Introduction
What Tracemill is and why it exists.
Tracemill is a stateful, high-fidelity telemetry generation engine. It produces realistic, correlated event streams from declarative YAML configurations — purpose-built for detection validation and stress-testing observability and security systems.
Why Tracemill?
Security and observability teams need realistic telemetry to validate detection rules, stress-test SIEM pipelines, and verify alert logic. Tracemill generates events that mirror real-world patterns — including stateful sequences, correlated identifiers, and realistic field values — without requiring access to production environments.
Two ways to run it
- CLI — run the engine yourself, locally or in CI.
- Cloud — Tracemill Cloud, the managed web UI with targets, pipelines, and run history.
Both share the same engine model.
Start here
- How it works — the Pool → Scenario → Runner → Sink model
- Scenarios — the core building block
- Install the CLI — generate your first events