Introduction

What Tracemill is and why it exists.

Tracemill is a stateful, high-fidelity telemetry generation engine. It produces realistic, correlated event streams from declarative YAML configurations — purpose-built for detection validation and stress-testing observability and security systems.

Why Tracemill?

Security and observability teams need realistic telemetry to validate detection rules, stress-test SIEM pipelines, and verify alert logic. Tracemill generates events that mirror real-world patterns — including stateful sequences, correlated identifiers, and realistic field values — without requiring access to production environments.

Two ways to run it

  • CLI — run the engine yourself, locally or in CI.
  • Cloud — Tracemill Cloud, the managed web UI with targets, pipelines, and run history.

Both share the same engine model.

Start here