Self-hosted · Rust-native

Log search and operations, on your infrastructure.

Sciuro collects and indexes machine data, lets your team investigate it with SPL-style search, and turns saved searches into scheduled alerts — on servers you control.

Search workspace · interface preview with sample data
Sciuro Search: an SPL query, a completed job with 17,842 matched events, an events-over-time chart, the field list and raw events

From input to action

One system for collecting, searching and acting on logs.

01 / COLLECT

Bring data in

Receive events over HTTP, syslog and file inputs, or forward them from other hosts. Each input assigns index, host, source and sourcetype at ingest.

  • HEC
  • Sciuro TCP
  • TCP/UDP syslog
  • File monitor
  • Script
  • Host metrics
  • OTLP logs
02 / SEARCH

Investigate

Write pipeline queries, read raw events beside a timeline, and switch to statistics when a query transforms its results.

  • 40+ commands
  • 70+ eval functions
  • Fast · Smart · Verbose
  • Field summary
03 / ACT

Schedule and alert

Save a search, run it on a cron schedule, and trigger actions when its alert condition matches. Every firing keeps a link to the job that produced it.

  • Cron schedules
  • Webhook
  • Log event
  • Summary index
  • Suppression

Jobs & alerts

Know what is running, and what fired.

Every search runs as a job with an owner, an app and a lifecycle. Saved searches run on a schedule and keep a history of each firing and the actions it triggered.

Queued, running, paused and completed jobs with events, results, scanned volume and duration.

Search Jobs list showing done, queued, running and paused jobs with owner, app, counts and duration

Data & administration

Inputs, indexes and access, managed in one place.

See which inputs are receiving, what they assign at ingest and how much they have received. Configuration and access control live in Settings, next to the data they govern.

Data inputs list with HEC, Sciuro TCP, TCP, UDP, file monitor, script, metrics and OTLP inputs and an inspector for the selected input

In Settings

  • Indexes
  • Data inputs
  • Sourcetypes
  • Forwarding
  • Lookups
  • Field extractions
  • Saved searches
  • Apps
  • Users
  • Roles
Parsing
Sourcetypes set line breaking, timestamps, and JSON or regex field extraction, with a preview before you save.
Enrichment
CSV lookups, automatic lookups and an uploaded GeoIP database for iplocation.
Access
Roles combine capabilities, allowed indexes and search limits. Saved searches carry an owner, an app and sharing permissions.

Interface

Built for long investigations, from a 4K desk to a phone.

  • Calm by defaultHealthy status recedes. Colour is kept for state that changed and for data you need to compare.
  • Exact where it mattersQueries, raw events, timestamps and numbers use a monospaced data face; reading and controls use a sans face.
  • Three official themesSciuro Dark, Light and High Contrast, with contrast checked for body text, labels and controls.
  • English and KoreanThe interface is written in both languages with the same task intent.
Sciuro Search on a phone in the Dark theme
Sciuro Search on a phone in the Light theme

Deployment

Runs where your data already is.

About these screensThe images on this page show the next Sciuro interface, currently in development, rendered with sample data. They are not live search results.

Get in touch

See Sciuro on your own data.

Tell us about your log sources and how your team searches today.