Phase 01 · Foundation
Foundation
A complete engagementOne vendor-agnostic collection layer, built on OpenTelemetry and collectors nobody licenses, replaces the pile of per-tool agents and puts you in control of where your data goes and what each destination gets.
01The collection layer
Collected once, on an open standard
Every host runs one collector and it is the open one, reading host metrics, event logs, syslog, application logs, Kubernetes, and the metrics endpoints your services already expose, with nothing changed in any application.
The OpenTelemetry Collector replaces the two or three per-vendor agents most hosts carry today, and it carries no per-host or per-agent licence. Traces are the one thing it cannot see from outside a process, and for most runtimes that is a flag or a wrapper on the service rather than a development project.
A collector is not the hard part. Running five thousand of them is. Each collector runs under a small supervisor that dials out to a control plane in your account over the Open Agent Management Protocol, the OpenTelemetry standard for managing fleets of collectors. The host opens the connection, so no credential to your network sits anywhere else.
02The control layer
One layer decides what each destination gets
The control layer sits between every source you have and every destination you pay for, and in most environments it cuts ingest to the expensive destinations 40-70% with zero detection loss.
Collect once, route anywhere. Events are parsed, trimmed, and enriched with context in flight, so only real signal moves forward and every downstream consumer benefits from the same cleanup. Your detections keep firing and your dashboards keep working, on a fraction of the data.
It is also pipeline insurance. Your destinations will change. SIEMs get replaced, monitoring vendors get dropped, new tools arrive, and each of those used to mean re-collecting everything. With the control layer in place, a vendor change becomes a routing change, not an 18-month rebuild.
03The Lake
The asset that compounds
The byproduct of the control layer is a Lake in your own storage, under your keys, holding clean, normalized, enriched telemetry partitioned so search stays fast and cheap across years of history.
Not an export the vendor allows. Yours. The data in it carries context that never existed before: which team owns the subnet, whether the IP is internal or external, which service the host belongs to.
Every future consumer reads from this Lake. The next SIEM, an in-house platform, an AI agent, all of them start with clean history on day one instead of an empty index. Nothing in your telemetry estate is hostage to a vendor again.
04The archive
Full fidelity, mask at the source
Everything, not just what the SIEM keeps, lands in a compliance archive at full fidelity, with sensitive fields masked at the source so PII that never lands can never leak.
The archive is replayable at any time. An investigation needs six months of firewall history, an auditor asks for evidence, a regulator wants the original records, a new tool needs its history backfilled. Each of those is a query and a replay, not a forensic project.
It is built to support the obligations your organization already carries, including HIPAA, PCI, and the log-producibility requirements supervised institutions answer to. Your compliance program stays yours. We give it evidence on demand.
05The fleet console
The pane of glass, in your repository
The fleet console is the same pane every platform vendor rents you for their agent, built for you instead: every host, its health, what it is running, and the rollout in progress, running in your account.
Everyone else rents you the pane of glass over their agent, and what you see in it is what they chose to show. This one is in your repository and your account, over an agent nobody owns, and it holds no state of its own to lose. That is what vendor agnostic means in practice: not a promise about the future, but a fleet you could hand to the next engineer, or the next vendor, tomorrow.
06Why first
Why the foundation has to come first
You cannot choose where telemetry lands, how much of it, or how clean, without owning the layer that collects it and the pipeline that shapes it.
Open collection makes you vendor agnostic at the source, and the pipeline sends each platform only what it needs, the rest wherever you decide, including a platform you build yourself or with us. Every platform you run is being rebuilt around AI, and the agents you buy next are only as good as the data they reach: clean, cheap to keep, and yours.
A valid place to stop
After Phase 01 you own the collectors, the pipelines, every routing decision, and the Lake. Everything after it is a continuation, not an obligation.
07Questions
Asked about the foundation
Does the collector require changing our applications?
No. The OpenTelemetry Collector reads host metrics, the Windows event log, syslog, any log file any application writes, Kubernetes, and anything exposing a metrics endpoint, with nothing changed in any application. Traces are the one exception, and for most runtimes that is a flag or a wrapper, not a development project.
Who owns the Lake?
You do, in the most literal sense: your S3 or Azure Blob, under your keys. Not an export the vendor allows. The data in it is clean, normalized, enriched, and partitioned so search stays fast and cheap across years of history. Every future consumer starts with clean history instead of an empty index.
Is Phase 01 really a valid place to stop?
Yes, and we badge it that way on purpose. After Phase 01 you own collection, routing, the Lake, and the fleet console, your expensive destinations receive only what earns its place, and every later phase is a continuation you can take or leave. Many estates stop here and are right to.
What does the fleet console cost to license?
There is no per-node or per-agent licence anywhere in the collection layer. The collectors are open source, the supervisor and control plane speak OpAMP, the open standard for managing collector fleets, and the console is built for you, running in your account, reading your repository.
Start with the review
You share your diagrams, we review them with you, and you leave with your version of the Logmetry Blueprint drawn on your stack. No system access, no obligation.