Lawliet Lawliet
Installation guide

From the bundle to a running platform in one command.

Your Lawliet bundle was built for your organisation. This guide takes you through installing it on one Linux server, signing in for the first time, activating the licence issued for your installation, connecting your first monitored hosts and looking after it from then on.

STEP 1

Before you begin

Lawliet runs as a set of containers on one server. Prepare that server and decide how people will reach it; the installer asks about both.

You needDetails
A Linux serverAny current 64-bit distribution: Ubuntu, Debian, RHEL, Rocky, Alma. Intel/AMD or ARM - the bundle carries native code for both.
HardwareStarts at 4 CPU cores, 8 GB RAM and 40 GB free disk. It scales with the number of monitored hosts and, above all, with how much log history you keep - see Sizing the server below.
DockerDocker Engine 24 or newer with the Compose plugin (docker compose), running, and usable by the account you install with. The installer checks for both and stops if either is missing.
Toolsbash, curl, tar. openssl only if you want the installer to create a self-signed certificate.
An addressThe DNS name or IP address operators and monitored hosts will use to reach the server.
A certificateRecommended: a TLS certificate and private key (PEM) for that name, from your own certificate authority. Otherwise the installer can generate a self-signed one.
Accurate timeNTP on the server and on every monitored host. Instructions older than 10 minutes are refused, so a drifting clock silently stops a host from acting.

Sizing the server

One server runs the whole stack in containers (PostgreSQL, Redis, the ClickHouse log store, the API and the console). CPU and RAM track the number of agents reporting and how many scans run at once; disk is driven mostly by log/SIEM retention and stored evidence. The installer warns and asks before continuing with less than 10 GB free. Treat the figures below as starting points and grow disk as your retention window grows.

EstateCPURAMFree disk
Evaluation / up to 10 hosts4 cores8 GB40 GB
Up to 50 hosts8 cores16 GB100 GB
Up to 200 hosts8-16 cores32 GB250 GB
200+ hosts16+ cores64 GB500 GB+

If you collect a lot of syslog or keep long log history, size disk for the log store first: a busy estate can generate tens of GB of logs per week. SSD storage is recommended for the database and log store.

STEP 2

Open the network

Monitored hosts connect out to the server; the server never connects in to them. Nothing needs to be opened on the hosts you monitor.

FromToPortWhy
Operators' browsersLawliet server443/tcpThe console, over HTTPS
Operators' browsersLawliet server80/tcpOptional: redirects to 443
Monitored hostsLawliet server443/tcpAgents report and fetch instructions
Server and hostsYour NTP servers123/udpClock synchronisation
Devices sending syslogLawliet server5514/udp 5514/tcpOnly if you collect logs

Keep the database private. PostgreSQL and Redis stay inside Docker and are never published. Do not open 5432 or 6379.

Using the lab mode (plain HTTP) instead

The installer offers plain HTTP on ports 3000 and 8000 for a laptop or a lab. It sends passwords and enrolment tokens in clear text, so do not use it on a real network. If you do: operators need both 3000/tcp and 8000/tcp (the page loads from 3000 and talks to 8000), and monitored hosts need 8000/tcp.

Optional features that need more

Network discovery probes the ranges you give it (TCP, plus UDP 137, 161, 1900, 5353 and ICMP). Firewall import reaches devices over SSH (22) or HTTPS (443). Emailed reports use SMTP (587). Single sign-on reaches your identity provider on 443. Open these only if you use the feature.

STEP 3

Install

Copy the bundle to the server, unpack it and run the installer. It checks the machine, asks five questions, generates every secret and starts the platform.

$ tar xzf lawliet-docker-*.tar.gz
$ cd lawliet-*/
$ ./lawliet install

What the installer asks

  1. Address

    The DNS name or IP address from step 1. It suggests the one it detects.

  2. How to serve it

    Choose 1, HTTPS on 443. Option 2 is the lab mode described above.

  3. Certificate

    Give the paths to your certificate (full chain, PEM) and private key, or let it generate a self-signed certificate. You can replace it later with ./lawliet tls.

  4. Administrator username

    admin unless you prefer another.

  5. Administrator password

    Let it generate a strong one, or type your own (at least 12 characters). This is a one-time password: you replace it at first sign-in.

It then shows a summary, asks for confirmation and starts. The first start builds the containers and takes several minutes. When it finishes it prints:

Copy the password now. You need it for the first sign-in. The folder you installed from is now your deployment: keep it, and run every later ./lawliet command from it.

STEP 4

First sign-in

Open the console address in a browser. The first sign-in has two short, required steps. Nothing else in the platform opens until both are done.

  1. Sign in with the one-time password

    If you used a self-signed certificate, the browser warns once. That is expected.

  2. Choose your own password

    At least 12 characters. Common and well-known passwords are refused. The one-time password stops working.

  3. Set up two-factor authentication

    Scan the QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password or any TOTP app), or type the key shown under it.

  4. Save the recovery codes

    Ten single-use codes that sign you in if you lose your phone. Copy or download them and keep them somewhere safe, such as your password manager. They are shown only once.

  5. Enter the 6-digit code from the app

    From now on every sign-in asks for a code. Next comes the activation screen, step 5.

STEP 5

Activate your licence

Your licence is issued for this installation and works on it alone. We need one thing from you to issue it: the installation fingerprint.

  1. Send us the fingerprint

    The installer printed it at the end. The activation screen you reach after the first sign-in shows it too, with Copy and Email it buttons, and the server shows it at any time:

    $ ./lawliet licence

    It is 32 characters, like 3f9a51c0d6e84b27a1f0c9d3e5b7c21e, and identifies this installation only: no host name, address or data. You can send it as soon as the installer finishes.

  2. Receive your licence key

    We reply with a key file. The key starts with LAWLIET-.

  3. Install it

    Paste the key on the activation screen and press Activate licence, or on the server:

    $ ./lawliet licence key-file

    The key is checked on the server before anything changes; nothing is sent anywhere. The platform opens straight away.

It stays with this installation. The licence survives restarts, updates and backup restores. A new server, or a reinstall that removes the data (./lawliet uninstall), is a new installation with a new fingerprint and needs a new licence: send us the new fingerprint.

If your bundle was delivered with a licence already inside it, there is no activation screen and you can skip this step.

STEP 6

Connect your hosts

A small agent on each server or workstation reports to Lawliet. The server prints ready-to-run install commands, with its own address and enrolment token filled in.

On the Lawliet server
$ ./lawliet token

Copy the command for each platform from its output and run it on the host you want to monitor. They look like this:

Linux (as root)
curl -sSL https://your-server/api/v1/agents/download/linux | sudo bash -s -- \
     --server https://your-server --token enrolment-token
Windows (PowerShell as Administrator)
Invoke-WebRequest https://your-server/api/v1/agents/download/windows -OutFile install.ps1
.\install.ps1 -Server https://your-server -Token enrolment-token
macOS
curl -sSL https://your-server/api/v1/agents/download/macos | sudo bash -s -- \
     --server https://your-server --token enrolment-token

Within a minute the host appears under Environment in the console. The same commands are available there from the Install agent button.

Using a self-signed certificate?

Each host has to trust it. Export it on the server and copy it to the host:

$ ./lawliet tls --export

This writes lawliet-server.pem. ./lawliet token then prints commands that include it (--cacert and --ca-cert on Linux and macOS, -CaCert on Windows).

Collecting logs from firewalls and servers (syslog)

Under Logs, Sources, add a syslog source on port 5514 (UDP or TCP), then point your devices at the server on that port. It is the port the server listens on; others are not reachable. Syslog carries no authentication, so restrict each source to the networks your devices are on.

Keep the enrolment token private

Anyone holding it can enrol a host. If it leaks, replace it with ./lawliet token --rotate. Hosts already connected are not affected.

STEP 7

Add your team

Create an account for each person under Settings, Users, and give each a role. Each new user goes through the same first sign-in: their own password, then two-factor.

Roles

Give people only what they need

Built-in roles cover administrators, analysts, auditors and viewers. Create your own under Settings, Access control, and adjust individual users if needed.

Dual control

Two people for critical actions

Assign the Left and Right Security Officer roles, and their critical actions (changing users, containment, remediation, firewall pushes) wait for the other officer to approve.

Requests waiting for a signature appear under Approvals. Which actions need one, and who approves whom, is set under Settings, Access control, Dual control.

STEP 8

Day-to-day care

Everything is done with ./lawliet from the deployment folder. ./lawliet help lists it all.

CommandWhat it does
./lawliet statusHealth, licence, version and how many hosts are connected
./lawliet backupA database backup into ./backups. The HTTPS setup also takes one daily on its own.
./lawliet restore fileRestore a backup, then restart. Asks before replacing anything.
./lawliet update new-bundleUpgrade to a newer bundle: takes a backup, installs beside the current one, verifies it
./lawliet restartRestart and wait until healthy. stop and start also exist; data is never touched.
./lawliet logs backend -fFollow a service's logs
./lawliet passwdReset the administrator password, for example if you are locked out
./lawliet tlsShow or replace the certificate
./lawliet licenceShow the licence and this installation's fingerprint. With a key: install a new licence.
./lawliet doctorCollect a diagnostics file for support. It holds no passwords and no data.

Updating

When you receive a new bundle, copy it to the server and run this from your current deployment folder:

$ ./lawliet update lawliet-docker-new-version.tar.gz

It backs up first and refuses to continue without a backup. It installs the new version in a folder next to the current one and brings your configuration across. From then on, run ./lawliet from the new folder. The old one is kept so you can go back.

Take a copy off the server. Copy ./backups and the .env file somewhere safe from time to time. .env holds the keys that protect stored data, and a backup cannot be restored without it.

STEP 9

Troubleshooting

Start with ./lawliet status, then ./lawliet logs backend -n 200.

The installer says a deployment already exists

Lawliet is already installed on this server under the same name. To add a second one beside it, install under its own name, and use the same variable for every later command in that folder:

$ COMPOSE_PROJECT_NAME=lawliet-staging ./lawliet install
The console does not load, or sign-in does nothing

Check 443/tcp is open from your desk to the server, and that you use the address given to the installer. In lab mode both 3000 and 8000 must be reachable. The platform's own health check:

$ curl -k https://your-server/health

It should answer with "status": "healthy".

A host never appears after installing the agent

In order of likelihood: the enrolment token is wrong (compare with ./lawliet token); the host does not trust a self-signed certificate (see step 6); the host cannot reach the server on 443; the host's clock is wrong. On Linux, journalctl -u lawliet-agent -f shows what the agent is doing.

A host is connected but commands never run

Almost always the clock. Instructions more than 10 minutes old are refused. Make sure NTP is running on the host and on the server.

I lost my phone

On the code screen choose Lost your phone? Use a recovery code and enter one of the codes you saved. Each works once. Then ask an administrator to reset your two-factor under Settings, Users; you set it up again on the new phone at your next sign-in. If the only administrator has neither phone nor codes, run ./lawliet passwd on the server: it sets a new password and can turn that account's two-factor off so it can be set up again.

The licence key is refused

"Bound to another installation": the key was issued for a different fingerprint. The message shows this installation's fingerprint; send us that one. "Issued before the licence in use": a newer licence is already installed, and nothing changed. Paste the whole key, starting with LAWLIET-, with no line breaks.

Moving to a new server

Install on the new server, restore your latest backup there (./lawliet restore file) and send us the new installation's fingerprint for a licence issued to it.

A module says it is not included in your licence

The screen shows what the module does. Contact us to add it. You will receive a new licence key; install it in either of two ways, and nothing needs reinstalling:

In the console, under Settings, Platform, Enter a new licence key. Or on the server, which checks the key before changing anything:

$ ./lawliet licence new-key-or-file

Asking for help

Run ./lawliet doctor and send us the file it writes, together with the build id shown by ./lawliet status. Both identify your installation exactly and contain no passwords or data.