LogsTotal documentation¶
LogsTotal is a self-hosted log analysis platform: upload a log file and several detection engines (Zircolite, Chainsaw, Hayabusa, ChopChopGo, RSigma) report what each of them found, grouped by severity, with MITRE ATT&CK context and the entities they involve.
These pages are for the people who install and run an instance, and for contributors.
The guide for analysts using it is built into the application, at /docs.
Every command here is run from the install directory as ./logstotal <name>. It needs
nothing installed first: see Prerequisites.
Get started¶
| You want to | Read |
|---|---|
| Try it, or run it on one server | Single-host installation |
| Put HTTPS in front of it | HTTPS with Caddy |
| Spread analysis over several machines | Fleet installation |
| Install where there is no internet access | Offline installation |
Start with the prerequisites, and go through the security checklist before anyone else can reach your instance.
Operate¶
- Health, logs and the first day
- Change the configuration
- Workers and stuck jobs
- Storage and retention
- Detection tools and workflows
- Back up and restore
- Upgrade and roll back
- Database migrations
- Move from SQLite to PostgreSQL
- Recover administrator access
- Troubleshooting
Reference¶
- Commands
- Configuration (environment variables)
- Admin pages and settings
- Fleet options and day-2 commands · Manual fleet installation
- Ingestion API
- Security · Capacity planning · Known limitations