1.7 KiB
1.7 KiB
LOGAR Server Hub
Central Python/TCP ingestion server for the LOGAR Log Analysis System.
Features
- Zero External GPG Requirement: Uses pure-Python OpenPGP (
pgpy+cryptography), no native GnuPG binary needed. - First-Run Key & Config Auto-generation: Generates OpenPGP keypairs, auth tokens, and
server_config.jsonautomatically on first launch. - Client Config Exporter: Generates
client_config.jsonbundles containing the server's encryption-only fingerprint and address. - Cloud-Side Temporal Persistence: SQLite database tracking candidate anomalies over 12-hour evaluation windows.
- 4-Run Persistence Rule: Filters out transient infrastructure blips, promoting issues to
VERIFIEDanomalies only after persisting across\ge 4runs. - Agentic Hermes Endpoint: REST API (
GET /api/hermes/report) providing verified system artifacts for Hermes agent alerts.
Installation
pip install -r requirements.txt
Running the Server
# Starts both the TCP socket listener (port 9443) and the Hermes API (port 8443)
python Server.py
Generating Client Configurations
To deploy edge forwarders, generate a client config file:
python Server.py --create-client-config --server-host <SERVER_IP_OR_DNS> --server-port 9443 --site-name "Frankfurt-DC" --client-out client_config.json
Copy the generated client_config.json into the deployment directory of Win_Client.py or Linux_Client.py.
Hermes Agent Integration
Hermes queries the verified anomalies via:
GET http://<SERVER_IP>:8443/api/hermes/report
Only issues meeting the 4-run persistence rule within the active 12-hour evaluation window are returned.