Long-term, tamper-evident operational log archival on Sia.
ObsidianLog is a cold-tier destination for operational logs. It sits beside your hot observability stack, such as Grafana, Datadog, or ELK, and archives logs encrypted, compressed, and hash-chained for later retrieval and verification. You control the encryption keys.
It is for teams and developers who need logs to remain private, retrievable, and tamper-evident after they leave their primary monitoring system.
Trying the beta? Start at the Beta Testing page. It explains what to test, what a completed test looks like, and how to give feedback.
Download the archive for your platform from the
Releases page.
The official obsidianlog binary includes both the local and Sia backends.
No source build is required.
For complete macOS, Windows, and Linux installation instructions, including Gatekeeper and SmartScreen guidance, see the Quickstart.
On macOS or Linux, after extracting the archive in a terminal:
chmod +x obsidianlog obsidianlog-ingest
./obsidianlog initobsidianlog is a terminal application, not a GUI application. Run it with a
subcommand such as init. Double-clicking it only prints help and exits.
Choose the local backend in init. It needs no Sia account and keeps the
sample data on your machine. Leave the server running in one terminal:
./obsidianlog init
./obsidianlog serveIn a second terminal in the same folder, send and verify one sample log:
curl -s -X POST http://localhost:7080/ingest \
-H 'content-type: application/json' \
-d '[{"timestamp":"2026-09-18T10:00:00Z","service":"api","level":"info","msg":"hello"}]'
./obsidianlog query --service api --level info --from 24h --format human
./obsidianlog verifyFor step-by-step platform guidance, see the local-backend tutorial.
Choose sia during init to archive through a Sia indexer. The default
hosted option uses sia.storage, where you approve
ObsidianLog through your own account. You can also supply a self-hosted or
third-party indexer. The first Sia write may take several minutes, so allow
15–20 minutes for the full test. Use sample data only while evaluating it.
Follow the Sia backend tutorial for the complete flow and current hosted-service considerations.
- Quickstart: install and run the full local loop.
- Choosing a backend: local, hosted Sia Storage, or your own indexer.
- Send logs with Vector: connect a real log shipper.
- Docker Compose quickstart: run the local backend in a container.
- CLI reference:
init,serve,query, andverify. - Architecture and security: pipeline, threat model, and design decisions.
- Building from source and testing against a live Sia indexer: developer setup and optional live-Sia integration testing.
- Grant progress tracker: milestones, delivery status, and current success criteria.
Fork this repository and run the
Demo workflow from the Actions tab. It runs the
real local pipeline, init, serve, ingest, query, and verify, with no
Sia account or secrets required.
- Give beta feedback, report a bug, or ask a question.
- Read CONTRIBUTING.md before proposing a change.
- See SECURITY.md for vulnerability reporting and the security model.
This project is under the MIT license.
This project is supported by a Sia Foundation grant.