Logpresso Graph

Download 110
Last updated Sep 29, 2026

Query Commands

Query Commands

Query commands load and browse the graph in bulk. The typical usage is piping query results from firewall, NAC, or scanner logs into the graph.

Note
Every set/remove batch command runs as a dry-run by default. Each row's _status field
shows the planned action, and _error explains any problem. Add the run=t option to
actually apply changes.

Generic Batch Commands

Work with every registered node/edge type. Input fields whose names match schema-defined attributes are stored along with the node or edge.

CommandInput fieldsPurpose
sonar-set-node-batchtype, value, display_name, source + per-type attributesUpsert nodes
sonar-set-edge-batchsrc_type, src_value, dst_type, dst_value, rel_type, source + edge attributesUpsert edges (missing nodes are created)
sonar-set-graph-batchsame as sonar-set-edge-batchAlias with identical behavior
sonar-remove-node-batchtype, valueDelete nodes (attributes and connected edges cascade)
sonar-remove-edge-batchsrc_type, src_value, dst_type, dst_value, rel_typeDelete edges
json "[{\"type\":\"malware\", \"value\":\"Emotet\", \"malware_types\":[\"trojan\",\"bot\"], \"is_family\":\"true\"}]"
| sonar-set-node-batch run=t
json "[{\"src_type\":\"campaign\", \"src_value\":\"Op-X\", \"dst_type\":\"threat-actor\", \"dst_value\":\"APT99\", \"rel_type\":\"attributed-to\", \"confidence\":80}]"
| sonar-set-edge-batch run=t

Validation Rules

Batch commands validate input against the schema; violating rows fail (in dry-run they are reported with _status=error and _error).

  • Unregistered type — unknown node type, unknown src_type, unknown rel_type
  • Undefined connection combination — each relationship declares its allowed source/target type pairs. For example, feeding user → cve into the serves relationship fails with unsupported combination.
  • Value format mismatch — types with a declared format validate their values. For example, a network-service value not in ip:port/tcp form fails with invalid value format.

Partial Updates

  • Nodes are matched by (type, value); existing ones are updated. Attributes you do not provide stay unchanged, so send only the fields you want to change.
  • Edges are matched by (source, target, relationship); existing ones only refresh last_seen.

Asset Graph Commands

Purpose-built commands for asset topology: one input row creates several nodes and edges at once.

CommandFieldsResult
sonar-set-ipv4-node-batchip (required), mac, hostname, user, zoneIP node + MAC/host/user/zone nodes with relationships
sonar-set-zone-node-batchname (required), display_name, cidrZone node
sonar-set-domain-node-batchdomain (required), ipDomain node (+ IP link)
sonar-set-cve-node-batchip, cve_id (required), cvss3_score, description, published, statusCVE node + has-vulnerability edge
sonar-set-cpe-node-batchcve_id, cpe (required)CPE node + affects edge

Each has a matching sonar-remove-*-node-batch.

json "[{\"ip\":\"10.0.1.1\", \"mac\":\"AA:BB:CC:DD:EE:FF\", \"hostname\":\"web01\", \"zone\":\"dmz\"}]"
| sonar-set-ipv4-node-batch run=t

Read Commands

CommandPurposeKey options
sonar-graph-nodesList nodestype, guid, value, min-risk, tag
sonar-graph-edgesList edgesguid, type, value, rel
sonar-graph-attrsList node attributesguid, type, value, attr
sonar-graph-node-defsRegistered node type definitions (names, attributes, value format)locale
sonar-graph-edge-defsRegistered relationship definitions (names, attributes, allowed pairs)locale
sonar-graph-buildersRegistered graph builders
sonar-graph-running-buildersCurrently running builders
sonar-graph-node-defs locale=ko

Builders

The app ships built-in builders that sync the employee and department roster into the graph every 30 minutes (employee nodes, department nodes, membership and lead edges). Check builder status with sonar-graph-builders. Other apps can register their own builders — see App Extension.