Architecture

Two tiers. One history.

A deliberate architecture for complete, cost-efficient log retention.

OBSESC runs entirely in your AWS account. It sits alongside your existing observability stack, receives a copy of your logs, and stores every event — using a compact navigation tier for speed and a complete fidelity tier for depth. No data leaves your account. No agents to deploy. No existing tools to replace.

SAME LOGS
MORE TIME
DEEPER ANSWERS
...
THE MAP
Fast answers.
In your account.
THE TERRITORY
Every event.
Yours.
Deployment overview

One image. In your account.

A single deployment in your account. OBSESC integrates with your existing log shippers, stores data in your object storage, and works with your existing query engines.

Your log shippers
(fan-out existing pipeline)
Fluent Bit
Vector
OpenTelemetry
Filebeat
Splunk HEC
...
Send a copy of your logs (no changes to existing flow)
aws Your AWS account
Operator console |Explore |Query API
OBSESC node
OBSESC node
OBSESC node
+ n
Navigation tier (in your account)
Navigation tier (in your account)
Navigation tier (in your account)
Your object storage bucket (S3)|Fidelity tier
Every event, complete, in open columnar files under an open table format
Your existing tools
(query data directly)
OBSESC Explore
Amazon Athena
Trino
Spark
DuckDB
Any engine that reads open formats
...
Runs in your AWS account

No hosted control plane.
No access role for us.

Sized to you

One machine image,
sized to your volume.

Reversible

A fan-out in your shipper.
Nothing removed.

Open by design

Your data in open formats,
readable by your tools.

The two tiers

A map to navigate.
A territory you can always return to.

OBSESC separates speed from completeness. The navigation tier makes aggregate questions fast. The fidelity tier keeps every event, complete.

The map | Navigation tier
Fast and structured
  • A compact, navigable view of your history
  • Fast answers to aggregate questions across any range
  • Kept on storage in your account
  • Not the source of truth: your events are
The territory | Fidelity tier
Complete, open, yours
  • Every event, complete — nothing sampled, nothing dropped
  • Stored in your object storage (e.g. S3)
  • Open columnar files under an open table format (e.g. Iceberg)
  • Queried in place with full SQL when you need the events
  • Searched deliberately, with no surprise scan costs
  • Readable by your existing engines, now and in the future
Data flow

From ingest to insight.

A single flow, from your existing telemetry to long-term answers.

  1. 1
    Ingest

    A copy of your logs is sent from your existing shipper (OTel, Fluent Bit, Vector, etc.).

  2. 2
    Understand

    OBSESC builds a navigable map of your logs while keeping every original event.

  3. 3
    Store

    The map goes to the navigation tier. Every event goes to your object storage.

  4. 4
    Query

    Ask aggregate questions in seconds, or run SQL over every event when you need it.

  5. 5
    Retain

    Your data stays in your account, for as long as you need it.