finds.dev← search

// the find

alibaba/loongcollector

★ 2,202 · C++ · Apache-2.0 · updated Oct 2026

Fast and Lightweight Observability Data Collector

LoongCollector is Alibaba's rewrite of iLogtail, a C++ agent for logs, metrics, traces, and eBPF-based network/security data, built for high-volume Kubernetes fleets. It's aimed at platform teams running their own observability pipeline at scale, not individual developers wanting a quick local logger.

The architecture notes are specific rather than hand-wavy: a shared SourceBuffer memory arena with string_view references avoids per-event copies, and the sender path skips intermediate protobuf objects to serialize straight to wire format. Multi-tenant pipeline isolation with high/low watermark back-pressure per pipeline is a real design choice that matters once you're running hundreds of configs on one node, not a feature list item. The eBPF-based network/security collection folded into the same agent as log/metric collection is a genuine differentiator versus Fluent Bit or Vector, which don't do that natively.

The benchmark table compares against Fluent Bit, Vector, and Filebeat with no linked methodology, hardware spec, or reproduction steps, so the 10x/80% numbers are not independently checkable as given. Remote config management is built around Alibaba Cloud's SLS console/SDK/Operator, and while it's open source, the primary docs live on observability.cn with the operational tooling clearly designed for Alibaba Cloud first, so expect friction running it fully independent of that ecosystem. The core mixes C++ and Go (plugins in both languages) plus eBPF kernel code, which raises both the build complexity (submodules, specific Go toolchain pin, Docker) and the contributor bar compared to a single-language agent like Vector.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →