Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Events

Events

An event is something a TTP detection rule found in the loaded evidence — the records it matched, collected into one thing a person can read.

Searching

Pick the project and host in the filter bar and search. Nothing is returned until a host is selected.

ColumnWhat it shows
PriorityThe rule's severity. Three bars is high, two medium, one low
First seen · Last seenThe time span of the records this event was cut from
Project · Host · ImageWhich case, which host, which piece of evidence it came from
MessageThe rule's message template with the actual values filled in
RuleThe rule that produced it

The time filter is compared against the event's own span. An event whose span falls outside the range drops out of the list, so widen the range if what you are looking for is missing. Events with no usable timestamp are always shown, regardless of the range.

The evidence panel

Click a row and the Evidence panel opens below it: the records the event was cut from, with their original fields.

Values are written out as field=value pairs that wrap, and nothing is abbreviated. Which fields a rule emits differs from rule to rule, so fixed columns cannot hold them — and truncating would hide the value you need in order to judge.

Note
A detection is a starting point, not a conclusion. Read the evidence, decide whether it is normal
behavior, then move to Artifacts and see what was happening around that time.

How records are grouped into an event

The field names in the rule's message template are what the grouping is keyed on.

If the template reads $computer$ raised $event_id$, the rule's result is sorted by those two fields and a new event is cut wherever the combination changes. A hundred records of the same event id on the same computer are therefore one event with a hundred records of evidence behind it.

A template with no fields at all collapses everything the rule matched into a single event.

This is why how you write the template decides how readable the results are. See Administration for the details.

Looking around a moment

Right-click a first-seen or last-seen cell for Search ±10 minutes. It sets the time range to that instant plus and minus ten minutes and searches again, which is the quickest way to see what surrounded a detection.

The range is shared, so moving to Artifacts or Logs from there shows you the same window from a different angle.

Running detection again

Detection runs by itself when loading finishes. Run it by hand when:

  • you have added or edited a rule
  • you want to rerun only some of them

Go to Administration → TTP Detection Rules, check the rules to run, and click Scan. With nothing checked, every enabled rule runs. Choose a project and an image in the dialog, and progress is shown as it goes.

Note
Scanning the same image again **accumulates**. Previous results are not cleared, so running the
same rule twice leaves two copies of the same event. Re-importing the evidence is different — the
tables are recreated, so the events are cleared with them.

Next: digging into the evidence, in Artifacts.