Developer tools/Open source

Microscope

Monitoring and alerting for Solana programs.

Microscope is self-hosted monitoring and alerting for Solana programs, open source under MIT. It watches every instruction your program runs and every event it emits, along with the Squads multisig that controls it, and alerts your team on Slack, Telegram or PagerDuty when something you care about happens. Point it at your program and its IDL, and one config file sets up the dashboards and alert rules.

One deployment watches one program and, optionally, one multisig. Alerts fire on decoded activity, never on raw log strings.

How to start

Clone, pick a setup, write the config, then deploy.

1

Clone the repo

git clone https://github.com/solana-foundation/solana-microscope.git
cd solana-microscope
2

Choose your setup

Microscope is five pieces, and your server runs all of them unless you already have your own:

Indexer
reads and decodes your program’s transactions
Alloy
ships decoded records to Loki
Prometheus
stores metrics
Loki
stores decoded records
Grafana
dashboards and alerts

Each row below is one way to deploy. A filled dot runs on your server; a hollow dot is one you already operate.

SetupIndexerAlloyPrometheusLokiGrafana
Docker Composeyour machine or one host
Terraforma VM in your AWS or GCP account
Grafana Cloudyour existing Grafana Cloud stack
Kubernetes · referenceyour cluster and observability
Microscope runs itYou already run it
3

Write the config

Have your AI agent run setup-deployment, a skill that ships with the repo. It asks for each value, derives alert rules from your IDL, writes the files your path needs and validates them.

4

Deploy

Docker Compose
cp microscope.toml.example microscope.toml
# add your endpoint and channel credentials to .env
just up

Grafana is on localhost:3000.

Running Kubernetes? The reference manifests run the indexer next to observability you already operate.


What you’ll see

An example of the dashboard Microscope generates.

Two time-series charts showing transaction and on-chain instruction error rates over the last hour
01Transactions / sec and Errors / sec. Decoded transaction rate and failed on-chain instructions. A failed instruction is not an indexer error.
Time-series chart of deposit, redeem, update_rate and withdraw instructions
02Instructions by type. Every decoded instruction your program ran, grouped by instruction name.
Panels showing 2.28 minutes since the last decoded activity and indexer status UP
03Seconds since last decoded activity and Indexer up. Shows how long since Microscope last decoded anything and whether the indexer is running.
Chart with a v4 proposal_approved series
04Squads multisig activity. The multisig’s actions over time. The series appears once the multisig does something.
Table of decoded events with time, event, signature, slot, failed and assets columns
05Decoded program events. Each decoded event as a row. “Not Found” means that event has no configured Assets field.
Table with a Squads v4 proposal_approved row
06Squads multisig activity details. Each multisig action as a row: action, version, instruction, signature and slot.
Four panels for last successful RPC poll, polling lag, quarantined transactions and confirmed head slot
07RPC polling health. Shown when RPC polling runs: last successful poll, lag, quarantined transactions and confirmed head slot.

An alert carries a signal_kind label. A datasource alert reports a degraded monitoring pipeline; activity alerts identify the decoded instruction, event or multisig action. DatasourceError means Grafana could not run a rule’s query, not that your RPC endpoint is down.


Try it today

Jupiter Lend walkthrough
~10 minDockerYellowstone endpoint
  • Decoded deposits, withdrawals, redemptions and rebalances
  • Critical alerts on the two instructions that change who controls the program
  • A warning whenever its Squads v4 multisig creates a proposal
  • Swap three values at the end to point it at your own program
Open the walkthrough

A teaching example. The Solana Foundation does not operate this deployment, monitor Jupiter Lend on anyone’s behalf, or claim affiliation with or endorsement by Jupiter.


FAQ

How do I backfill history?

The indexer sees activity only from the moment it starts. With the stack running, load earlier activity from a regular RPC endpoint:

RPC_URL=https://your-rpc-endpoint just backfill 7d
  • It crawls your program and multisig state account with getSignaturesForAddress, decodes through the same pipeline and backdates records to block time.
  • Backfilled records never trigger alerts. They fall outside the alert lookback window.
  • Windows accept s, m, h, d and w and cannot exceed Loki retention: 30 days in the bundled config.
  • Any failure aborts before anything is written. Prometheus metrics are not backfilled.

On Grafana Cloud, push through Alloy and state the depth cap yourself: add --loki-url http://alloy:3100 --loki-max-age 30d.

What does it cost to run?

About $50 a month on AWS or GCP for the VM, disk and public IPv4 address, or run it on your own machine. Buckets and secrets cost cents. You pay for your own Yellowstone or RPC endpoint.

The stack needs 2 vCPUs, 4 GiB RAM and 40 GiB disk. The first-boot Rust build sets that floor; steady state uses less.

Can I watch more than one program?

Yes, with one Microscope deployment per program. Each deployment watches one program and optionally one Squads multisig because its decoder is built from that program’s IDL. The Terraform modules can run several deployments from the same directory.

Do I need a Squads multisig?

No. Leave out the [multisig] block and Microscope monitors the program only.

An alert fired. How do I investigate?

Every alert carries a signal_kind label. datasource means the pipeline is degraded or lost data. instruction, event and multisig mean your program did something you asked to hear about.

The repo’s diagnose-incident agent skill classifies the alert, checks upstream alerts, confirms the cause against live metrics and logs, assesses data loss, suggests a runbook fix and writes an incident report.

Investigation is read-only. Any deployment change waits for your confirmation, and the skill never reads values out of .env.

My dashboard is empty. Is my program quiet, or is Microscope broken?

Every deployment gets health alerts for its own pipeline whether you configure them or not. They cover a stalled stream, stale or failing RPC polls, a corrupt checkpoint and log delivery.

Check those alerts and the Indexer up panel before concluding the program is quiet. The diagnose-incident skill does this check for you.

Does it work on devnet?

Yes. Point your endpoint at devnet and add ?cluster=devnet to explorer_transaction_url so alert links open the right cluster.

Can I add another alert channel?

Slack, Telegram and PagerDuty are supported today. Microscope is open source, so you can build another channel and contribute upstream. See CONTRIBUTING.md.


Resources


© 2026 Fundação Solana. Todos os direitos reservados.