Skip to main content
Introducing packages.sweber.dev
All posts
Release1 min read

Logarithm Pro 0.7.0 released

Elasticsearch, OpenSearch and Grafana Loki sinks, plus retries with exponential backoff and a dead-letter queue so a SIEM outage no longer costs you audit events.

By Seya Weber

Logarithm Pro 0.7.0 is out and available to all Pro customers. The free packages stay at 0.4.0. Nothing breaks: 0.6.0 code keeps working as it is.

Security teams want audit events in their SIEM, and they want them reliably. This release adds two more destinations and makes every destination robust against outages.

Elasticsearch, OpenSearch and Loki

import { elasticSink, lokiSink } from "@weber-development/logarithm-export"

elasticSink({ url: "https://es.example.ch:9200", index: "audit-log", apiKey: process.env.ES_KEY! })
lokiSink({ url: "https://loki.example.ch/loki/api/v1/push", orgId: "acme", labels: { env: "prod" } })

elasticSink uses the _bulk API with the event id as document id, so a redelivery never creates duplicates. It also reports item errors that Elasticsearch hides inside a 200 response, which a naive status check would miss. lokiSink writes one JSON line per event, with nanosecond timestamps and the action as a label. Both work with basic auth, API keys or bearer tokens, and with your own fetch.

Retries and dead letters

A SIEM that is down for ten minutes used to mean ten minutes of missing events. withRetry wraps any sink, including the existing Splunk, Datadog and webhook sinks:

const siem = withRetry(splunkSink({ url, token }), {
  attempts: 5,
  deadLetter: (letter) => saveDeadLetter(letter), // { sink, events, error, failedAt }
})

// from a cron job
const stillFailing = await replayDeadLetters(await loadDeadLetters(), siem)

It retries with exponential backoff and jitter. Refused requests, such as a wrong token (4xx except 408 and 429), are not retried, because waiting does not fix them. After the last attempt the events go to your deadLetter callback and the error is still thrown, so onError of withForwarding hears of it. replayDeadLetters sends them again and returns the ones that still fail.

Update

pnpm add @weber-development/logarithm-export@latest @weber-development/logarithm-integrity@latest @weber-development/logarithm-retention@latest

Logarithm Pro is available on the package page and is part of the Compliance Bundle.

Package in this post

Logarithm

A self-hosted audit log for SaaS apps: who changed what, and when. Field-level diffs in your own Postgres or SQLite, and a ready React view for your customers' admins.

pnpm add @sweberdev/logarithm @sweberdev/logarithm-react
View package

Related posts

Release

Logarithm 0.3.0 released

Counts and breakdowns for dashboards, typed action catalogs, a MySQL and MariaDB store, and in Logarithm Pro alerts to Slack and Teams plus anomaly detection for unusual exports, deletions and failed logins.

Logarithm
Release

Logarithm 0.4.0 released

French and Italian for the activity log, and in Logarithm Pro an S3 and Cloudflare R2 archive for expired events plus log entries that prove your retention policy and erasures actually ran.

Logarithm
Release

Logarithm 0.5.0 released

A conformance suite so your own audit-log store behaves exactly like the built-in ones, a verified WCAG AA contrast for the viewer, and new guides for migrations, Drizzle and Prisma.

Logarithm