Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Install Guide

What you need before installing

Logpresso Forensic is where an incident responder uploads collected evidence and takes it apart. The evidence files live in the file store, and loading and detection run as background jobs. The app alone is therefore not enough — three things have to be in place.

Note
- The **File Store app** must already be installed. That is where evidence archives are kept.
- The company needs **at least one cluster administrator account**. Loading and detection run as
that account.
- Without the `forensic` feature in the license, you can create **only one project**.

Work through the steps in order.

1. Install the file store

Install Logpresso File Store from the app store.

Evidence archives are stored encrypted in the file store and fetched into a work directory when an import runs. Without it, evidence upload fails outright, so install it before this app.

2. Install the app

Install Logpresso Forensic from the app store.

When it finishes, the left menu shows Projects, Events, Artifacts, File System, Registry, Logs and Administration. On first start the app prepares itself:

  • Evidence type and artifact extraction rule definitions are seeded into the database
  • The bundled TTP detection rules are registered per company
  • The tables and schemas an investigation needs are created

You can tell it is ready when Administration → Evidence Types and Administration → Artifact Extraction Rules list entries.

3. Check the license

How many projects you may create is decided by the license.

LicenseProjects
Includes the forensic featureUnlimited
Does notOne

When the limit is reached, a banner appears above the Projects list and the Add button is disabled. Deleting an existing project frees the slot.

4. Prepare the execution account

Evidence loading and TTP detection do not run as the user who asked for them. They run as a cluster administrator of the same company, because writing to the app's own tables requires that privilege. When there is more than one, the oldest account is used.

Check under System → Accounts that the company has at least one cluster administrator. Without one, loading fails with:

no cluster administrator in this company to run the import as; grant one and retry

5. Verify the installation

Running one investigation end to end tells you more than any single check.

  1. Create a project under Projects → Add and save it
  2. Open it and use Register Evidence File to give a host name and an evidence archive
  3. Once the upload finishes, check the evidence row and start Import
  4. Wait for the import to reach 100%; detection then runs by itself
  5. Open Artifacts, select the project and host, and search — the extracted artifacts appear

Evidence must be a ZIP archive. The ZIP signature is checked before the upload is opened, so anything else is refused before a file is written.

Troubleshooting

SymptomCauseWhat to do
Upload never startsFile store app not installedInstall the file store and restart the app
not a zip file (missing PK magic)The file is not a ZIPRepackage the evidence as a ZIP and upload again
no cluster administrator in this companyThe company has noneGrant cluster administrator to one account in that company
The Add button on Projects is disabledLicense limit reachedDelete a project, or check the license
no known evidence files in zipNothing in the archive is recognizedCompare what you collected against Administration → Evidence Types
Import finished but no artifactsThe time range excludes the evidenceWiden the range in the top filter and search again

With the installation done, see the User Guide for how an investigation runs.