I love projects like these. I honestly love logs and SIEMs. It wouldn’t hurt my feelings to work on a big SIEM product one day.

blog.nano.rs
Introducing nano | nano blog — nano / blog
nano is a lightweight SIEM in Rust on ClickHouse, with a piped query language, a real detection lifecycle, and AI that does actual investigation work. Here is what it is and why every piece is the way it is.