Go to file
Hengfei Yang d5d0b23666
fix: accept org ingestion tokens for OTLP gRPC (#13627)
## Summary

- accept organization ingestion tokens (`o2oi_`) for OTLP gRPC logs,
metrics, and traces
- keep internal cluster, search, node, and other non-OTLP gRPC services
on the existing authentication path
- add coverage for accepted, missing, and internal-RPC token cases

## Root cause

The HTTP ingestion authentication path validates organization ingestion
tokens, but the global gRPC interceptor only recognized internal gRPC
tokens and user credentials. As a result, the same organization token
succeeded over HTTP OTLP and failed over gRPC OTLP with
`Unauthenticated: No valid auth token[5]`.

This change assigns the organization-token-aware interceptor only to
external OTLP services. Internal RPCs continue using the original
interceptor, preserving the existing security boundary.

## Testing

- `cargo test --release -p openobserve-api-grpc
handler::grpc::auth::tests --lib` (6 passed)
- `cargo build --release --bin openobserve`
- live local E2E on latest `main`: created a real organization ingestion
token, exported an OTLP log over gRPC, then searched the stream and
verified the expected record (`total=1`)

Fixes #12540
2026-08-04 15:07:10 +00:00
.agents chore: expose Claude skills to agents (#13212) 2026-07-16 04:31:05 +00:00
.cargo chore: UX revamp for Incidents RCA analysis (#13388) 2026-07-27 14:42:10 +00:00
.claude fix(alerts): bring External Alert Sources page up to the listing standard (#13625) 2026-08-04 13:31:30 +00:00
.devcontainer ci: update rust (#12394) 2026-06-02 03:58:01 +00:00
.github test: enhance logs visualization error handling and persistence tests (#13591) 2026-08-04 12:09:26 +00:00
.opencode/agents/e2e_ci_council_of_agents test: E2E Council Refiner — remediate Sentinel findings instead of dead-ending (#12876) 2026-06-25 09:20:31 +00:00
config fix: pagerduty integration bugs (#12975) 2026-07-01 16:01:43 +00:00
cross feat: re_patterns at ingestion (#7323) 2025-07-23 14:55:03 +05:30
deploy ci: update docker token (#13184) 2026-07-14 20:26:15 +08:00
qa-reports ci(test-assist): batch dispatcher + qa-reports backlog sweep (#12963) 2026-07-01 07:27:49 +00:00
screenshots docs: restructure README and refresh product screenshots (#13441) 2026-07-24 06:05:14 +00:00
scripts feat: per-group and per-series alerting, and SLO measurement (#13547) 2026-07-31 07:23:22 +00:00
src fix: accept org ingestion tokens for OTLP gRPC (#13627) 2026-08-04 15:07:10 +00:00
tests test(e2e/alpha1): robustness — auth self-heal + service-graph wide window (#13622) 2026-08-04 13:14:04 +00:00
web fix(alerts): bring External Alert Sources page up to the listing standard (#13625) 2026-08-04 13:31:30 +00:00
.claudeignore fix: llm evaluations (#10612) 2026-03-04 17:55:01 +05:30
.cursorignore fix: llm evaluations (#10612) 2026-03-04 17:55:01 +05:30
.env.example fix: payload limit (#10021) 2026-01-14 16:54:35 +08:00
.gitattributes refactor: design token migration + CI guards (#13173) 2026-07-20 18:06:21 +00:00
.gitignore feat: per-group and per-series alerting, and SLO measurement (#13547) 2026-07-31 07:23:22 +00:00
.typos.toml chore: fix frontend typos (#4612) 2024-09-25 11:09:26 +08:00
CONTRIBUTING.md docs: fix outdated requirements and typos in CONTRIBUTING.md (#10575) 2026-02-23 11:31:58 +08:00
Cargo.lock refactor: move streaming aggregates to OSS (#13589) 2026-08-03 08:44:55 +00:00
Cargo.toml refactor: move search and compaction optimizations to OSS (#13583) 2026-08-03 06:20:37 +00:00
Cross.toml feat: re_patterns at ingestion (#7323) 2025-07-23 14:55:03 +05:30
LICENSE change license 2023-11-26 11:04:37 -08:00
README.md docs: restructure README and refresh product screenshots (#13441) 2026-07-24 06:05:14 +00:00
SECURITY.md ignore yaml and md files for CI 2025-08-11 17:06:35 -07:00
build.rs feat: add tokio runtime metrics collection (#8371) 2025-09-11 13:34:29 +08:00
clippy.toml chore: upgrade rust to 2025-05-20 (#7316) 2025-07-01 21:25:45 +08:00
coverage.sh chore: new home page (#11458) 2026-04-25 19:18:21 +00:00
deny.toml refactor: split HTTP APIs by domain (#13479) 2026-07-27 12:12:59 +00:00
download.sh chore: Add download script (#3714) 2024-06-10 13:10:01 -07:00
downloadO2.sh fix: OTable resize and add/remove column feature (#12433) 2026-06-04 09:52:51 +00:00
opencode.jsonc chore: removing glm5.2 review (#13314) 2026-07-21 07:01:58 +00:00
openobserve.cdx.xml chore: regenerate Rust CycloneDX SBOMs (#13534) 2026-07-29 09:23:25 +00:00
package-lock.json feat: adding 1-click data onboarding capabilities (#10331) 2026-02-17 22:22:29 +05:30
rust-toolchain.toml ci: update rust (#12394) 2026-06-02 03:58:01 +00:00
rustfmt.toml ci: update rust to nightly-2025-03-02 (#6145) 2025-03-02 17:27:10 +08:00

README.md

OpenObserve

Open source Datadog alternative for logs, metrics, traces, and frontend monitoring. Modern observability platform: 10x easier, 140x lower storage cost, high performance, petabyte scale.

GitHub Release License GitHub Stars Contributors GitHub Issues Last Commit

Cloud · Documentation · Slack · Quickstart


OpenObserve (O2) is a cloud-native observability platform for logs, metrics, traces, analytics, Real User Monitoring (RUM), and AI/LLM observability. It's a cost-effective alternative to Datadog, Splunk, and Elasticsearch for teams that need full observability without the complexity or cost — with Parquet columnar storage and an S3-native design that cuts storage costs by up to 140x.

Table of Contents

Why OpenObserve?

A single platform for all of your observability signals. Here's why teams choose OpenObserve:

Benefit Description
140x lower storage cost Parquet columnar storage + S3-native architecture dramatically reduce costs vs Elasticsearch
Single binary deployment Up and running in under 2 minutes — no complex cluster setup required
OpenTelemetry native Built on the OpenTelemetry standard — no vendor lock-in
Unified platform Logs, metrics, traces, RUM, dashboards, alerts, and incidents in one tool
High performance Better query performance than Elasticsearch on a quarter of the hardware
SQL + PromQL Query logs and traces with SQL, metrics with SQL or PromQL — no proprietary query language
Built in Rust Memory-safe, high-performance, single binary

Cost comparison: OpenObserve vs Elasticsearch

OpenObserve vs Elasticsearch storage cost comparison

Quick Start

OpenObserve Cloud (fastest way)

Get started in minutes without managing infrastructure. The free tier includes up to 50 GB/day of ingestion.

Get Started Free →

🐳 Docker

docker run -d \
      --name openobserve \
      -v $PWD/data:/data \
      -p 5080:5080 \
      -e ZO_ROOT_USER_EMAIL="root@example.com" \
      -e ZO_ROOT_USER_PASSWORD="Complexpass#123" \
      public.ecr.aws/zinclabs/openobserve:latest

Then open http://localhost:5080 and log in with the credentials above.

For other installation methods, see the quickstart documentation. For clustered deployments, see the High Availability deployment guide.

Product Tour

OpenObserve ships with a powerful, unified web UI for every signal — logs, traces, metrics, dashboards, RUM, alerts, incidents, pipelines, and AI observability.

Watch the OpenObserve introduction video

🏠 Unified Overview

A single home for your workspace — active incidents, service health (error rate, latency, requests), anomalies, and recent events at a glance.

OpenObserve home overview

📊 Logs

Centralized log management with full-text search, SQL queries, quick filters, and a visual query builder. Instantly search across all your logs, build dashboards from log data, and set up alerts — all on Parquet columnar storage for 140x lower storage cost than Elasticsearch. Read more →

Logs search with histogram and field explorer

🔍 Distributed Tracing

Powered by OpenTelemetry, tracing helps you follow requests across services and pinpoint performance bottlenecks. Explore the full request flow with waterfalls, flame graphs, and Gantt charts; click any span to drill into the trace. Read more →

Distributed trace waterfall view

🕸️ Service Graph

Visualize service-to-service dependencies and request flow across your system, with per-edge request counts and health-based coloring (healthy, degraded, warning, critical) to spot problem hotspots at a glance.

Service dependency graph

📈 Metrics

Explore metrics from your infrastructure and applications, then query them with SQL or PromQL. Browse thousands of metrics with faceted filters, preview them inline, combine multiple queries with formulae, and visualize the results with 19+ chart types. Read more →

Metrics explorer browsing metric time series

📉 Dashboards

Build custom dashboards from any signal with 19+ built-in chart types and 200+ visualization variations, a drag-and-drop panel builder, template variables, and geo maps. Read more →

Kubernetes namespace dashboard with template variables

👀 Frontend Monitoring (RUM)

Real User Monitoring with Core Web Vitals, error tracking, performance analytics, and full session replay — so you can see exactly what your users experience. Read more →

Session replay with event timeline

🔔 Alerts

Get notified when something unusual happens on any signal — logs, metrics, or traces. Define thresholds, scheduled or real-time alerts, and notification channels, with alert history and anomaly detection to catch issues early. Read more →

Alerts list with scheduled, real-time, and anomaly alerts

🚨 Incidents

Correlate related alerts into incidents and track them through their lifecycle — open, acknowledged, and resolved — with severity and dimension context for faster response.

Incident management and tracking

🔀 Pipelines

Enrich, redact, reduce, or normalize data at ingest time with a visual editor. Build stream-processing flows — including logs-to-metrics conversion — from source, transform (VRL functions and conditions), and destination nodes. No external tools required. Read more →

Visual pipeline editor

🤖 AI Observability

Monitor your GenAI and LLM applications: track cost, tokens, latency percentiles, and error rates across models, with agent graphs, session traces, and evaluation/quality scoring.

AI/LLM observability insights

O2 AI Assistant

An in-product assistant that writes your SQL, VRL, and PromQL and walks you through logs, traces, metrics, and incidents — turning natural-language questions into queries, dashboards, and alerts.

O2 AI Assistant

For the full feature list, see the documentation.

Architecture

OpenObserve achieves 140x lower storage costs and high performance through a modern, cloud-native architecture:

  • Parquet columnar storage — efficient compression and fast analytical queries
  • S3-native design — inexpensive object storage with intelligent caching
  • Built in Rust — memory-safe, high-performance, single binary
  • Partitioning, indexing, and smart caching — reduces search space by up to 99% for most queries
  • Native multi-tenancy — organizations and streams as first-class concepts with complete data isolation
  • Stateless architecture — rapid scaling and low RPO/RTO for disaster recovery

Scale & Deployment

  • Thousands of concurrent users can query a single cluster simultaneously
  • Single binary scales to terabytes — unique in the observability space
  • High Availability mode scales to petabytes for the most demanding workloads
  • Multi-region deployments with cluster federation via Super Cluster architecture (Enterprise)
  • Federated search across regions and clusters (Enterprise)

High Availability & Disaster Recovery

Deploy in High Availability mode with clustering for mission-critical workloads requiring maximum uptime. OpenObserve's stateless architecture with S3-backed storage enables very low Recovery Point Objective (RPO) and Recovery Time Objective (RTO): stateless nodes restart rapidly, and durability is guaranteed by S3's 99.999999999% (11 nines).

Read the architecture documentation → · Read the enterprise deployment guide →

Comparisons

OpenObserve vs Datadog

Aspect OpenObserve Datadog
Deployment Self-hosted or Cloud SaaS only
Pricing model Per-GB (free up to 200 GB/day) Per-host + per-GB
Open source Yes (AGPL-3.0) No
OpenTelemetry Native OTLP Supported
Query language SQL + PromQL Proprietary
Vendor lock-in None High

OpenObserve vs Elasticsearch

Aspect OpenObserve Elasticsearch
Storage cost 140x lower High (hot/warm/cold tiers)
Setup complexity Single binary Complex cluster management
Query language SQL Lucene/KQL
Hardware requirements ~1/4 the resources High memory/CPU

OpenObserve vs Splunk

Aspect OpenObserve Splunk
Licensing Open source Expensive enterprise licensing
Deployment Single binary or HA cluster Complex
Query language SQL + PromQL SPL (proprietary)
Cost Predictable, low Unpredictable, high

OpenObserve vs Grafana/Loki/Prometheus Stack

Aspect OpenObserve Grafana Stack
Components Single platform Multiple tools (Grafana + Loki + Prometheus + Tempo)
Management One binary Multiple deployments
High cardinality Full support Loki struggles with high cardinality
Query performance Fast on large volumes Loki slow on large data

Production Ready

OpenObserve is battle-tested in production environments worldwide:

  • Thousands of active deployments across diverse industries
  • Largest deployment: 2+ PB/day ingestion
  • Single binary scales to terabytes — unique in the observability space

Read customer stories →

Security & Compliance

Security Features

  • Secure by design with hardened container images
  • Data encryption at rest and in transit
  • Sensitive Data Redaction (SDR) — automatically redact sensitive data at ingestion and query time (Enterprise)
  • Single Sign-On (SSO) — OIDC, OAuth, SAML, LDAP/AD integration (Enterprise)
  • Role-Based Access Control (RBAC) — granular permissions (Enterprise)Learn more →

Compliance Certifications

  • SOC 2 Type II certified
  • ISO 27001 certified
  • GDPR compliant
  • HIPAA ready (BAA available with Enterprise contracts)

OpenObserve meets the stringent security and compliance requirements of regulated industries including finance, healthcare, and government.

Enterprise Edition

OpenObserve is a true open source project. The open source edition is feature-complete and production-ready — logs, metrics, traces, dashboards, alerts, pipelines, and everything you need to run observability at scale. It will always remain actively maintained and free to use without restrictions.

For organizations that need enterprise-grade features and support, an Enterprise edition adds:

Enterprise features

  • Single Sign-On (SSO) — OIDC, OAuth, SAML 2.0, LDAP/AD, and major identity providers (Okta, Azure Entra, Google, GitHub, GitLab, Keycloak)
  • Advanced RBAC — granular role-based access control with custom roles — Learn more →
  • Audit trails — comprehensive immutable audit logs with configurable retention
  • Federated search — query across multiple clusters and regions with Super Cluster
  • Sensitive Data Redaction (SDR) — automatically redact PII at ingestion and query time
  • Advanced encryption — AES-256 SIV cipher keys with Google Tink KeySet and Akeyless integration
  • Query & workload management (QoS) — control query resource usage and priorities in multi-tenant environments

Support & SLAs

  • Dedicated support with contractual SLA guarantees and priority response times
  • Technical account management, architecture review, and deployment assistance
  • Migration support from existing tools, plus training and onboarding

Pricing

  • Free tier: up to 50 GB/day of ingestion (~1.5 TB/month), including full commercial use (registration required at 50 GB/day)
  • Volume discounts and multi-year contracts available
  • View the complete feature comparison →

For enterprise inquiries and custom deployments, contact our sales team.

Community & Support

The best way to get help, share ideas, and connect with other OpenObserve users is through our community channels.

🔗 Join us on Slack

Join OpenObserve on Slack

Our Slack community is the most active place for installation and configuration help, sharing best practices, discussing the roadmap, and connecting with the core team.

Join the conversation →

📱 Join the OpenObserve community on WeChat

OpenObserve WeChat QR code

Other ways to connect

Contributing

We welcome contributions from the community! Whether you're fixing bugs, adding features, improving documentation, or sharing feedback, your help makes OpenObserve better for everyone.

To get started, read our Contributing Guide, which covers setting up your development environment, code standards, submitting pull requests, and reporting issues.

FAQ

How does OpenObserve achieve 140x lower storage costs?

Through a combination of Parquet columnar storage (efficient compression) and an S3-native architecture (inexpensive object storage). See the cost comparison chart in the Why OpenObserve? section.

What are the limitations?

All data in OpenObserve is immutable — once ingested, it cannot be modified or deleted (only entire retention periods can be dropped). This is by design and is a feature for logs and compliance use cases, ensuring data integrity and audit trails.

Is this production-ready?

Yes. OpenObserve runs in production across thousands of deployments worldwide, including environments processing in excess of 2 PB/day. See our customer stories for real-world examples.

How does query performance compare to Elasticsearch?

OpenObserve delivers better performance than Elasticsearch for most workloads, with faster search and significantly faster analytics — while using about a quarter of the hardware. The columnar Parquet format is particularly effective for complex aggregations and analytics.

Is there a steep learning curve?

No. OpenObserve is designed to be intuitive from day one:

  • Familiar query languages — SQL for logs and traces, PromQL for metrics; no proprietary query language to learn
  • Easy-to-use GUI — an intuitive interface with a drag-and-drop dashboard builder
  • No complex tuning — unlike Elasticsearch, there are no shards, replicas, or heap sizes to manage. Just install and go.

Most users are productive within hours, not weeks.

License

Open Source Edition — licensed under AGPL-3.0. We chose AGPL to ensure that improvements to OpenObserve remain open source and benefit the entire community, while still allowing free commercial use. Why AGPL, and why it's good for the community →

Enterprise Edition — licensed under a commercial Enterprise License Agreement (not AGPL), which provides additional flexibility for enterprise deployments.

SBOM

Software Bill of Materials for OpenObserve. You can analyze either SBOM with Dependency-Track.

Rust

The SBOM is available here. To regenerate it:

cargo install cargo-cyclonedx
cargo-cyclonedx cyclonedx

JavaScript

The SBOM is available here. To regenerate it:

npm install --global @cyclonedx/cyclonedx-npm
cd web
cyclonedx-npm > sbom.json