Skip to content
logmast

One path from a log line to a fix

Logmast is deliberately narrow. It collects what your services emit, makes it understandable, correlates failures across operations, and hands you a permanent link to the evidence.

Collect

Structured logs and failure reports over HTTPS, from a Rust layer or any language that can post JSON.

  • Committed before acknowledged. A batch is on disk before the API answers, so a success really means stored.
  • Retries are free. Resend after a timeout and duplicates are recognised, never double counted.
  • Bad input is explained. An invalid batch is rejected whole, with an error for each field that failed.
  • Back-pressure is honest. Rate limits and quotas return clear codes and a Retry-After, never silent drops.
let config = logmast_reporting::Config::from_env()?.expect("LOGMAST_* set");
let (layer, _guard) = logmast_reporting::start(config)?;

tracing_subscriber::registry()
    .with(tracing_subscriber::fmt::layer())
    .with(layer)               // batches, redacts and ships in the background
    .init();

// Anything you already log at warn or above is collected.
tracing::error!(code = "BILLING.INVOICE.PERSIST_FAILED", invoice_id, "could not persist invoice");

// Or report a typed error with its cause chain and a correlation id.
logmast_reporting::report_error(&err, Some("BILLING.INVOICE.PERSIST_FAILED"), None, "invoice.persist", Some(&request_id));

200 OK in 18 ms, committed to disk

{ "receipt_id": "0192f3…", "new_events": 1, "duplicates": 0 }

Ingest limits
Events per batch100
Request size1 MiB
Event size64 KiB
Attributes per event32
Sustained rate200 events/s per workspace
Duplicate detection90 days

Process

Redaction, grouping and indexing happen on arrival, so a new failure is searchable in well under a second.

Groups that stay put

Every group gets a permanent ID and URL. Rename a service or move it between projects and every link in your tickets and pull requests still works.

Grouping follows a fixed order: producer fingerprint, server rule, error code with cause, normalised stack, then message. The group page shows which one decided.

Search by what you know

Paste a correlation ID from a customer ticket and see every event it touched across every service. Or search messages and stack traces in full text.

Browse the tree of error code prefixes to see which part of the system is struggling, from BILLING down to one operation.

Investigate failures

Search retained evidence, follow correlation IDs and review grouped occurrences. Observed failures do not measure availability; keep your existing uptime monitor.

Alert

Alerts that arrive once, carry the evidence, and never bury you.

Rules you can reason about

Alert on the first occurrence of a new group, on ten events in five minutes. Threshold alerts rearm after things calm down, and each group has a cooldown.

A workspace budget caps email per hour. The final message in a bad hour is a summary of everything held back.

Mute with a reason and an end date

Every mute records why and until when. Preview it against recent history before confirming, so you know exactly what goes quiet.

Acknowledging is separate: say you are on it without hiding anything from the rest of the team.

API

Everything you can see, your tools and agents can read.

Read tokens expose groups, occurrences, search and workspace settings over a stable JSON API. Link a pull request to a group, let an on-call bot post a diagnostic summary, or feed evidence to a coding agent.

Logmast stays in its lane: it owns the evidence and the notification, and gives every piece of it a permanent URL. Your tracker, your repository and your automation point back to it.

GET /api/v1/groups?service=billing-api&state=needs_attention
GET /api/v1/groups/0192f3a1-…/occurrences?correlation_id=req-7b1e
GET /api/v1/catalog

Send your first logs this week

Create a trial in the console or use the agent guide to enroll through the management API.