v0.28.0 · 10 releases this weekrelease notes →

Free for your first app.

Self-hosted logging, with errors, alerts, and uptime built in. Your coding agent reads it too. No per-GB meter. $99 once for unlimited apps.

$ curl -fsSL lognorth.com/install | sudo bash -s logs.example.com

10.1k downloads · works with AI agents →

tail -f · rails-demo live
05:00:56.997POST/checkout201 · 850ms
05:00:57.138Loading user profile21ms
05:00:57.280Fetching cart items40ms
05:00:57.563Creating payment intent7ms
05:00:57.941GET/projects/42/todos200 · 38ms
05:00:58.012POST/checkout500 · 1204ms
05:00:58.013Stripe::CardError Your card was declined.payment_service.rb:67
05:00:58.230POST/checkout500 · 1188ms
05:00:58.231Stripe::CardError Your card was declined.72×
ALERTrails-demo — spike: /checkout at 18.2% → telegram

[01] the problem

Stop paying more to watch your app than to run it.

Hosted log platforms store and query billions of lines from thousands of customers at once. That scale is the hard part. It is also the part you don't have. You pay for it anyway.

diff hosted.conf self-hosted.conf
@@ where your logs live @@
thousands of tenants, billions of lines
metered by the gigabyte
alert rules you tune by hand
one more dashboard to check
one tenant: you
one SQLite file on a $5 box
alerts from each endpoint's own history
free for one app, $99 once for more

Why hosted logging costs what it does →

[02] what it does

Logs do all of it.

One stream of logs does every job: errors, alerts, and what your coding agent reads. Uptime is a ping every minute. No second system.

man lognorth
LOGNORTH(1)Self-hosted loggingLOGNORTH(1)

NAME

lognorth - one stream of logs that alerts, monitors, and debugs. Your coding agent reads it too.

THE LOGS

alert
Compares each endpoint with its own history: this hour against the same hour on earlier days. Fires when it's actually wrong.
monitor
An outage shows up as silence: the traffic that stopped.
debug
Logs and errors in one stream. 1 issue, not 1,000 duplicates.
connect
Each issue says how many users it hit, the release it came in, and which error failed first in the same requests. Every deploy is a dashed line on the charts.
replay
An error shows what its user did in the 30 minutes before it: the steps to reproduce.
ask
Claude Code or Cursor reads production over MCP and hands you the fix.
read
Plain lines. Errors in red. Context attached. No grep.
keep
No per-GB meter, so you log everything. You pick retention, up to forever.

THE PING

uptime
Pings your URL every minute. Alerts after 3 misses in a row, and again when it's back. 30 days of pings: when it failed, and why.
cause
The down alert names the errors that jumped as the app went down. An error that happens all day is not a cause, so it stays out.
status
A public page per product, on its own domain: the uptime since the first ping, 90 days of bars, the outages, and your notes on them.

COMMANDS

north tail
your production log, live, in the terminal
north top
endpoints, alerts, and uptime, like htop
ctrl+b, :
every screen in the app, from the keyboard. ? lists the keys
:theme amber
north, catppuccin, gruvbox, nord, dracula, or a 1983 amber terminal. Press t on this page

ALERTS GO TO

telegram
bot token + chat id
webhook
a JSON POST per alert: Grok Bot, Slack, your own endpoint
ntfy.sh
free push, no account
email
your own SMTP

SDKS

Another language? Follow the client protocol, or run /lognorth:integrate in your coding agent and it writes the client.

SEE ALSO

One thing that isn't a log: a ping to your URL every minute. Click a failed minute and you get its errors.

uptime · shop.example.com 99.93% · 24h
24h ago12hnow

up 84ms · last ping 12s ago

last failure 15:21 · 503 · 1,204ms

[03] autofix

Alert at 3am. Fixed by breakfast.

A LogNorth alert starts a Grok Bot routine through the webhook. The bot reads the failing requests over MCP, writes the fix with a test, and opens a pull request. LogNorth watches production until the alert clears. You wake up to a closed incident.

The loop: LogNorth alerts, a webhook wakes Grok Bot, it investigates, fixes, opens a pull request, ships, and LogNorth verifies the fix until the alert clears. your app shop-prod ■ in production [lognorth] 01 alert /checkout 8% vs 1% [lognorth] 02 webhook POST to the routine grok bot 03 investigate logs, trace, commits grok bot 04 fix branch + failing test grok bot 05 pull request #412 with the evidence grok bot 06 ship CI, merge, deploy [lognorth] 07 verify 0.9% since the deploy [lognorth] 08 closed alert clears, report sent
  1. 01 [lognorth] alert /checkout 8% vs 1%
  2. 02 [lognorth] webhook POST to the routine
  3. 03 grok bot investigate logs, trace, commits
  4. 04 grok bot fix branch + failing test
  5. 05 grok bot pull request #412 with the evidence
  6. 06 grok bot ship CI, merge, deploy
  7. 07 [lognorth] verify 0.9% since the deploy
  8. 08 [lognorth] closed alert clears, report sent
LogNorth watches and judges. Grok Bot does the work. Neither one needs you.

Set it up in three steps →The webhook docs →

[04] terminal

Production, in your terminal.

north tail follows the log. north top is htop for your app. Both run on your laptop and read your server with a read-only key. Open source, MIT.

north top

[lognorth] top · rails-demo · logs.yoursite.com■ up 84ms · 15:04:22

uptime 24h 99.93%

SPIKE /checkout 18.2% errors in the last 5 min, normally 0.9% · since 15:01

PATHREQSERRORSERR%AVG

> /checkout SPIKE 1,204 219 18.2% 850ms

/projects/:id/todos 3,210 4 0.1% 38ms

/sessions 827 1 0.1% 179ms

/dashboard 612 0 — 142ms

/webhooks/stripe 203 0 — 52ms

j/k move · enter errors · w window · q quitupdated 2s ago

install · macOS or Linux · no sudo
$ curl -fsSL lognorth.com/cli | sh   # then it asks for your URL and agent key
$ north tail --errors
$ north top

Everything tail and top do →Source on GitHub →

[05] alerting

Percentages lie.

Most tools alert on a flat threshold like 5%. Same number, two very different nights.

requests by hour · tue
hourrequestserrorsrateverdict
03:002015%noise
12:0010,0005005%fire

LogNorth compares each endpoint with its own past: the same hour on the last 7 days. It alerts when something is actually wrong.

[06] the math

Own it. The bill stops.

Free for one app, $99 once for more, plus a $5 box you own. Cancel a subscription and your logs are gone. You can't cancel what you own.

total cost · 5 years
lognorth
$399
hosted
$1,560
you keep$1,161

A small app at 12,000 requests a day. LogNorth: the $99 license, which the first app does not need, plus Hetzner's cheapest box at $5/mo. Hosted: a real entry plan at $26/mo with 90-day retention. That's the floor. Five years of request logs is about 7 GB.

[07] pricing

Free for one app. $99 once for all of them.

receipt
first app, every featurefree
unlimited apps$99
docker images1
databaseSQLite
serverany $5 VPS
data leaves your boxnever
updatesyour major version, forever
supportemail me
subscriptionnone
TOTAL · ONCE$99
Buy unlimited apps · $99

30-day money-back guarantee. No questions asked.

install · 3 minutes

# free for your first app. no license, no signup.

curl -fsSL lognorth.com/install | sudo bash -s logs.example.com

# docker, TLS, live backups, nightly updates. done.

# amd64 or arm64: a $5 VPS, a Raspberry Pi,

# or any box you already rent.

# update now instead of waiting: run it again.

[08] faq

Questions.

What is LogNorth?
Self-hosted logging, error tracking, alerts, and uptime checks in one tool. One Go binary in one Docker container, with one SQLite file for storage. It runs on a $5 VPS or a 64-bit Raspberry Pi (amd64 or arm64). SDKs for TypeScript/Node/Bun, Go, and Rails, plus OpenTelemetry logs and a plain HTTP API. A read-only MCP server lets Claude Code, Cursor, Codex, and Gemini CLI read production. Built and supported by one developer, Carlos Castellanos.
Who is it for, and who is it not for?
For solo developers and small teams who run web apps on their own server and don't want separate, metered tools for logs, errors, and uptime. Not for teams that need APM, distributed tracing, session replay, profiling, or compliance features. LogNorth doesn't accept Sentry SDKs: use its SDKs, OpenTelemetry logs, or the HTTP protocol.
What are the limits?
It is sized for one tenant: you. An event takes about 0.3 KB on average, so 100,000 events a day for a year is about 11 GB. A small app at 12,000 requests a day writes about 7 GB in five years. OpenTelemetry traces and metrics are accepted and dropped; LogNorth keeps logs.
What does it cost over five years, next to Sentry or Better Stack?
Prices checked October 2026. Sentry Team is $26/month (annual, 50K errors): $1,560 over five years. Better Stack's first paid telemetry bundle is $30/month in Europe: $1,800. LogNorth on a $5/month server: $300 for one app, or $399 with the license for unlimited apps. Both have free tiers (Sentry for one user, Better Stack with 3 days of logs), and both do more, like replays and tracing. If you only need logs, errors, and uptime, you pay for the rest anyway.
What is free, and what does $99 add?
Your first app is free, with every feature: logs, errors, alerts, uptime checks, AI debugging, all SDKs. The $99 license adds unlimited apps. You pay once. No subscription. 30-day money-back guarantee.
Can I try it before I buy?
You don't need to. Install it and your first app is free, for as long as you run it. Add a license when you add a second app, for example staging. You can also click around the live demo. If it is not for you, you get your money back within 30 days.
Does it monitor uptime?
Yes. Paste your app URL when you create the app and LogNorth pings it every minute. 3 failures in a row = down, and you get an alert. When it answers again, you get another with how long it was down. LogNorth keeps 30 days of pings, so you can see when it failed and why: an HTTP 503 or a timeout. Each product can have a public status page on its own domain, like status.yourapp.com: the uptime since the first ping, a bar for each of the last 90 days, the outages, and your notes on them. How uptime works.
Can my AI agent read the logs?
Yes. LogNorth has a read-only MCP server built in. Claude Code, Cursor, Codex, and other agents ask it what is alerting, which requests failed, and what the trace says, then find the line of code and the commit behind it. Every alert email ends with /lognorth:investigate, ready to paste. Your logs stay on your server: only the answer reaches your AI provider. How agents use LogNorth.
Why not use Sentry?
Sentry is a platform. LogNorth is a single Docker container. One file database. No dependencies. Runs on a $5 VPS. That's the trade-off: fewer features, far less to run.
What frameworks are supported?
Go, Node/Bun, and Rails. Also accepts OpenTelemetry logs (OTLP/HTTP). LogNorth keeps the logs and discards traces and metrics. Any other language: follow the client protocol, or run /lognorth:integrate in your coding agent and it writes the client for you.
How does alerting work?
LogNorth groups errors into issues, compares each endpoint with its own history, and only alerts when something needs attention. 1 error in 1,000 requests? Normal. Sudden spike? That's a real problem. Push notifications via Telegram, a webhook, ntfy.sh, or email with your own SMTP.
Does it tell me which deploy or outage an error belongs to?
Only when the data says so. Each error carries the release it ran in and the user who hit it, so an issue shows the release it first appeared in, how many users it hit, and what the last user did in the 30 minutes before. When another error fails first in the same requests most of the time, the issue names it: fix that one first. Every deploy is a dashed line on the charts. When your app goes down, LogNorth lists the errors that jumped to at least 5 times their usual rate in those minutes. An error that happens all day is not a cause, so LogNorth leaves it out.
How long are logs stored?
You decide. Default is 90 days. Configure from 7 days to 1 year, or keep them forever. Shorter retention = smaller database.
Do I get updates?
Yes. Updates for your major version, forever. LogNorth updates itself each night, after a backup of its database. To update right now, run the install line again.

[08] who

~ $ finger karloscodes

Carlos Castellanos
Login: karloscodesName: Carlos CastellanosProject: LogNorth

Plan:

Your logs hold your stack traces, file paths, and user IDs. They shouldn't sit on a vendor's server, billed by the gigabyte.

LogNorth runs on a box you own. You pay once. If something breaks, you email me.

karloscodes.com · @karloscodes