petit is a command-line log analyzer for developers and systems administrators. It matches repetitive strings in a log (logins, cron runs, health checks, etc) and counts them. This separates the signal from the noise, leaving a short, easy read. The unusual lines stand out. It also has a whole host of other functions which make working with logs more convenient (Graphs, Word Counts, etc). Petit digests many different text formats, and it auto-selects the correct drivers (syslog, journalctl, Apache, Snort, application logs with stack traces, JSON, email). And, it has been doing all of this since 2009.
-
Hashing.
petit --hashgroups lines by what's left after numbers, IPs and timestamps are taken out, and prints each pattern once with its count. A 1500-line sshd log becomes eight lines.--fingerprintgoes further and collapses whole reboots into one line. Hashing -
Reports.
--daemon,--hostand--wordcountcount a log by program, by machine, or by word, which shows its shape before you read a single line. Reports -
Graphs.
--graphdraws the whole log over time in the terminal, choosing a column size that fits;--hgraph,--mgraph,--span 90mand friends pick a fixed window. Graphs -
Format detection. petit frames the input into records (JSON objects, mail messages, multi-line messages with their stack traces, or lines) and votes on a driver to read them. It streams: memory follows the number of distinct patterns, not the size of the log. Reading logs
-
Python library.
hash_lines(),analyze_text()and friends return the same groups as data, with no files, stdout or exits involved. Library
# Fedora, RHEL and rebuilds (Debian, Ubuntu and SUSE are in docs/install.md)
sudo curl -fsSLo /etc/yum.repos.d/crunchtools.repo \
https://crunchtools.github.io/packages/rpm/crunchtools.repo
sudo dnf install petit
# Anywhere with Python 3.11+
uv tool install petit-log-crunchtools
# Or in a container
podman run --rm -v $(pwd):/data:ro,Z quay.io/crunchtools/petit --hash /data/some.logPackages for RHEL, Fedora, Ubuntu, Debian, and Suse are also available.
Then:
petit --hash --fingerprint /var/log/messages # what happened, minus reboots
petit --daemon /var/log/messages # who's talking
petit --graph /var/log/httpd/error_log # when
grep error /var/log/messages | petit --mgraph # when, for just the errorspetit started as lt, a Perl script inspired by Marcus Ranum's
artificial ignorance,
and became petit in August 2009. Since then:
- 2009: first shown at the Akron Linux Users Group; hosted in Subversion at eyemg
- 2010: packaged in Fedora and EPEL, then Debian; moved to crunchtools.com and presented at PyOhio
- 2010–2015: hosted on Google Code as
petit-log, in Mercurial - 2011–2019: shipped in every Ubuntu release from 11.04 to 19.10
- 2015: moved to GitHub by the Google Code exporter
- 2018–2020: dropped from Fedora, Debian and Ubuntu along with Python 2
- 2022: ported to Python 3
- 2026: moved to the crunchtools org, relicensed AGPL, back in native packages
The full timeline, with sources, is in History.
Further reading: Introduction: Petit Log Analysis Tool for Systems Administrators (video, 2009), Centralized Logging System, Analysis, and Troubleshooting (2010), Snort Alert Log: Simple Analysis and Daily Reporting with Arnold and Petit (2010), Log Analysis with Python, PyOhio 2010, Petit for Log Analysis by Jason Antman (2012), Petiti – An Open Source Log Analysis Tool for Linux SysAdmins by Aaron Kili at Tecmint (2017).
| Page | What it covers |
|---|---|
| Install | Native packages for Fedora, RHEL, SUSE, Debian and Ubuntu; PyPI; container |
| Hashing | --hash, samples, filters, --fingerprint, --identifiers |
| Reports | --daemon, --host, --wordcount |
| Graphs | Every graph, its units, window and width |
| Reading logs | Framers, drivers, big inputs, multi-line messages, JSON |
| Library | The Python API and what SemVer covers |
| Philosophy | Why petit removes certainty and leaves uncertainty |
| History | Where petit has lived since 2009, and what's been written about it |
| Writing and tuning drivers | For contributors: framers, entry and hash drivers, stopwords, reboot corpora |
uv sync --all-extras # dev tools: pytest, ruff, mypy
uv run pytest # tests
uv run ruff check src test # lint
uv run mypy src # types
podman build -t petit . # containerPackages, the container image and PyPI releases are built by GitHub Actions on every GitHub release. The README demo is rendered from docs/demo/petit.tape.
AGPL-3.0-or-later. See COPYING.

