Documentation
Everything you need to install obserae, describe your network, and start investigating traffic by name. New here? Start with Installation, then the Quickstart.
Getting Started
Installation
Install with the one-line installer, Docker or binaries and get the daemon running.
Sizing
Work out the disk, memory and CPU your traffic and retention need.
Verify a Release
Check the signature, SBOM and provenance of a download before running it.
Configuring Exporters
Configure routers, firewalls and host probes to send NetFlow/IPFIX to obserae.
Quickstart
Build a tiny cartography, add rules, send traffic and run the first queries.
Configuration
Understand every YAML key and the practical tuning recipes.
Daily Use
Web GUI
Know what each screen is for and where to click next.
Authentication
Sign in with local accounts, LDAP or OIDC, and mint tokens for machines.
CLI
Automate admin tasks and recover access from the terminal.
REST API
Drive obserae from scripts over the HTTP API with a Bearer token (OpenAPI spec included).
API Reference
Interactive OpenAPI 3.1 reference for every obserae REST endpoint.
Cartography
Describe networks, hosts, groups and services by name.
Sessions
Understand the bidirectional conversations built from raw flows.
NAT
Declare what your firewalls translate so the flow matrix reports the real conversation.
NFQL
Query flows, sessions, enrichment and rule matches, with typed arithmetic, explicit missing-value predicates, and time or numeric range buckets.
NFQL Cookbook
Copy explained SOC patterns spanning traffic, assets, enrichment, NAT, detections and dashboard-ready aggregations into Investigation.
Dashboards
Map typed NFQL fields explicitly to chart axes, values and series, use live saved queries, edit a responsive canvas through protected resource-scoped sessions, then publish stable read-only views.
Detection Rules
Model allowed connectivity and inspect what matched.
Rule Sets
Manage local vocabulary, import packaged rules, and keep them up to date.
Writing Rule Sets
Author your own rule set, from the YAML up.
Community Rule Set
What the shipped community set covers, rule by rule.
Alerting
Turn saved NFQL queries into alerts.
Anomaly Detection
Explainable self-learning rules with separate model/policy decisions, historical validation and safe lifecycle.
Assistant
Ask obserae questions in plain language, and let it make confirmed changes.
Outputs
Send alerts to chat, on-call, webhooks, syslog/SIEM or search platforms — with a documented, machine-readable payload a SOAR can map without guesswork.
Connectors
Understand flow exporters, device connectors, enrichment sources and alert outputs.
IP Enrichment
Use cloud, threat-intel, GeoIP and ASN ranges in queries.
Reports
Produce operations and compliance documents on demand or on a schedule.
Lifecycle
Manage retention, storage and backups.
Monitoring
Watch ingestion throughput, pipeline saturation, memory and DB activity.