Skip to main content

ChainLog

ChainLog answers one question: why did my infrastructure fail?

It reads the logs an operator already has — execution clients, consensus clients, validators, and Kubernetes — and returns a cause that cites those lines. The case stays on the machine. A model is optional, and it only sees redacted excerpts.

ChainLog does not restart a client, edit a manifest, scrape a cluster, or sign with a validator key.

Work is tracked in milestones. This tree is the 0.1.0 shell: chainlog --version is the command that exists today.

Command

Question Command
Read logs into a local case ingest
Which failure classes are present? classify
What happened, in order? timeline
Why did it fail? why
Has this happened before? patterns
What should I check next? ask
Write the report report

why can take a case id, or the same files as ingest. It classifies, builds the timeline, and states a cause.

chainlog ingest \
  --execution /var/log/geth/geth.log \
  --consensus /var/log/lighthouse/beacon.log \
  --validator /var/log/lighthouse/validator.log \
  --builder /var/log/mev-boost.log \
  --kube /tmp/events.json

chainlog why --case 20261008T061200Z
chainlog ask --case 20261008T061200Z "what happened in the slot before the miss?"
chainlog report --case 20261008T061200Z

Exit 0 means a cause is stated and every claim cites a timeline row. Exit 1 means the evidence is not enough. Exit 3 is a usage error or an unreadable input.

What a cause is allowed to say

A cause cites timeline rows: time, source, and the redacted line. The report separates three things:

  • Trigger — the earliest cited class that explains what followed.
  • Contributors — cited conditions that made it worse, such as disk pressure before a database error.
  • Symptoms — later misses, restarts, or probe failures that the trigger explains.

A symptom is never printed as the trigger. A class is applied only when a catalog rule matches, and every rule has a source. An unmatched line stays unclassified. When the lines do not support a cause, why says so and names what is missing.

A doppelganger detection or a slashable duty is printed first, even when an earlier warning exists in the window.

Sources

Source Clients and objects What it explains
Execution Geth, Nethermind, Erigon, Besu, Reth Sync, database, engine API, peers, disk, JWT
Consensus Lighthouse, Prysm, Teku, Nimbus, Lodestar Slots, fork choice, checkpoints, engine calls
Validator Validator clients, Web3Signer Missed duties, doppelganger, signer timeouts
Builder MEV-boost Relay and builder timeouts on a proposal
Kubernetes Container logs, cluster events OOM, eviction, probes, volume mounts, node pressure

Slot, epoch, and block are taken from the line that prints them. A slot filled in from a nearby consensus line is marked inferred. When two consensus lines disagree, the slot stays blank.

Around the failure

An alert can open the case. A ValidatorPulse or Prometheus alert sets the window: one hour before it fired, and fifteen minutes after. A metric snapshot for that window can support a contributor: disk, memory, restarts, peer count, head lag, attestation effectiveness.

ChainLog reads the snapshot the operator exports. ValidatorPulse remains the monitor that raises the alert. ChainDiff remains the tool that decides whether a client upgrade is safe. ChainLog records the version change and stops there.

A pattern exported for another host contains class ids, client, version, and the order of classes. It contains no log lines and no host names.

Where a case lives

Cases are written under ~/.chainlog, or CHAINLOG_HOME when that is set. The case stores redacted excerpts and citations. The raw files stay at the paths the operator passed.

Redaction removes private keys, mnemonics, keystore passwords, JWT secrets, and API tokens before the case is written and before any model sees text. Validator pubkeys and peer ids stay, because the timeline joins on them. A removed span is marked.

ask answers from the case. With no model configured, it answers from the cause and the sourced runbook. --remote is off unless that invocation sets it, and the command prints that a remote call is about to happen. If redaction did not run, the remote call is refused.

Report

report writes markdown and JSON: cause, trigger, contributors, symptoms, the last healthy slot, the first bad slot, citations, and the pattern note. --no-paths drops local file paths. --bundle writes the redacted citations, the signature, and a hash. --verify checks that hash later.

Install

pip install chainlog-ai

The package is published from a GitHub release. Python 3.11 or newer. The command is chainlog.

chainlog --version

Limits

ChainLog explains a failure from evidence the operator provides. It does not fetch logs from a cluster API, apply a fix, or decide that a release is safe to run.

Metadata

Release files for chainlog-ai 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for chainlog-ai 0.1.0
File Size Uploaded
chainlog_ai-0.1.0.tar.gz 5.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for chainlog-ai 0.1.0
File Interpreter ABI Platform
chainlog_ai-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 11.2 kB

Release files / chainlog_ai-0.1.0.tar.gz

Download URL chainlog_ai-0.1.0.tar.gz
Size 5.5 kB
Tags Source
SHA-256 checksum
How to use checksums
90c2dcd6cbaf806ee06b6df5c0dd56b4b518c660baa7de4c422ad5ac285b6059
BLAKE2b-256 checksum
How to use checksums
0e97781e8dc22e02da88c0ecd682701a4278ccee46bd858e8a7b286befb36639
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / chainlog_ai-0.1.0-py3-none-any.whl

Download URL chainlog_ai-0.1.0-py3-none-any.whl
Size 5.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b1c2dc054b8c11650abb3b50454677aa809f623f3fa78aef21ef2f6c5f1ece03
BLAKE2b-256 checksum
How to use checksums
19a8ed3c2b4d75067a04295615db499230c66acc3463bd963a3410c359629855
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page