◉
24observe
Product
AI NOC + SOC Analyst
Root-cause on every incident
SIEM & detections
87 detections, investigated
AI-agent observability
Cost · latency · behaviour
AI-agent security
Injection · tool abuse
Uptime monitoring
HTTP · TCP · TLS · cron
Log management
Ingest · search · live-tail
Metrics & alerting
Thresholds that open cases
Tracing
OpenTelemetry-native spans
Network monitoring
SNMP · Cisco · Palo · Forti
Context graph
Topology · blast-radius
On-call & incidents
Rotations · escalation
Alerting
Ten channels · no flood
Status pages
Auto-updated · subscribers
The Linux Sensor
One-line host telemetry
Integrations
OpenTelemetry · webhook map
API for agents
Pure-REST · tool defs · MCP
For NOC teams
Network + ops, one platform
Solutions
For SRE & DevOps
Cut MTTR, kill toil
For SOC & security
Detections that investigate
For NOC teams
Network + ops, one platform
For AI & platform teams
Observe & secure agents
For MSPs
Many customers, one platform
For startups
One platform, an AI on call
Self-host / air-gapped
The full platform, in your perimeter
Compare
All comparisons
vs Datadog
vs Splunk
vs Grafana
vs PagerDuty
vs Elastic
Migrate from Datadog
Migrate from Splunk
Migrate from Pingdom
Docs
Get started
Quickstart (10 min)
Concepts & glossary
User guide
Admin guide
Detection authoring
Test guide
Metric & SNMP alerting
Network onboarding
Response playbooks
Build an agent (cookbook)
MCP server setup
Connect an agent
The collector
Logs
API reference
API for agents
Webhooks
Context graph
Browse all docs
→
Pricing
Resources
Changelog
Roadmap
About
Contact
Status ↗
GitHub ↗
checking…
Sign in
Start free
→
Documentation
Pick your starting point.
Hosted in 60 seconds, or self-host on your own infra. Either way, the API surface is the same.
Getting started
Hosted quickstart
→
Sign up, get a personal access token, create a monitor.
Self-host quickstart
→
Run the full stack on your own host.
OpenAPI spec
→
Machine-readable spec — generate a typed client in any language.
Testing & validation
Test guide
→
Use AI to generate synthetic telemetry, send it, and verify detections, incidents, alerts, and the AI analyst — with exact commands and expected outcomes.
API for agents and scripts
The agent API, in 6 features
→
Rate-limit headers, signed event webhooks, scoped tokens, idempotency, error codes, tool-format URLs.
API reference
→
PAT auth, base URL, 24 scopes, error codes, rate limits, curl + TS + Python examples.
Operational context graph
→
Resolve entities, walk evidence-ranked neighborhoods, get an incident blast-radius. Read API + MCP tools, behind context:read.
Interactive OpenAPI
→
Every endpoint with schemas + try-it-now, rendered live from the spec the API publishes.
Heartbeats / cron jobs
→
Receive URL spec, two-step token retrieval, end-to-end agent example.
Event webhook subscriptions
→
Subscribe to incident.opened / acknowledged / resolved / monitor.status_changed / log_alert.fired. Signed delivery, retry, auto-disable, full delivery log.
Verify webhook signatures
→
HMAC-SHA256 signature recipe with Node, Python, and Go examples. Same scheme for per-monitor alerts AND event subscriptions.
Logs
Send your first event
→
Pick a source. Ship in five minutes. JSON, NDJSON, OpenTelemetry, anything that speaks syslog.
Search & live tail
→
Type the words you remember. Live-tail at sub-100ms. KQL-lite when you need filters.
Auto-extracted facets
→
Every primitive JSON field becomes a click-to-filter chip. No schema to declare.
Pattern grouping
→
Collapse 10,000 similar lines into one template. Numbers, UUIDs, IPs, timestamps all normalize.
Error tracking
→
Stack-trace fingerprinting. JS, Python, Java, Go, generic ERROR/FATAL. See each bug once.
Sentry SDK & Web Vitals
→
Point your @sentry/* DSN at us; beacon Core Web Vitals from web-vitals. No new SDKs, no per-seat bill.
Log-derived metrics
→
Save any search as a time-series. Chartable, alertable, free.
Anomaly alerts
→
Spike-vs-baseline when "normal" varies by service. No ML to tune.
Threshold alerts
→
Page on-call when N matches in W seconds. Same routing as your monitors.
Log sources
AWS CloudWatch / Lambda
→
Subscription filter → Firehose → us. Lambda, ECS, EKS, RDS, anything CloudWatch-logged.
Heroku
→
One `heroku drains:add` and every dyno log line flows. No buildpack, no SDK.
Vercel
→
Paste the drain URL. Lambda, edge, static, build logs — all of them.
Docker daemon
→
Switch the log-driver to syslog. Daemon-wide or per-container. No agent.
systemd-journald
→
Mount /var/log/journal into our collector. Every unit, with severity preserved.
24observe collector
→
One Docker container for syslog, fluentforward, OTLP. The "everything else" path.
Concepts
Check types
→
The check primitives and when to use each.
Browser (synthetic) monitors
→
Headless Chromium renders the page, runs its JS, and asserts on the real DOM. For SPAs and JS-gated content.
Heartbeats / cron jobs
→
Inverted check: your job pings us; we alert when the pings stop.
Enterprise SSO (OIDC)
→
Sign in through Okta, Azure AD, Google Workspace, Auth0, or OneLogin. One connection per org, owner-configured.
Status pages
→
Public, slugged, optional custom domain, custom CSS, IP allowlist, white-label.
Trust commitments
→
What we promise about your data.
Incident response runbook
→
What to check, in what order, when something is wrong.
Integrations
Slack / Discord / Telegram / Teams
→
Paste an incoming webhook URL — done.