Skip to content

LogsTotal documentation

LogsTotal is a self-hosted log analysis platform: upload a log file and several detection engines (Zircolite, Chainsaw, Hayabusa, ChopChopGo, RSigma) report what each of them found, grouped by severity, with MITRE ATT&CK context and the entities they involve.

These pages are for the people who install and run an instance, and for contributors. The guide for analysts using it is built into the application, at /docs.

Every command here is run from the install directory as ./logstotal <name>. It needs nothing installed first: see Prerequisites.

Get started

You want to Read
Try it, or run it on one server Single-host installation
Put HTTPS in front of it HTTPS with Caddy
Spread analysis over several machines Fleet installation
Install where there is no internet access Offline installation

Start with the prerequisites, and go through the security checklist before anyone else can reach your instance.

Operate

Reference

Contribute