Big ears for your logs.

Hark reads your Google Cloud Run logs every five minutes. It stays quiet until something new shows up, or something steady stops.

One email when there’s a spot for you. Nothing else.

One Cloud Run service in your own project. One Slack channel. One config file.

Illustration: a fennec fox peeks over a dune made of repeating log lines, ears up. One line is highlighted, the only one that was not there yesterday.

An hour of logs, folded into patterns.

Logs repeat. Hark folds them into templates with Drain3, masks anything personal, and asks a model about each new template once. Cost follows novelty, not volume.

Templates

Templates Hark has seen this hour, with counts
PatternSeenStatus
GET /api/cart <*> <*>ms 0 known
healthcheck ok 0 known
GET /api/events <*> <*>ms 0 known
cache hit key=evt:<uuid> 0 known
session refreshed user=<email> 0 known
pubsub ack id=<hex> <*>ms 0 known
Lines read
0
Templates
6
Model calls
0

Illustrative traffic. The folding and the one-call rule are real.

Cloud Logging in, Slack out.

Every five minutes Cloud Scheduler wakes Hark for one tick. It does the cheap work first and only spends a model call on a line it has never seen.

  1. Fetch

    Reads Cloud Logging from where the last tick stopped, a minute behind real time so late entries are not missed. Up to 20,000 entries a tick.

  2. Mask

    Emails, tokens, keys, JWTs, card numbers, IPs, UUIDs and long hex runs become placeholders before anything is stored or sent to a model.

  3. Mine

    Drain3 folds each service’s lines into templates. Snapshots live in a bucket in your own project.

  4. Count

    Hourly counts per template, kept in Firestore. This is Hark’s memory of what normal looks like.

  5. Score

    A model judges each new template once: what it is, who it affects, whether to page. Capped at 60 calls an hour.

  6. Quiet check

    Patterns that show up steadily are compared with the same hour on previous days. When one stops, or a whole service goes silent, that is news too.

  7. Alert

    Only what should interrupt you. At most five an hour, and never the same thing twice in a day.

  8. Digest

    One message a morning: what is new, what grew, what stopped. Ten lines at most.

  9. You

    Every digest line has Useful and Noise links. Two Noise votes mute that pattern for good.

Three kinds of message. That’s all.

No dashboard to keep open. Hark posts to one Slack channel and keeps every message short enough to read on a phone, half awake.

A new pattern that matters

! checkout: Payments failing since the last deploy. Stripe rejects an unknown field.1
Template: PaymentIntent create failed: unknown field <*>
Sample: PaymentIntent create failed: unknown field "receipt_url" (order <uuid>)2
First seen: 2026-09-30 14:05 UTC
Last deploy: 12 min ago (checkout-00041-xbz)3
Example new-pattern alert
  1. Written by the model, once, when it first saw the template.
  2. Masked before it left your project. The model never sees the order ID.
  3. Hark knows your revisions, so “since the last deploy” is a fact, not a guess.
  4. Opens Logs Explorer already filtered to this pattern.

Something steady went quiet

? sync-worker: Pattern went quiet: usually about 240/hour at this time of day, none in the last hour.1
Template: Synced cohost batch <*> (<*> tickets)
First seen: 2026-09-12 09:40 UTC2
Example gone-quiet alert
  1. Compared with the same hour on previous days, so a 3 a.m. lull is not an incident.
  2. Only patterns that show up nearly every hour qualify. If a whole service goes silent, you get one message for the service, not one per pattern.

The morning digest

hark digest 2026-09-30: 2 alerts sent, 3 feedback (2 useful, 1 noise)
new  checkout: Stripe rejects an unknown field  Useful Noise1
grow api: Upstream timeout, retrying <*> x14 (5320 in 24h)  Useful Noise2
stop sync-worker: Synced cohost batch <*> (was 5760/day)  Useful Noise
Example daily digest
  1. Things worth knowing that were not worth waking you for. Ten lines at most.
  2. Two Noise votes mute a pattern. On a quiet day the digest says so in one line: nothing new, nothing growing, nothing stopped.

Examples use made-up services. The formats are the real ones.

What’s under the sand.

It lives in your project, reads with the least access that works, and has one config file.

How Hark is built and deployed
Runs in Your Google Cloud project. One Cloud Run service, one instance at most. deploy.sh sets it up
Remembers with Firestore for counts and verdicts, a Cloud Storage bucket for Drain3 snapshots.
Can read Logs, through a service account with logging.viewer, datastore.user, its own bucket and its own secrets. Nothing else. least privilege
Masks Emails, tokens, keys, JWTs, card numbers, IPs, UUIDs and long hex runs, before storage and before any model call.
Asks Claude by default, or another model through OpenRouter. A shadow scorer can judge alongside without alerting, so you can compare. at most 60 calls an hour
Is woken by Cloud Scheduler, with an OIDC token. Feedback links are HMAC-signed and need a click to confirm.
Is configured by One hark.yaml: services, thresholds, digest time, timezone. Thresholds can be set per service, so checkout pages at a lower bar than a cron job. secrets stay in Secret Manager

And one rule we hold to: Hark never reads its own logs.

On our own services since 18 September 2026.

alerts on the first scoring tick. Thirteen new templates judged, nothing wrong, so nothing said.
0
Cloud Run services watched
3
minutes between ticks
5
digest, New York time
08:00

Fair questions.

What do I need to run it?

A Google Cloud project with services on Cloud Run, a Slack incoming webhook, and a hark.yaml that lists your services. One deploy script creates the service account, Firestore, the bucket, the secrets, the Cloud Run service and both scheduler jobs.

Does a model read my logs?

It reads templates, not your log stream. Each new template is sent once, with a masked sample line and a little context about the service. Known templates cost nothing, however often they repeat.

Only Cloud Run?

For now, yes. Hark reads Google Cloud Logging and understands Cloud Run revisions, which is how it can say “since the last deploy”. Tell us what else you run when you join the waitlist.

How does it tell quiet from broken?

Only patterns that show up nearly every hour, at a decent rate, are watched for silence. The last hour is compared with the same hour on up to seven previous days, so a Sunday-morning lull is not an alert.

What will it cost?

We haven’t set a price yet. Model spend grows with how many new patterns you have, not with how many lines you log. People on the waitlist hear first.