Lightweight distributed observability and alerting system designed for edge and constrained environments (e.g. Raspberry Pi clusters, home labs, or remote infrastructure nodes).
It provides centralized log aggregation, event filtering, and real-time security alerting through a Telegram-based notification pipeline.
This project explores how observability concepts used in production systems can be adapted to resource-constrained environments.
Modern systems require visibility into distributed nodes, but full-scale observability stacks (ELK, Datadog, Grafana stacks) are often too heavy for:
- Edge devices (Raspberry Pi, IoT nodes)
- Home lab environments
- Lightweight private infrastructure
- Educational or experimental setups
This project explores how to build a minimal but effective observability pipeline using standard Linux tooling.
Client Nodes (Raspberry Pi / Linux Hosts)
│
▼
rsyslog ingestion layer
│
▼
/var/log/remote/<hostname>.log
│
▼
Event filtering layer (security rules)
│
▼
Telegram alerting daemon (systemd service)
│
▼
Real-time notifications
- Centralized log aggregation using rsyslog
- Multi-host log separation by hostname
- SSH brute-force detection (Failed password events)
- Lightweight event filtering pipeline
- Real-time alerting via Telegram Bot API
- systemd-managed daemon for reliability
- Designed for low-resource edge devices
- Fully reproducible configuration via Python bootstrapper
git clone https://github.com/mainformatico/edge-observability-pipeline.git
cd edge-observability-pipelinecp config.example.yml config.ymlEdit:
telegram:
token: "YOUR_BOT_TOKEN"
chat_id: "YOUR_CHAT_ID"
rsyslog:
remote_port: 514
alerts:
ssh_failed: true
log_file: "/var/log/telegram-alerts.log"sudo python3 main.py --config config.ymlFrom any client node:
logger "TEST ALERT: system verification"🚨 ALERT: Failed password for invalid user admin from 192.168.1.50
Chosen for its simplicity, low overhead, and native Linux integration. It avoids introducing heavy dependencies.
Provides a zero-infrastructure alerting channel without requiring additional messaging infrastructure.
A deliberate design choice to maintain transparency and debuggability of the system.
- No deduplication or rate limiting of alerts
- No structured log schema (JSON not enforced)
- No persistent queue or backpressure handling
- Not suitable for high-throughput production environments
- Add structured logging (JSON + schema validation)
- Introduce alert aggregation (anti-spam / batching)
- Replace file pipeline with event queue (Redis / NATS)
- Add FastAPI control plane for remote configuration
- Export metrics to Prometheus / Grafana
- Multi-node orchestration layer
This project explores:
- Event-driven system design on constrained hardware
- Trade-offs between simplicity and scalability
- Building observability without heavy external stacks
- Linux-native infrastructure tooling (systemd, rsyslog)
- Distributed log pipeline design principles
- Python 3
- rsyslog
- systemd
- Telegram Bot API
- Linux (Raspberry Pi OS / Debian-based systems)
This project is intended for educational and infrastructure experimentation purposes in controlled environments.
It demonstrates practical understanding of:
- Distributed systems fundamentals
- Observability pipelines
- Event-driven architecture
- Linux systems engineering
- Lightweight infrastructure design