Operations and updates
Everything is done with ./lawliet from the deployment folder. ./lawliet help lists it all.
Day-to-day commands
| Command | What it does |
|---|---|
./lawliet status | Health, licence, version and connected hosts |
./lawliet backup | A database backup into ./backups. HTTPS installations also take one daily. |
./lawliet restore <file> | Restores a backup and restarts. Asks before replacing anything. |
./lawliet update <bundle> | Upgrades to a newer bundle. See below. |
./lawliet restart | Restarts and waits until healthy. Data is never touched. |
./lawliet logs backend -f | Follows a service's logs |
./lawliet passwd | Resets the administrator password |
./lawliet tls | Shows or replaces the certificate |
./lawliet licence | Shows the licence and the installation fingerprint, or installs a key |
./lawliet token | Prints the agent install commands |
./lawliet doctor | Collects a diagnostics file for support, with no passwords and no data |
Updates
Updates arrive as a new signed bundle. Copy it to the server and, from the current deployment folder:
./lawliet update lawliet-docker-<version>-<organisation>.tar.gz
It backs up the database first and stops if the backup fails, installs the new version beside the current one, runs the database migrations, and checks the schema and version before it finishes. Your licence and settings carry over.
Retention
Each kind of record has its own retention period, and 0 keeps it forever. The defaults are 180 days for file integrity events, 365 days for data loss prevention incidents, and 730 days for compliance results and the audit trail.
Receiving syslog
Point network devices and servers at the Lawliet server on port 5514, UDP or TCP. Accepted formats are RFC 5424, RFC 3164, CEF, LEEF and JSON.
Forwarding to your SIEM
Lawliet can forward events as CEF, LEEF, RFC 5424 or JSON, over syslog (UDP, TCP or TLS) or HTTPS. HTTPS forwarding works with Splunk HEC, Microsoft Sentinel and Sumo Logic.

