Logpresso Graph

Download 110
Last updated Sep 29, 2026

Network Topology

Network Topology

A visualization that lays out network zones and IPs on isometric 3D platforms and replays detection event flows in time order.

  • Platforms (boxes) are zones, and the dots on them are IPs.
  • Zone type determines color and row placement — internet (red, top) → dmz (orange) → office (blue) → server_farm (green) → unclassified (gray, bottom).
  • IP node color darkens from yellow to red with the risk level (number of distinct rules) in the selected range.
  • Drag to pan and scroll to zoom.

Building Zones

A zone is a zone-type node in the knowledge graph. IPs land on a zone platform by these rules, in order:

  1. Explicit membership — a belongs-to edge from ipv4-addr to zone places the IP on that zone.
  2. Automatic CIDR assignment — set the zone node's cidr attribute (e.g. 10.0.1.0/24; multiple ranges separated by commas) and IPs in that range are placed on the zone automatically, without belongs-to edges. When ranges of several zones overlap, the narrowest range (longest prefix) wins.
  3. Automatic grouping — IPs that belong to no zone are grouped into ad-hoc platforms: private addresses by /24, public addresses by ASN (or /24).
json "[{\"name\":\"dmz\", \"cidr\":\"10.0.1.0/24\"}]" | sonar-set-zone-node-batch run=t

Zone name, type, and CIDR can also be edited as zone node properties in the Knowledge Graph screen.

Time Range

Select the event window at the top right — 10 minutes / 1 hour / 6 hours / 12 hours / 24 hours. The default is 1 hour, and the last selection is remembered in the browser. The timeline's aggregation interval adjusts with the range (10 seconds for the 10-minute range up to 10 minutes for the 24-hour range).

Event Replay and Timeline

Detection events are drawn as arcs flying from the source IP to the destination IP. Arc color is the event priority (HIGH red / MEDIUM orange / LOW yellow tones).

Arcs replay in their actual order of occurrence. The timeline at the bottom of the screen shows the replay state.

  • A histogram of event counts per interval (colored by the highest priority in the bucket).
  • A vertical playhead marking the moment currently being replayed, with the time shown next to it.
  • Click or drag on the timeline to seek to a moment.
  • The button on the left toggles play/pause.

Node Details

Click an IP node to open the detail panel on the right; the replay pauses and the events involving that IP are shown as static arrows.

  • Assigned employees — connected via assigned-to edges.
  • Logged-in users — connected via logged-in edges.
  • Events — recent detection events for the IP. Hovering an item highlights its arc.

Click empty space to deselect and resume the replay.

Note
The topology skeleton (zones, IPs, membership) comes from graph data; the arcs come from
detection events. To place IPs on zones, create belongs-to edges or set the zone's cidr
attribute.

See Query Commands for populating the skeleton from firewall or NAC logs.