Skip to content
CAI
Software that uses CAICheck a score

napalm-automation/napalm-logs

63.1

Adequate · 22 September 2026

10.1k

lines of production code

Python

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Napalm-logs is a Python-based syslog parsing and publishing service that transforms raw network device logs into structured OpenConfig or IETF YANG models. It features a multi-process architecture with pluggable components for listening (TCP, UDP, ZMQ, Kafka), buffering (memory, Redis), and transport (HTTP, Kafka, Prometheus), allowing flexible integration with various backends. The system supports secure client authentication and provides comprehensive test coverage for a wide range of network operating systems, including Cisco IOS/IOS-XR, Juniper Junos, Arista EOS, and Fortinet.

How it got here

2017 — Initial release and architecture design

32 changes.

This period marks the initial release of the napalm-logs project, establishing its core Python library and multi-process architecture. The work focused on building a pluggable system for parsing and publishing syslog messages, supported by comprehensive test coverage for various network operating systems.

2018 — Pluggable architecture and test coverage expansion

16 changes.

The project introduced a pluggable serializer and buffer system, allowing users to select output formats and caching backends. Concurrently, extensive test coverage was added across multiple network platforms to validate log parsing and state mapping for various interface and protocol events.

2019–2022 — Test coverage expansion

16 changes.

This period focused on expanding test coverage across multiple network operating systems, including Junos, EOS, NXOS, SONiC, and Fortinet. The work involved adding new test fixtures and expected outputs for various error states, syslog messages, and lifecycle events to ensure accurate parsing and validation.

Features

Add Docker support for Napalm-logs

Introduced a new Docker-based deployment option for Napalm-logs, including a Makefile for building and running the container, a start script, and configuration files. Users can now build a local image or pull a pre-built image from Docker Hub to run Napalm-logs in a containerized environment, with configurable Kafka publishing and port mapping.

docker · high confidence

Add NX-OS log parsing for interface state changes, duplex mode, and user logins

Users will now see structured log notifications for NX-OS devices, including interface up/down states (link failure, error-disabled, individual port down), duplex mode changes, STP BPDU guard blocks, and user login events. This adds comprehensive monitoring for interface lifecycle and authentication events on Nexus switches.

_napalm\logs/config/nxos · high confidence

Add client authentication and secure communication utilities

Added a new \napalm\_logs.utils\ module containing the \ClientAuth\ class, which implements secure client authentication, SSL socket management, and message decryption using the NaCl library. This introduces a keep-alive mechanism to maintain the connection with the authentication server and handles reconnection logic, enabling clients to securely authenticate and receive encrypted logs.

_napalm\logs/utils · high confidence

Add example scripts and configuration for secure and unsecured client connections

Users can now reference provided Python and JavaScript client scripts to connect to the napalm-logs server. The examples demonstrate how to establish connections using ZeroMQ, including a secure client that uses a certificate and key for authentication, as well as an unsecured client. A configuration file example is also provided to show how to set up the server with specific addresses, ports, and Kafka listener settings. Additionally, sample server certificate and key files are included to facilitate testing and setup.

examples · high confidence

Add pluggable memory and Redis buffer interfaces

The napalm-logs package now includes a new \buffer\ module that provides a pluggable interface for log buffering. Users can choose between an in-memory cache (accessible via 'memory' or 'cache') or a Redis-based buffer (accessible via 'redis'). The \\_\init\\_.py\ file registers these implementations in a lookup table, allowing the server pipeline to dynamically select the appropriate buffer type based on configuration.

_napalm\logs/buffer · high confidence

Add systemd service file for NAPALM logs daemon

A new systemd unit file (napalm-logs.service) is introduced to manage the NAPALM logs daemon as a background service. The configuration sets the service to start after the network is available, configures file descriptor limits, and defines the executable path, enabling automatic startup on multi-user boot.

pkg · high confidence

Initial release of napalm-logs: a Python library for parsing and publishing syslog messages

The napalm-logs package is introduced, providing a Python library that parses syslog messages from network devices and structures them according to OpenConfig or IETF YANG models. The release includes the core library, a command-line interface (CLI) for running the daemon, and configuration files (MANIFEST.in, setup.py, etc.) to support installation and packaging. It also adds standard project files such as a Code of Conduct, a Dockerfile for containerized deployment, and documentation configuration for Read the Docs.

(repo-wide) · high confidence

Introduce CLI entry-point script with Prometheus metrics and SSL support

The napalm-logs scripts are now exposed via a new cli.py entry-point, enabling users to start the engine with command-line options for configuring listeners, publishers, and serializers. Notable additions include support for Prometheus metrics collection (with configurable address, port, and directory), SSL/TLS configuration via certificate and keyfile options, and the ability to disable security features. The script also handles process signals (SIGINT, SIGTERM) for clean shutdowns and integrates with the napalm-logs engine for processing syslog messages.

_napalm\logs/scripts · high confidence

Introduce multi-process architecture with dedicated worker processes

The napalm-logs engine has been refactored into a multi-process architecture where distinct worker processes handle specific roles: listening for incoming syslog messages, identifying the operating system and parsing log content, authenticating clients via SSL, and publishing processed data. This separation improves stability, allowing individual components like the listener or device parser to restart independently without crashing the entire system. The base engine now initializes and manages these subprocesses, each with its own lifecycle and signal handling, while the main process coordinates their startup and graceful shutdown.

_napalm\logs · high confidence

Introduce pluggable serializer system

Users can now choose from multiple output formats for log data, including JSON, YAML, msgpack, and Python's pprint. The new serializer module provides a lookup mechanism to select the desired format, with msgpack as the default. This allows users to configure their preferred serialization method for log output.

_napalm\logs/serializer · high confidence

Introduce pluggable transport architecture for napalm-logs

The napalm-logs package now supports a pluggable transport system, allowing users to send log messages to various backends. The diff introduces a new \transport\ package with a \TransportBase\ interface and specific implementations for ZeroMQ, CLI, logging, HTTP, Kafka, Alerta, and Prometheus. A central \get\transport\ function in \\\init\\_.py\ dynamically loads these transports based on availability (e.g., \kafka\ if the \kafka\ library is installed, \http\ if \requests\ or \tornado\ are present). This change enables flexible log routing and integration with diverse systems like message queues, HTTP endpoints, and monitoring tools.

_napalm\logs/transport · high confidence

Behavioural changes

Centralize and expand configuration defaults for logging and transport

The configuration defaults for napalm\logs are now centralized in a new \\init\\_.py file, establishing a single source of truth for the application's settings. This change introduces explicit defaults for TCP and UDP listeners, ZMQ-based IPC proxy URLs for internal communication, and specific options for the logger and publisher (including send\_raw and send\_unknown flags). It also defines the structure for message mappings, logging levels, and authentication keep-alive parameters, providing a more robust and extensible configuration foundation.

_napalm\logs/config · medium confidence

Pluggable listener architecture with TCP, UDP, ZMQ, and Kafka support

The napalm-logs listener module has been refactored into a pluggable architecture, introducing a \ListenerBase\ and a \get\_listener\ factory that dynamically registers available listener types. Users can now configure and use TCP, UDP, ZeroMQ (ZMQ), and Kafka listeners. The TCP listener supports both traditional and octet-counted framing, while the Kafka listener handles message decoding and JSON parsing. This change enables easier integration of new transport protocols and improves error handling and logging across all listener types.

_napalm\logs/listener · high confidence

Test coverage

Add Junos BGP prefix limit/threshold exceeded test cases; Add Junos NTP server unreachable test case; Add Junos test fixtures for NH\_HOLD\_PACKET; Add test cases for Junos SYSTEM\_ALARM\_CLEARED events; Add test coverage for Junos PROCESS\_CEILING\_WATERMARK\_REACHED error; Add test coverage for NX-OS interface up notification in trunk mode; Add test coverage for NXOS BPDU Guard error handling; Added IOS test cases for interface and OSPF neighbor state changes; Added Junos FAILED\_ALLOCATING\_PACKET\_BUFFER syslog test; Added Junos ISIS neighbor state test cases; Added Junos NAT session creation test cases; Added Junos NH\_REGION\_GRAB\_FAILED test case; Added Junos SYSTEM\_ALARM test cases; Added Junos alarm test cases for major alarm set and cleared states; Added Junos test cases for configuration commit and MAC limit messages; Added Junos test cases for configuration errors and rollback events; Added Junos test fixtures for BGP and user mode events; Added Junos test fixtures for configuration commit completion; Added Netiron test cases for BGP, OSPF, and interface state changes; Added test cases for BGP and OSPF neighbor state changes; Added test cases for Huawei interface state changes; Added test cases for ISIS neighbor state changes; Added test cases for Junos BGP connection rejection and reset scenarios; Added test configurations for SONiC BGP and interface state changes; Added test coverage for Arista EOS BGP neighbor state changes; Added test coverage for EOS ISIS neighbor state changes; Added test coverage for EOS user write config and syslog messages; Added test coverage for Fortinet FORWARD\_TRAFFIC syslog and YANG mapping; Added test coverage for Fortinet LOCAL\_TRAFFIC syslog parsing; Added test coverage for IOS-XR configuration commit completion; Added test coverage for Junos BGP prefix limit exceeded scenario; Added test coverage for Junos BGP session not configured error; Added test coverage for Junos BPDU block disabled port error; Added test coverage for Junos DDOS\_PROTOCOL\_VIOLATION\_SET; Added test coverage for Junos LACP interface down notifications; Added test coverage for Junos MINOR\_ALARM\_SET and MINOR\_ALARM\_CLEARED messages; Added test coverage for NXOS interface down scenarios; Added test coverage for NXOS user login events; Added test fixtures for AGENT\_INITIALIZED syslog and YANG messages; Added test fixtures for BFD state change events on EOS; Added test fixtures for BGP prefix threshold exceeded on IOS-XR; Added test fixtures for Cisco IOS XR interface state changes; Added test fixtures for EOS interface up/down state changes; Added test fixtures for EOS maintenance mode state changes; Added test fixtures for EOS process lifecycle events; Added test fixtures for IPv6 BGP prefix threshold exceeded scenario; Added test fixtures for NTP server unreachable scenario; Added test fixtures for OpenGear console server events; Added test fixtures for authentication; Added tests for BGP and BFD state conversion utilities.

Dependencies

Established explicit dependency lists for the project

The project now explicitly defines its dependencies in three separate requirement files: requirements.txt for core packages (including pyzmq, pyyaml, pynacl, dateparser, sentry\_sdk, u-msgpack-python, and prometheus\_client), requirements-dev.txt for development and testing tools (such as tox, black, pytest, pylama, and flake8-import-order), and docs/requirements.txt for documentation generation (including jinja2, sphinx, and related themes). This structure separates production, development, and documentation dependencies to improve clarity and manageability.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 63 (+7.7)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 78 → 87 (+8.9)
  • Architecture 100 → 96 (-4.1)
  • Maturity 65 → 65 (-0.4)
  • Readiness 46 → 54 (+8.2)
  • Security 53 → 67 (+13.9)

Resolved (30)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (napalm_logs/listener/tcp.py)
  • Duplicated block (11 lines × 2) (napalm_logs/transport/prometheus.py)
  • Duplicated block (11 lines × 2) (napalm_logs/transport/prometheus.py)
  • Duplicated block (12 lines × 2) (napalm_logs/device.py)
  • Duplicated block (13 lines × 2) (napalm_logs/transport/alerta.py)
  • Duplicated block (7 lines × 2) (napalm_logs/device.py)
  • Duplicated block (8 lines × 2) (napalm_logs/scripts/cli.py)
  • Duplicated block (9 lines × 2) (napalm_logs/listener/tcp.py)
  • Duplicated block (9 lines × 2) (napalm_logs/scripts/cli.py)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 10 more

New (53)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.rst)
  • Documentation: no installation or build instructions (docs/releases/index.rst)
  • Documentation: no licence statement (docs/releases/index.rst)
  • Documentation: no usage examples (docs/releases/index.rst)
  • Duplicated block (10 lines × 2) (napalm_logs/listener/tcp.py)
  • Duplicated block (10 lines × 4) (napalm_logs/buffer/init.py)
  • Duplicated block (11–12 lines × 2) (napalm_logs/device.py)
  • Duplicated block (12 lines × 2) (napalm_logs/device.py)
  • Duplicated block (12–13 lines × 2) (napalm_logs/transport/prometheus.py)
  • Duplicated block (14 lines × 2) (napalm_logs/listener/tcp.py)
  • Duplicated block (14 lines × 2) (napalm_logs/scripts/cli.py)
  • Duplicated block (14 lines × 2) (napalm_logs/scripts/cli.py)
  • Duplicated block (16 lines × 2) (napalm_logs/transport/alerta.py)
  • Duplicated block (29 lines × 2) (napalm_logs/transport/prometheus.py)
  • Duplicated block (5 lines × 2) (napalm_logs/pub_proxy.py)
  • Duplicated block (7 lines × 2) (napalm_logs/device.py)
  • Further orphaned files (smaller)
  • High IaC: WD-DOCKER-0013 (Dockerfile)
  • High: security finding (details withheld)
  • …and 33 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

napalm-automation/napalm-logs was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1f7b06f808156812bab07d1c622fa1d0ba91f2d5 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.