diff --git a/README.md b/README.md index aa52f6e..b2c0c16 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,8 @@ # SignalScope -SignalScope is a local multi-stream security log correlation and anomaly detection agent. It ingests FortiGate, Graylog MCP streams, DNS, Windows, proxy, Nginx, VPN, and infrastructure events through a common model, then builds baselines and correlation evidence. +SignalScope is a local multi-source security analytics agent. Its primary mode connects to Graylog through MCP, discovers the streams and fields already available in your environment, and uses stream profiles to normalize events, build baselines, correlate entities, and explain anomalies with a local LLM. + +FortiGate is one supported example. The same workflow applies to DNS/AdGuard, Windows Event Logs, Sysmon, Nginx, Squid, VPN, Proxmox, Filebeat-collected logs, and future Graylog streams. The Python module and legacy `fgai` command remain available for compatibility. New installations can use `signalscope`. @@ -25,15 +27,17 @@ Or use the helper script, which creates/uses `.venv` automatically and runs `pip `./start.sh` starts three local background processes: -- UDP syslog listener writing `logs/fg_syslog.jsonl` +- Optional UDP syslog listener writing `logs/fg_syslog.jsonl` - Continuous monitor writing `state/fgai-status.json` - Local dashboard at `http://127.0.0.1:8088` -## Graylog MCP +## Primary Workflow: Graylog MCP -Graylog 7.1 MCP can be used as the active log source instead of the local JSONL -listener. In the dashboard, open `Settings`, select `Graylog MCP`, provide the -MCP URL and a read-only API token, then load and enable the streams to analyze. +Graylog 7.1 MCP is the primary log-source integration. In the dashboard, open +`Settings`, select `Graylog MCP`, provide the MCP URL and a read-only API token, +then load and enable the streams to analyze. SignalScope uses MCP `list_streams`, +`list_fields`, `search_messages`, and `aggregate_messages` to work with existing +log sources rather than requiring every source to be forwarded locally. The token field accepts a raw Graylog API token, the Base64 value after `Basic `, or a complete `Basic ` header. Tokens are stored only in the local runtime @@ -44,9 +48,11 @@ Graylog datatype/capability metadata and lets you select an entity field, a time field, and categorical/numeric fields for the stream profile. Profiles are stored under `graylog_stream_profiles` in `state/fgai-config.json`. -Enabled streams are normalized through the same event model. The dashboard and -Ollama correlate source IPs that occur across two or more streams, for example -FortiGate, AdGuard/DNS, Windows Security, Nginx, Squid, VPN, or Proxmox. +Enabled streams are normalized through the same event model. Stream profiles +define the entity, timestamp, categorical, and numeric fields used for baselines. +The dashboard and Ollama then correlate behavior across sources, for example a +client IP appearing in FortiGate, AdGuard/DNS, Windows Security, Nginx, Squid, +VPN, or Proxmox. The current MCP endpoint is `http://:9000/api/mcp`. Enable it in Graylog under `System -> Configurations -> MCP` and use stream IDs internally; @@ -213,7 +219,7 @@ For slower machines or large models: OLLAMA_MODEL=llama3.1 OLLAMA_TIMEOUT=300 fgai analyze-logs --logs logs/fg_syslog.jsonl --llm ``` -## FortiGate Inputs +## Optional FortiGate Input For logs, configure FortiGate syslog to write into a local file such as `logs/fg_syslog.jsonl`. The parser supports common key/value syslog lines and JSONL.