User Guide
Overview
Logpresso Graph accumulates security entities — IP addresses, hosts, domains, vulnerabilities, employees, and threat intelligence objects — as a graph of nodes and relationships (edges), and visualizes it through threat analysis screens. Fragments collected from firewalls, NAC, scanners, and other sources come together in a single graph, so you can trace in one place "which zone and host does this IP belong to, who is it assigned to, and what vulnerabilities and attack history does it have?"
Data Model
- Node: an entity identified by a
(type, value)pair. Examples:10.0.1.5of typeipv4-addr,CVE-2024-1234of typecve. About 30 types ship out of the box, covering asset types (IPv4 address, domain, host), STIX-based threat intelligence types (threat actor, malware, attack pattern, and so on), and organizational types (employee, department). - Edge: a directed relationship between two nodes. Examples:
belongs-tofromipv4-addrtozone,has-vulnerabilityfromipv4-addrtocve. Allowed source/target combinations are declared in the schema, so only defined relationships can be created. - Attributes: type-specific extra information on nodes and edges, such as the CVSS score
of a
cvenode or the CIDR range of azonenode.
Menus
| Menu | Description | Manual |
|---|---|---|
| Threat Intel | Period-based threat summary and intel cards per asset, employee, and department | Threat Intel |
| Attack Graph | Analysis screen that explores detection events as an IP relationship graph | Attack Graph |
| Knowledge Graph | Management screen for browsing and editing nodes and edges directly | Knowledge Graph |
| Network Topology | Visualization that lays out zones/IPs and replays event flows | Network Topology |
Four Ways to Populate the Graph
- Manual entry — add nodes and connections in the Knowledge Graph screen for small amounts of data.
- Query commands — bulk-load query results with batch commands such as
sonar-set-node-batchandsonar-set-edge-batch. See Query Commands. - Built-in builders — the app automatically syncs the employee and department roster
into the graph every 30 minutes (check with the
sonar-graph-builderscommand). - App extensions — other apps can register graph schema and threat intel tabs. For example, installing the Genian NAC app automatically adds NAC Node / CVE / Open Ports tabs to threat intel cards. See App Extension.
Note
The Threat Intel and Attack Graph screens query Sonar detection events, so detection rules
must be running for data to appear. Network Topology and Knowledge Graph use the nodes and
edges loaded into the graph.
must be running for data to appear. Network Topology and Knowledge Graph use the nodes and
edges loaded into the graph.