Skip to content

Introduction

Hyperwatch is a flexible access log processor that helps operators analyze HTTP traffic reaching their infrastructure.

It’s built on a real-time stream processor that handles logs from inputs of any type:

  • CDNs: Cloudfront, Cloudflare, Akamai…
  • Load balancers: ELB
  • Reverse proxies: Nginx, HAProxy…
  • Web servers: Nginx, Apache…
  • Applications: Node, Ruby, PHP…

Stream pipeline

Every log flows through a pipeline you shape with plain JavaScript: map, filter and branch streams in real time.

Enrichment

Modules add geolocation, verified hostnames, identities, User-Agent parsing, DNSBL checks and signatures.

APIs & live streams

Query aggregations as JSON, CSV or HTML, and tail any pipeline node over HTTP or WebSocket.

Firewall

Tag listed IPs and User-Agents and keep the lists in sync with Cloudflare WAF custom rules.