Docbook: Add a Logwolf quick start.

This commit is contained in:
Gerald Combs 2022-02-24 11:10:04 -08:00
parent 5d3ffe9b57
commit 5c769757ff
1 changed files with 56 additions and 0 deletions

View File

@ -0,0 +1,56 @@
= Logwolf Quick Start
Logwolf is a sibling application for Wireshark which focuses on log messages. It helps people understand, troubleshoot, and secure their systems via log messagess similar to the way Wireshark helps people understand, troubleshoot, and secure their networks via packets.
This document provides brief instructions for building Logwolf until more complete documentation comparable to the Wireshark Developers and Users Guides can be written.
== Building Logwolf
Logwolf requires the same build environment as Wireshark.
See the https://www.wireshark.org/docs/wsdg_html_chunked/[Wireshark Developers Guide] for instructions on setting that up.
It additonally requires libsinsp and libscap from https://github.com/falcosecurity/libs/[falcosecurity/libs] and any desired plugins from https://github.com/falcosecurity/plugins/[falcosecurity/plugins].
In order to build Logwolf, do the following:
1. https://falco.org/docs/getting-started/source/[Build falcosecurity/libs].
2. Build falcosecurity/plugins.
3. Build the Wireshark sources with the following CMake options:
+
--
[horizontal]
BUILD_logwolf:: Must be enabled, e.g. set to ON
SINSP_INCLUDEDIR:: The path to your local falcosecurity/libs directory
SINSP_LIBDIR:: The path to your falcosecurity/libs build directory
--
4. Create a directory named `sysdig` in you Logwolf plugins directory, and either copy in or symlink any desired Falco plugins.
.Example 1: Building on macOS using Ninja
[sh]
----
cmake -G Ninja \
-DBUILD_logwolf=ON \
-DSINSP_INCLUDEDIR=/path/to/falcosecurity/libs \
-DSINSP_LIBDIR=/path/to/falcosecurity/libs/build \
..
ninja
mkdir run/Logwolf.app/Contents/PlugIns/sysdig
(cd run/Logwolf.app/Contents/PlugIns/sysdig ; ln -sn /path/to/falcosecurity-plugins/plugins/cloudtrail/libcloudtrail.so )
----
.Example 2: Building on Linux using Make
[sh]
----
cmake \
-DBUILD_logwolf=ON \
-DSINSP_INCLUDEDIR=/path/to/falcosecurity/libs \
-DSINSP_LIBDIR=/path/to/falcosecurity/libs/build \
..
make -j $(getconf _NPROCESSORS_ONLN)
mkdir run/plugins/sysdig
(cd run/plugins/sysdig ; ln -sn /path/to/falcosecurity-plugins/plugins/cloudtrail/libcloudtrail.so )
----