Tailpipe Hub for your favorite service (e.g. AWS, Azure, GCP): Configure your connection credentials, table partition and data source. Here is an AWS CloudTrail example: Download, enrich, and save logs from your source (examples): Enter interactive query mode: Run a query: Detections as Code with Powerpipe Pre-built dashboards and detections for the AWS plugin are available in Powerpipe mods, helping you monitor and analyze activity across your AWS accounts. For example, the AWS CloudTrail Logs","default_branch":null,"files":null,"tree":[],"storefront":"/r/turbot","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/turbot/tailpipe/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}