Skip to content

Getting started

Four pages, in order. They take you from an empty machine to querying data you sent yourself.

  1. Quickstart: bring the full stack up with one docker compose command, send a log record, query it back.
  2. Your first queries: the events table, the SQL surface, and how to read the cost and scan statistics that come back with every response.
  3. Sending real data: point an OpenTelemetry Collector, an SDK, or an Elasticsearch bulk client at Siglake.
  4. Local development: building from source, running the test gate, and the single-process demo mode.

What you'll be running

The quickstart stack is the smallest topology that exercises the real production code paths: object storage, a SQL catalog, and every server role as its own process.

Service Role Port
ingester OTLP + bulk endpoints, writing WAL segments 8088 (API), 9100 (metrics)
compactor Drains sealed WAL segments into Iceberg; runs compaction 9101 (metrics)
query-server DataFusion SQL over Iceberg + the WAL buffer 8089 (API), 9105 (metrics)
postgres Iceberg catalog 5433
minio S3-compatible warehouse 9000 (S3 API), 9001 (console)
prometheus Scrapes every role 9090

One replica of each service on a single host: this is not a high-availability topology, and it is not meant to be. For a real deployment see Operations.

Prerequisites

  • Docker with the Compose plugin.
  • curl, and jq for reading responses.
  • Roughly 4 GB of free RAM and a few GB of disk for the first image build.

You do not need a Rust toolchain to run the quickstart. Rust is only needed if you build from source.