Tangent
Security log pipeline powered by WASM
Details
- External ID
- 45994592
- Source
- HN
- Company
- —
- Product
- Tangent
- Website domain
- github.com
- Launched
- Nov. 20, 2025
- Cohort
- —
- Upvotes
- 28
- Upvotes percentile
- 0.74235807860262
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Hi HN! We’re Ethan and Danny, the authors of Tangent (https://github.com/telophasehq/tangent), a Rust-based log pipeline where all normalization, enrichment, and detection logic runs as WASM plugins.We kept seeing the same problems in the OCSF (https://ocsf.io) community: 1) Schemas change constantly. Large companies have whole teams dedicated to keeping vendor→OCSF mappings up to date. 2) There’s no shared library of mappings, so everyone recreates the same work. 3) Writing mappers is tedious, repetitive work. 4) Most pipelines use proprietary DSLs that are hard to share and hard for tools/LLMs to generate.Tangent takes a different approach: no DSLs – mappings and enrichments are just normal code compiled to WASM, shareable plugins – we maintain a community library (https://github.com/telophasehq/tangent-plugins), interoperability – we can run other engines’ DSLs (e.g., Bloblang) inside WASM for easy migration, full flexibility – plugins can validate schemas, call external APIs (https://github.com/telophasehq/tangent/blob/main/examples/en...), or perform complex transforms (https://github.com/telophasehq/tangent-plugins/blob/main/zee...).Here's an example Python transformation plugin to drop all fields from a log except `message`: import json from typing import List from wit_world.imports import log # `log.Logview` is Tangent's zero-copy JSON accessor type. def process_logs(self, logs: List[log.Logview]) -> bytes: out = bytearray() for lv in logs: msg = lv.get("msg") value = msg.value if msg is not None else "" out.extend(json.dumps({"message": value}).encode() + b"\n") return bytes(out) We have plenty more examples in the repo.Because plugins are just Go/Python/Rust, LLMs can create new mappers with ease. For example, I asked: Generate a mapper from AWS Security Hub Finding to OCSF and only had to make a few minor tweaks. (https://github.com/telophasehq/tangent-plugins/blob/main/aws...)Performance-wise, a 16-core Amazon Linux box processes ~480 MB/s end-to-end (TCP → Rust-WASM transform → sink) on ~100-byte JSON logs. The CLI includes tooling to scaffold, test, and benchmark plugins locally. Here's a deep dive into how we are able to get this performance: https://docs.telophasehq.com/runtime.We’d love to get your feedback! What do you think?
Enrichment
- Theme
- database infrastructure and developer tools
- Vertical
- Security
- Function
- Data infrastructure
- Audience
- B2B
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- wasm-powered security log pipeline
- Manually corrected
- False
Could you build this?
No Building a high-throughput, low-latency log processing engine in Rust that embeds a WebAssembly runtime (e.g. Wasmtime) and normalizes high-volume security telemetry into OCSF requires deep systems programming and security domain expertise.
What it would actually take: The architecture requires a Rust-based stream processing daemon (using Tokio and Wasmtime/Wasmer) that ingests streaming logs (via Kafka, Syslog, or S3), executes sandboxed WASM plugins for mapping fields to the complex OCSF schema, and handles out-of-order events with minimal memory overhead. Building it requires deep knowledge of zero-copy parsing, WASM ABI guest-host communication, and enterprise cybersecurity data schemas.
Discussion
2 comments analyzed.
Competitors
Other products that read as similar to this one — 91 launches clear the similarity bar, closest 8 shown.
Attention rank: #30 of 92 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 19 days after the earliest competitor.
- Talos · hn · 2026-06-18 · 106 upvotes · similarity 0.46
- Bloodhound · hn · 2025-12-09 · 5 upvotes · similarity 0.43
- Glintlog · hn · 2026-02-04 · 10 upvotes · similarity 0.41
- BetterDB · hn · 2026-01-23 · 6 upvotes · similarity 0.41
- Rocky · hn · 2026-04-28 · 122 upvotes · similarity 0.40
- Sandboxing untrusted code using WebAssembly · hn · 2026-02-03 · 76 upvotes · similarity 0.40
- Timberlogs · hn · 2026-01-13 · 13 upvotes · similarity 0.39
- Telescope now queries Kubernetes logs directly · hn · 2026-02-16 · 9 upvotes · similarity 0.39
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a data infrastructure tool for Media & entertainment yet.