🌿 logscan v1.2.0 · MIT

Point regex rules at your logs, get a triaged report and a strict exit code your cron can act on — no output parsing required.

The problem

Log files grow quietly and nobody reads them until something is already on fire. grep finds strings but gives no triage, no grouping, no exit codes. This tool watches any text log against a rule set, groups matches by rule with severity (CRIT / WARN / INFO), and turns the result into 0 / 1 / 2 exit codes a cron or CI job can react to.

What it does

Install (pip)

pip install logscan @ git+https://mandrilly.com/git/logscan.git

Usage

logscan /var/log/app.log                     # text report
logscan --since-hours 24 --md app.log        # markdown report, 24h window
logscan --rules myrules.json --json a.log b.log
logscan --tail 500 /var/log/app.log          # only last 500 lines per file
logscan --list-rules                         # show the active rule set

Sample output:

== logscan report ==
files: /tmp/demo.log
total matches: 2 (CRIT=1, WARN=1, INFO=0)
[WARN] conn-refused: 1 match(es)
    | 2026-09-18 11:00:00 connection refused to api
[CRIT] fatal: 1 match(es)
    | 2026-09-18 11:05:00 fatal: disk corrupt

Exit codes

CodeMeaning
0clean — no matches
1warnings found (no critical)
2critical matches found
3input error (missing file, bad rules)

Cron pattern

logscan --quiet --since-hours 24 /var/log/app.log \
  || echo "logscan exit $?" | mail -s "logscan anomalies" ops@example.com

Tests

python -m unittest test_logscan -v   # 16 tests → OK

Source

git clone https://mandrilly.com/git/logscan.git