# teler-sh/teler

Real-time HTTP Intrusion Detection

Repository: https://github.com/teler-sh/teler
Canonical: https://ross.abutalabs.com/products/teler
Homepage: https://teler.app
Language: Go
License: Apache-2.0
License Family: permissive
Topics: threat-hunting, threat-intelligence, ids, intrusion-detection-system, threat-analyzer, go, golang, intrusion-detection, intrusion, threat, threat-rules, analyze-logs, iocs, logs, log-analyzer, log
Archived: true
Last push: 2024-02-13T04:54:25+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2234, "days_push": 932, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3083, forks 249 (observed 2026-08-28T04:07:41.985103+00:00)

## What it is
teler is a real-time HTTP intrusion detection system that analyzes web server logs and alerts on threats using threat intelligence and custom rules. It is a Go-based CLI tool; development of v2 is on hold while a v3 rewrite based on eBPF and teler-waf is planned.

## Use cases
- detect intrusion attempts in nginx access logs in real time
- alert on malicious HTTP requests hitting my web server
- analyze web logs for IOCs and known attack patterns
- monitor web traffic for threats from the terminal
- run an IDS on my server logs without heavy infrastructure
- feed threat intelligence into my log monitoring pipeline

## When to avoid
- you need actively maintained software with recent releases and guaranteed support
- you need host-level or network-level IDS beyond HTTP log analysis
- you want eBPF-based detection today, which is only planned for the unreleased v3

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: monitoring, alerting, logging, security
- domain: security, monitoring, self-hosted
- platform: windows, cli, cross-platform
- tags: ids, intrusion-detection, log-analysis, threat-intelligence, http-logs, web-security, devops, linux, macos

## Member repositories
- teler-sh/teler (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:41.985103+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:27:42.278990+00:00, confidence not recorded.
  - readme: https://github.com/teler-sh/teler (fetched 2026-08-28T04:07:41.985103+00:00, sha a7c9fc26de58)
- Data as of 2026-08-30T08:39:29.467469+00:00.
