The applications on this page are not installed by default. The default set is covered on the applications page. The procedures for installing and removing applications are in the administration section.
Available options
The following applications are commonly added to a LARK. Each layers onto the default stack rather than replacing any part of it.RunReveal: SIEM and log correlation
RunReveal: SIEM and log correlation
RunReveal aggregates logs and alerts from across the appliance, correlates them, and applies detection rules. When present, it serves as the central point for searching and correlating collected data. Without it, the underlying data is still captured and stored by the default applications; RunReveal adds the correlation and search layer.
Grafana: dashboards and visualization
Grafana: dashboards and visualization
Grafana provides dashboards for visualizing data held on the appliance, supporting the identification of patterns and trends and the monitoring of activity over time. It reads from the appliance’s stored data and presents it visually.
Nessus: vulnerability scanning
Nessus: vulnerability scanning
Nessus performs active vulnerability scans against hosts on a network. In contrast to the passive monitoring the appliance performs by default, Nessus actively assesses systems, and is used where active vulnerability assessment is required alongside passive observation.
Tracecat: security automation and case work
Tracecat: security automation and case work
Tracecat provides automation workflows and case management for investigations, with an AI assistant that operates from the case record. It can run automated playbooks in response to activity and provides analysts a single timeline to work from. When present, it serves as the system of record for investigation work.