Skip to content

Platform Overview

What Auditty does to your logs, where it runs, and what reaches Auditty

Auditty cuts log noise at the source. It runs inside your cluster, reads every log line as it is written, forwards the ones that carry information and folds the repeats into one searchable summary each, before anything reaches your observability platform. Your logging agents, your pods and your dashboards stay exactly as they are; the bill does not.

Key Benefits

  • No changes required to pods, logs, existing logging agents or cluster
  • Seamless installation and uninstallation via Helm
  • Typical 80-95% cost reduction on observability platforms (workload- and pricing-dependent)
  • Every original one click away: correlation keys are indexed inline in every summary, and the suppressed lines behind it open from the Vault with one click
  • Measure before you commit: shadow mode runs every rule over live traffic and reports what it would save, while every line still reaches your platform

Start in shadow mode

A new install can run in shadow mode first: Edge reads each container’s output without intercepting it, changes nothing, and counts what its rules would have suppressed. The dashboard shows the projected savings with nothing is suppressed while measuring beside each figure, and the Fleet Rules page shows what each rule would take. When the numbers look right, an admin presses Go live and every node switches within seconds, with no restart. Set shadow_mode: true in the Edge config, or press Measure first on the Fleet Rules page after installing; the Configuration guide has the details.

How It Works

Auditty Edge deploys two components in your cluster (plus an hourly archive-maintenance job when the Vault is enabled):

  • Edge DaemonSet (auditty-edge): Runs on each node to intercept and process container logs. Runs as root with two scoped Linux capabilities, not in privileged mode
  • Edge API (auditty-edge-api): Non-privileged cluster-level service with RBAC permissions to query the K8s API

Data Flow

  1. Containers write to stdout/stderr (no changes needed)
  2. Edge intercepts the standard output of the containers your rules select, on the node
  3. Edge processes the stream (suppress repeats, summarise them, add insights)
  4. The reduced stream reaches the node’s logs: what kubectl logs and your logging agents read, as they always did
  5. Edge API collects metrics from all nodes and sends them to Auditty

Edge API is the one component that talks to Auditty, so your cluster makes one outbound connection, and your cloud-storage credentials stay in the cluster with it. Its settings are in the Configuration guide.

Privacy Guarantees

  • Your logs stay in your cluster. Edge processes them on the node they were written on, and suppressed originals go only to the Vault, cloud storage in your own account
  • A backfill link is the one exception, and you open it. When you do, the lines behind that one summary are read from your Vault from inside your cluster and shown in Auditty, which holds them for up to four hours to serve the page and then discards them
  • The lines kept and the suppression summaries are what reaches the node’s logs, where your logging agents already read
  • What reaches Auditty on its own is usage metrics, log fingerprints, the shape of an anomalous pattern (its constant words and field names, with every value masked), and Edge’s own warnings, which describe an effect on your logs in plain words