product image
product image
product image

Loglight

$29/ month
14 day trial

Self-hosted threat detection from logs & network flows — with a 3D network map

You have logs. Nobody reads them — so a brute force or a beacon is found a week too late. Loglight is the self-hosted SIEM-lite for that gap, and since v0.2 it sees your network flows too.

Features

  • Inputs: syslog (RFC3164/5424), files, journald, Docker, Windows events, NetFlow v5/v9/IPFIX
  • Seven detections: brute force, distributed auth-failure spikes, port and host scans, abnormal egress, new privileged accounts, beaconing, new listening service
  • Correlation: scan → brute force → successful login from one source = one CRITICAL kill-chain incident with timeline
  • 3D network map (fully offline): who talks to whom, node size = traffic, detected hosts glow by severity
  • Receives other Hexward tools’ findings over syslog; each shows the numbers and the fix

Server requirements

  • Linux x86-64; single static binary or Docker
  • Measured: ~12 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Sizing: 1 vCPU / 1 GB RAM / 5 GB disk for a few hosts; 2 vCPU / 2-4 GB / 20+ GB at Pro’s 10 sources with flows
  • Dashboard 127.0.0.1:8427; inbound syslog 5514 and the flow ports you configure

Tiers. Free: 1 source (GitHub). Pro: 10 sources, correlation, email/Slack/Telegram. Team: unlimited, multi-user, PagerDuty/MS Teams. 14-day trial.

Self-hosted; flows are metadata only; offline activation.

Delivery. Automatic: key by Whop DM after checkout; download in the Downloads tab.

Whop sells paid licences only. Free: github.com/nizartuanku/loglight