Install Guide
What you need before installing
Logpresso Forensic is where an incident responder uploads collected evidence and takes it apart. The evidence files live in the file store, and loading and detection run as background jobs. The app alone is therefore not enough — three things have to be in place.
- The company needs **at least one cluster administrator account**. Loading and detection run as
that account.
- Without the `forensic` feature in the license, you can create **only one project**.
Work through the steps in order.
1. Install the file store
Install Logpresso File Store from the app store.
Evidence archives are stored encrypted in the file store and fetched into a work directory when an import runs. Without it, evidence upload fails outright, so install it before this app.
2. Install the app
Install Logpresso Forensic from the app store.
When it finishes, the left menu shows Projects, Events, Artifacts, File System, Registry, Logs and Administration. On first start the app prepares itself:
- Evidence type and artifact extraction rule definitions are seeded into the database
- The bundled TTP detection rules are registered per company
- The tables and schemas an investigation needs are created
You can tell it is ready when Administration → Evidence Types and Administration → Artifact Extraction Rules list entries.
3. Check the license
How many projects you may create is decided by the license.
| License | Projects |
|---|---|
Includes the forensic feature | Unlimited |
| Does not | One |
When the limit is reached, a banner appears above the Projects list and the Add button is disabled. Deleting an existing project frees the slot.
4. Prepare the execution account
Evidence loading and TTP detection do not run as the user who asked for them. They run as a cluster administrator of the same company, because writing to the app's own tables requires that privilege. When there is more than one, the oldest account is used.
Check under System → Accounts that the company has at least one cluster administrator. Without one, loading fails with:
5. Verify the installation
Running one investigation end to end tells you more than any single check.
- Create a project under Projects → Add and save it
- Open it and use Register Evidence File to give a host name and an evidence archive
- Once the upload finishes, check the evidence row and start Import
- Wait for the import to reach 100%; detection then runs by itself
- Open Artifacts, select the project and host, and search — the extracted artifacts appear
Evidence must be a ZIP archive. The ZIP signature is checked before the upload is opened, so anything else is refused before a file is written.
Troubleshooting
| Symptom | Cause | What to do |
|---|---|---|
| Upload never starts | File store app not installed | Install the file store and restart the app |
not a zip file (missing PK magic) | The file is not a ZIP | Repackage the evidence as a ZIP and upload again |
no cluster administrator in this company | The company has none | Grant cluster administrator to one account in that company |
| The Add button on Projects is disabled | License limit reached | Delete a project, or check the license |
no known evidence files in zip | Nothing in the archive is recognized | Compare what you collected against Administration → Evidence Types |
| Import finished but no artifacts | The time range excludes the evidence | Widen the range in the top filter and search again |
With the installation done, see the User Guide for how an investigation runs.