Logpresso Graph

Download 110
Last updated Sep 29, 2026

User Guide

Overview

Logpresso Graph accumulates security entities — IP addresses, hosts, domains, vulnerabilities, employees, and threat intelligence objects — as a graph of nodes and relationships (edges), and visualizes it through threat analysis screens. Fragments collected from firewalls, NAC, scanners, and other sources come together in a single graph, so you can trace in one place "which zone and host does this IP belong to, who is it assigned to, and what vulnerabilities and attack history does it have?"

Data Model

  • Node: an entity identified by a (type, value) pair. Examples: 10.0.1.5 of type ipv4-addr, CVE-2024-1234 of type cve. About 30 types ship out of the box, covering asset types (IPv4 address, domain, host), STIX-based threat intelligence types (threat actor, malware, attack pattern, and so on), and organizational types (employee, department).
  • Edge: a directed relationship between two nodes. Examples: belongs-to from ipv4-addr to zone, has-vulnerability from ipv4-addr to cve. Allowed source/target combinations are declared in the schema, so only defined relationships can be created.
  • Attributes: type-specific extra information on nodes and edges, such as the CVSS score of a cve node or the CIDR range of a zone node.

Menus

MenuDescriptionManual
Threat IntelPeriod-based threat summary and intel cards per asset, employee, and departmentThreat Intel
Attack GraphAnalysis screen that explores detection events as an IP relationship graphAttack Graph
Knowledge GraphManagement screen for browsing and editing nodes and edges directlyKnowledge Graph
Network TopologyVisualization that lays out zones/IPs and replays event flowsNetwork Topology

Four Ways to Populate the Graph

  1. Manual entry — add nodes and connections in the Knowledge Graph screen for small amounts of data.
  2. Query commands — bulk-load query results with batch commands such as sonar-set-node-batch and sonar-set-edge-batch. See Query Commands.
  3. Built-in builders — the app automatically syncs the employee and department roster into the graph every 30 minutes (check with the sonar-graph-builders command).
  4. App extensions — other apps can register graph schema and threat intel tabs. For example, installing the Genian NAC app automatically adds NAC Node / CVE / Open Ports tabs to threat intel cards. See App Extension.
Note
The Threat Intel and Attack Graph screens query Sonar detection events, so detection rules
must be running for data to appear. Network Topology and Knowledge Graph use the nodes and
edges loaded into the graph.