LawlietLAWLIET
Book a demo

Operations and updates

Everything is done with ./lawliet from the deployment folder. ./lawliet help lists it all.

Day-to-day commands

CommandWhat it does
./lawliet statusHealth, licence, version and connected hosts
./lawliet backupA database backup into ./backups. HTTPS installations also take one daily.
./lawliet restore <file>Restores a backup and restarts. Asks before replacing anything.
./lawliet update <bundle>Upgrades to a newer bundle. See below.
./lawliet restartRestarts and waits until healthy. Data is never touched.
./lawliet logs backend -fFollows a service's logs
./lawliet passwdResets the administrator password
./lawliet tlsShows or replaces the certificate
./lawliet licenceShows the licence and the installation fingerprint, or installs a key
./lawliet tokenPrints the agent install commands
./lawliet doctorCollects a diagnostics file for support, with no passwords and no data

Updates

Updates arrive as a new signed bundle. Copy it to the server and, from the current deployment folder:

./lawliet update lawliet-docker-<version>-<organisation>.tar.gz

It backs up the database first and stops if the backup fails, installs the new version beside the current one, runs the database migrations, and checks the schema and version before it finishes. Your licence and settings carry over.

Retention

Each kind of record has its own retention period, and 0 keeps it forever. The defaults are 180 days for file integrity events, 365 days for data loss prevention incidents, and 730 days for compliance results and the audit trail.

Receiving syslog

Point network devices and servers at the Lawliet server on port 5514, UDP or TCP. Accepted formats are RFC 5424, RFC 3164, CEF, LEEF and JSON.

Forwarding to your SIEM

Lawliet can forward events as CEF, LEEF, RFC 5424 or JSON, over syslog (UDP, TCP or TLS) or HTTPS. HTTPS forwarding works with Splunk HEC, Microsoft Sentinel and Sumo Logic.