Every logging stack is fine at first. Then volume grows, and the failure is always the same shape: the bill grows faster than the data, and the thing you are asked to do about it is log less.
Logging less is a terrible answer. The logs you drop are the ones you needed during the incident you had not had yet. But the alternative — an index-per-field cluster you now have to operate, or a vendor charging per host, per GB, per query and per seat — is how observability ends up costing more than the infrastructure it watches.
So Logstreem takes the other side of the trade. No indexes, so there is nothing to size and nothing to reindex. Columnar blocks on object storage, so retention is cheap and predictable. One meter — gigabytes in — so the cost of keeping a log is a number you can reason about before you write the log line.