Complete rewrite of the SOC dashboard using FastAPI + Jinja2 + htmx + Chart.js + Tailwind CSS. Replaces the old React/Vite frontend with server-rendered templates. Dashboard pages: - Overview: KPIs, timeline chart, threat distribution, top IPs - Detections: paginated/filterable anomaly table - Scores: ml_all_scores with AE error & XGB prob columns - Traffic: HTTP logs with method/host filters - IP Investigation: full deep-dive (scores, features, HTTP logs, classify) - Classification: SOC feedback form + history - Features: AI + thesis feature stats - Models: scoring stats + model metadata API: 9 JSON endpoints with parameterized queries, sort whitelists SQL fixes: - 05_aggregation_tables: add deduplicate_merge_projection_mode - 11_views: fix nested aggregate (argMax inside sum) - 12_thesis_features: remove invalid 'let' bindings, fix groupArrayIf type Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
ClickHouse Migrations — ja4-platform
Migration Order
Apply these files in numeric order against the ClickHouse server:
clickhouse-client --multiquery < 00_database.sql
clickhouse-client --multiquery < 01_raw_tables.sql
clickhouse-client --multiquery < 02_dictionaries.sql
clickhouse-client --multiquery < 03_anubis_tables.sql
clickhouse-client --multiquery < 04_mv_http_logs.sql
clickhouse-client --multiquery < 05_aggregation_tables.sql
clickhouse-client --multiquery < 06_ml_tables.sql
clickhouse-client --multiquery < 07_ai_features_view.sql
clickhouse-client --multiquery < 08_users.sql
clickhouse-client --multiquery < 09_audit_table.sql
File Descriptions
| File | Contents |
|---|---|
00_database.sql |
CREATE DATABASE |
01_raw_tables.sql |
http_logs_raw ingest table |
02_dictionaries.sql |
ASN geo dict, bot IP/JA4/network reference tables |
03_anubis_tables.sql |
Anubis crawler rule tables and dictionaries (UA, IP, ASN, country) |
04_mv_http_logs.sql |
Canonical http_logs target table + mv_http_logs materialized view with full Anubis enrichment |
05_aggregation_tables.sql |
agg_host_ip_ja4_1h, agg_header_fingerprint_1h + their MVs |
06_ml_tables.sql |
ml_detected_anomalies, ml_all_scores |
07_ai_features_view.sql |
view_ai_features_1h with Anubis enrichment |
08_users.sql |
ClickHouse users and grants |
09_audit_table.sql |
audit_logs table for SOC dashboard audit trail |
Prerequisites
Place CSV data files in /var/lib/clickhouse/user_files/:
iplocate-ip-to-asn.csv— IP-to-ASN mapping (from IPLocate)bot_ip.csv— Known bot IP prefixesbot_ja4.csv— Known bot JA4 fingerprintsasn_reputation.csv— ASN reputation labels
Notes
04_mv_http_logs.sqlis the canonical version of the MV, superseding the base version inservices/correlator/sql/init.sql. It includes full Anubis enrichment.- All migrations are idempotent (use
IF NOT EXISTS/IF EXISTS). - Anubis dictionary passwords in
03_anubis_tables.sqlmust be changed before production use.