Docs: Quick start
Documentation / Get started

Quick start

Deploy OBSESC from AWS Marketplace, send a test event, and see it arrive, in the fewest steps.

This page takes you from an AWS Marketplace subscription to a stored, visible event. It uses the stack defaults wherever possible. When you’re ready to harden the deployment, follow Deployment (AWS Marketplace).

Before you begin

You need:

  • An AWS account and permission to create CloudFormation stacks, IAM roles, EC2 instances, EBS volumes and security groups.
  • A VPC and a subnet in it. The instance needs outbound access to Amazon S3 and the other AWS APIs it calls, through a NAT gateway or VPC endpoints.
  • A customer-managed KMS key. OBSESC uses it to encrypt the EBS volumes and every object it writes to S3.
  • An S3 bucket for raw events. You can use an existing bucket, or let the stack create one.
  • A machine inside the VPC (or connected to it) from which you can run curl and open a browser.

1. Subscribe and launch the stack

  1. Subscribe to OBSESC on AWS Marketplace.
  2. Launch the OBSESC CloudFormation template.
  3. Fill in the five required parameters:
ParameterWhat to enter
AmiIdThe OBSESC AMI for your Region
RawBucketNameYour bucket’s name, for example my-obsesc-bucket
VpcIdThe VPC to deploy into
SubnetIdA subnet in that VPC
KmsKeyArnYour key, for example arn:aws:kms:us-east-1:111122223333:key/...
  1. Check AllowedIngestCidr. It defaults to 10.0.0.0/8 and controls who can reach the ingest ports, the console and the query API. Narrow it to the ranges your shippers and operators use.
  2. If you don’t have a bucket yet, set CreateRawBucket to true. The stack then creates RawBucketName for you.
  3. Create the stack.

The stack doesn’t report CREATE_COMPLETE until the node is ready to accept data. If the node doesn’t become ready, the stack fails. It doesn’t report success with a broken node.

2. Read the stack outputs

When the stack completes, open its Outputs tab. For this quick start you need:

OutputValue
IngestEndpointEshttp://<private-ip>:9200/_bulk
IngestEndpointOtlphttp://<private-ip>:4318/v1/logs
UiUrlThe console: http://<private-ip>:18080/ on a default deployment

The rest of this page uses obsesc.your-domain.internal for the node’s address. Replace it with the private IP from your outputs, or with a DNS name you’ve pointed at it.

3. Send a test event

The Elasticsearch _bulk endpoint accepts plain NDJSON, so it’s the easiest to test with curl. From a host that AllowedIngestCidr covers:

curl -sS -X POST "http://obsesc.your-domain.internal:9200/_bulk" \
  -H "Content-Type: application/x-ndjson" \
  --data-binary @- <<'EOF'
{"index":{}}
{"@timestamp":"2026-09-24T10:00:00Z","service":"quickstart","message":"hello from the OBSESC quick start","level":"info"}
EOF

A successful request returns HTTP 200 with an Elasticsearch-style JSON body. Each accepted document reports status 201. OBSESC takes the service name from service, the log line from message, and the timestamp from @timestamp. Every other field is kept as an attribute.

If you haven’t configured ingest tokens, the listeners accept requests without authentication. To require tokens, see Deployment (AWS Marketplace).

4. Watch it arrive

In a second terminal, open a live tail of the quickstart service, then send the event again:

curl -N "http://obsesc.your-domain.internal:18080/v1/tail?service=quickstart&max_events=5"

The event appears in the stream as the node accepts it. The tail confirms delivery, not storage. To confirm storage, query the raw events as described in Your first logs.

5. Open the console

Browse to the UiUrl output (http://obsesc.your-domain.internal:18080/ on a default deployment) from inside the VPC.

If you’ve set AuthSecretArn but haven’t set up sign-in through your identity provider, the console loads but can’t show data. Set up sign-in as described in Deployment (AWS Marketplace).

6. Point a real shipper at OBSESC

Add OBSESC as a second output next to your existing destination. For example, with the OpenTelemetry Collector:

exporters:
  otlphttp/obsesc:
    endpoint: http://obsesc.your-domain.internal:4318

service:
  pipelines:
    logs:
      receivers: [otlp]
      # keep your existing exporter in this list alongside OBSESC
      exporters: [otlphttp/obsesc]

Your first logs has ready-to-use configurations for Filebeat and Fluent Bit, and explains how to confirm the data is stored.

What to do next

Before you rely on this deployment, work through these items:

  • Alert delivery. OBSESC ships alert rules that deliver to your Alertmanager. Until you set AlertmanagerEndpoint, they aren’t delivered anywhere. The AlertDelivery stack output tells you which state you’re in.
  • Authentication, TLS and sign-in. Set AuthSecretArn, the TLS parameters and console sign-in. See Deployment (AWS Marketplace).
  • Retention. OBSESC keeps everything until you configure a retention window. See What happens next.