A desktop log analysis tool for Android developers, IT staff, and support personnel. Load logcat, bugreport, dumpstate, and kernel (dmesg) files, or stream live from ADB — then search, filter, and run custom analysis pipelines powered by a YAML processor system with embedded Rhai scripting.
Windows (Chocolatey): from an elevated shell; installs for all users:
choco install logtapper
Windows (winget): pending approval. LogTapper's first winget manifest is awaiting review
by the Microsoft maintainers of microsoft/winget-pkgs
(#438639). Until it merges, winget
will not find the package; use Scoop or the direct download below. Once it is approved:
winget install jpicklyk.LogTapper
Windows (Scoop):
scoop bucket add logtapper https://github.com/jpicklyk/logtapper-scoop
scoop install logtapper
macOS (Homebrew): LogTapper is not yet notarized (see macOS first launch below), so clear the quarantine flag once after installing:
brew install --cask jpicklyk/logtapper/logtapper
xattr -d -r com.apple.quarantine /Applications/LogTapper.app
Older instructions used brew install --cask --no-quarantine; Homebrew has since removed
that option and rejects it as invalid. If Homebrew reports an error in the cask itself, run
brew update and install again — Homebrew refreshes taps only periodically, so a retry can
otherwise reuse a cask that has since been fixed.
Scoop installs update with scoop update logtapper — the in-app updater is disabled for
them, since Scoop owns the install directory. Chocolatey, winget and Homebrew installs
self-update like any other install (see Updates below), so brew upgrade leaves LogTapper
to that updater. After a self-update, choco list still reports the version Chocolatey
installed; choco upgrade logtapper reinstalls the current release and brings the two back in
step.
Or download the latest release for your platform directly from GitHub Releases:
- Windows:
.exe(NSIS installer) or.msi - macOS:
.dmg— pickaarch64for Apple Silicon orx64for Intel (see the note below) - Linux:
.debor.AppImage
Installed builds update themselves. LogTapper checks for a newer release shortly after
launch and from Settings > General > Updates, where you can also check by hand;
"Install and restart" downloads the update, verifies its signature against the key built
into the app, installs it and relaunches. Neither the launch check nor the install opens a
browser, so the one-time steps below (SmartScreen on Windows, the quarantine flag on macOS)
do not repeat for updates. .deb installs are the exception and update by hand.
LogTapper is not yet notarized by Apple, so a build installed from the .dmg or with
Homebrew carries a quarantine flag. On first launch macOS reports "LogTapper is damaged
and can't be opened" and offers to move it to the Trash. The app is not damaged — this is
Gatekeeper blocking an unsigned download. Right-clicking Open no longer clears it on
current macOS.
To install from the .dmg:
-
Open the
.dmgand drag LogTapper to your Applications folder. -
Eject the disk image.
-
Remove the quarantine flag from the installed app:
xattr -d -r com.apple.quarantine /Applications/LogTapper.app
-
Launch LogTapper from Applications as normal.
A Homebrew install needs only step 3. Either way it is a one-time step: in-app updates do not carry the quarantine flag (see Updates above). A notarized build would remove the step entirely, which needs an Apple Developer Program membership; until then this is the supported install route on macOS.
LogTapper ships a bundled MCP (Model Context Protocol) server that gives AI agents direct tool access to your live log sessions — tools for searching lines, running analysis pipelines, reading state-tracker events, and managing bookmarks and watches. Installed releases need no Node.js or separate install.
Enable the bridge in Settings > General > MCP Integration, then connect your client:
| Client | Setup |
|---|---|
| Claude Code | One command with the URL shown in Settings (default http://127.0.0.1:40405/mcp) — or let the LogTapper plugin do it |
| Claude Desktop | Install the bundled .mcpb relay once from Settings; it forwards to the same URL and never needs updating |
| Other MCP clients | Connect to the URL over Streamable HTTP, or launch the binary bundled with installed releases over stdio |
LogTapper must be running with the bridge enabled for tool calls to work.
See the MCP Setup Guide for binary locations, the full tool list, and troubleshooting.
The LogTapper plugin adds two skills to Claude Code:
attach-mcp, which registers the MCP server for you and verifies it with a test
call, and log-analysis, which walks Claude through investigating the sessions you
have open — searching for crashes, tracing state transitions, running processors,
and publishing line-anchored findings back into the app.
Install it from the marketplace in this repo. Inside a Claude Code session:
/plugin marketplace add https://github.com/jpicklyk/logtapper
/plugin install logtapper@logtapper-plugins
Or from a terminal:
claude plugin marketplace add https://github.com/jpicklyk/logtapperclaude plugin install logtapper@logtapper-pluginsThen, with LogTapper running and the bridge enabled, ask Claude:
attach to the LogTapper MCP
Full details in Connect LogTapper to Claude Code.
LogTapper uses a YAML-based processor system with embedded Rhai scripting for custom log analysis. See the Processor Authoring Guide to create your own analysis rules — reporters for extracting metrics, state trackers for monitoring transitions, and correlators for linking related events.
Everything below is for building LogTapper from source. Users installing a release need none of it.
Desktop shell: Tauri 2.x — Rust backend + web frontend in a native window
Backend (Rust)
- Tauri command handlers for all IPC
- Custom log parsers (logcat, kernel, bugreport/dumpstate)
- Layered pipeline engine: transformers, reporters, state trackers, correlators
- Rhai scripting sandbox for processor logic
- PII anonymizer with pluggable detectors
- Axum HTTP bridge (loopback only) behind the bundled MCP server
Frontend (Solid 1.9 / TypeScript)
- Vite 8 for bundling and dev server
- Hand-rolled virtualized viewer (
src-solid/viewer/) over a shared fetch scheduler and line cache (handles millions of lines) - CodeMirror 6 for the editable scratch pad / text editor and analysis bodies
- Three-layer design tokens (
src-solid/styles/tokens.css): dark, light and high-contrast bases, user themes on top - Plain Solid stores composed once in
App.tsx, CSS Modules for scoped component styles - Tauri dialog and window-state plugins
- Node.js >= 22
- Rust (stable toolchain, MSVC on Windows)
- npm (comes with Node)
- Bun (optional — only
npm run build:fullneeds it, to compile the standalone MCP sidecar binary)
npm install# Full app — starts Vite dev server + Rust backend together
npx tauri dev
# Frontend only (no Rust backend)
npm run dev# TypeScript check + Vite production bundle
npm run build
# Full Tauri app bundle (includes Rust compilation)
npx tauri buildnpx tauri build does not compile the MCP sidecar binary; the release workflow stages it
with Bun. A source checkout therefore has no sidecar, and tauri dev starts no MCP server —
see Running from source to run it with Node instead.
# Frontend tests
npm test
# Rust backend tests
cargo test --manifest-path src-tauri/Cargo.toml
# Rust linting
cargo clippy --manifest-path src-tauri/Cargo.toml -- -D warningsFive files declare the version (package.json, package-lock.json twice,
src-tauri/Cargo.toml, src-tauri/Cargo.lock, src-tauri/tauri.conf.json); the updater
compares the installed app against what tauri.conf.json said at build time, so they must
never drift.
npm run version:bump -- 0.13.0 # writes all five
npm run version:check # what release.yml also runs before building
git commit -am "chore(release): v0.13.0" && git tag v0.13.0 && git push --tagsThe tag runs .github/workflows/release.yml: one job per platform, each uploading its
installers, the updater bundles and their .sig files to a draft release, and merging
its entry into the release's latest.json. Installed apps read
releases/latest/download/latest.json, which only ever resolves to a published
release — so check the draft has all four platform keys in latest.json, then publish.
Publishing is the moment every installed copy starts being offered the update.
Signing key. Updater bundles are minisign-signed. The public key is
plugins.updater.pubkey in tauri.conf.json; the private key exists only as the
TAURI_SIGNING_PRIVATE_KEY / TAURI_SIGNING_PRIVATE_KEY_PASSWORD repository secrets and
in the maintainer's password manager. It is compiled into every shipped build: if it is
lost, no existing install can ever accept another update and everyone reinstalls by hand.
It is never committed (.gitignore refuses *.key) and there is no rotation.
src-tauri/ Rust backend (Tauri commands, parsers, pipeline engine, MCP bridge)
src-solid/ Frontend source (Solid UI: shell, viewer, stores, surfaces)
src-shared/ Framework-free modules shared with the frontend (IPC bindings, cache, filter, viewport)
mcp-server/ MCP server the app spawns over HTTP, plus the Claude Desktop relay (`.mcpb`)
marketplace/ Processor marketplace (YAML definitions + pack manifests)
plugins/ Claude Code plugin (attach-mcp and log-analysis skills) and its marketplace manifest
docs/ User documentation (MCP setup, processor authoring)
design_docs/ Architecture and security design specs
Copyright (c) 2026 Jeff Picklyk
Licensed under the GNU General Public License v3.0.