Sprint Log Parser Logo Sprint Log Parser
Docs / Getting Started / Workspace Setup

Workspace Setup

Configure multi-tenant isolated projects, invite developers, manage access tokens, and customize server alert load thresholds.

1. Workspace Concepts

In Sprint Log Parser, all telemetry logs, agents, firewalls, and configurations are securely isolated inside **Workspaces** (Projects). Workspaces function as independent secure containers, meaning logs ingested into Project A are completely invisible to users in Project B.


2. Create & Toggle Workspaces

You can own multiple workspaces and collaborate on external projects simultaneously. To manage workspaces:

  • Creation: Visit the Projects Panel and click **Create Project**. Provide a unique name and optional descriptions.
  • Active Toggling: Use the workspace dropdown selector in the top navbar to instantly shift context. All dashboard charts, threats table, and settings will refresh for the selected active project.

3. Team Management & Collaboration

Workspace owners can invite other registered developers to join their workspace:

  • Sending Invitations: Navigate to workspace settings, enter the invitee's email address, and click **Invite**. An invite link is generated immediately.
  • Accepting Invites: The invitee can open the secure activation URL to accept membership and join the workspace.
  • Revoking Membership: Owners can instantly revoke member privileges by clicking **Remove** beside the user's name in the active members list.

4. Host Alerting Thresholds

Each workspace monitors active servers shipping telemetry. By default, host warning flags trigger when a server reports a CPU usage load exceeding 90%. Owners can customize this alerting threshold to avoid false alarms:

Adjusting CPU thresholds:

1. Go to the dashboard **Host Settings** panel.
2. Enter your custom CPU Alert threshold percentage (e.g. 95% for heavy load grids).
3. Save configurations. The alerting engine will evaluate inbound telemetry payload rules against this updated threshold.


5. Alert Recipient Emails

Manage where threat digests and load warning alerts are routed. Under Project Settings, you can configure multiple comma-separated email recipients:

alert_email_recipient: "ops-alerts@company.com, security-triage@company.com"

6. Log Ingestion IP Whitelisting

To protect your workspace against API token hijacking or rogue log injection, Sprint Log Parser allows workspace administrators to configure strict **Log Ingestion IP Whitelists**:

🛡️ IP Whitelist Rules & Formats

  • Default Behavior (Empty Whitelist): Log ingestion requests to /api/projects/ingest are allowed from any IP address.
  • Exact IPv4 & IPv6 Addresses: Enter single server IPs, e.g. 192.168.1.100 or 2001:db8::1.
  • CIDR Subnet Ranges: Support for IPv4 and IPv6 CIDR subnet masks, e.g. 10.0.0.0/24 or 2001:db8:abcd::/48.
  • Automated Security Auditing: Requests originating from unlisted IP addresses are rejected with HTTP 403 Forbidden and generate a compliance audit log entry in WorkspaceAuditLog.
// Example Workspace Whitelist Configuration (One IP/CIDR per line):
192.168.1.50
10.0.0.0/24
2001:db8::1
2001:db8:abcd::/48

7. 1-Click API Token Rotation

If an ingestion token is exposed or compromised, workspace administrators can instantly revoke and regenerate the token with **1-Click API Token Rotation**:

🔄 Token Rotation Lifecycle

  • Instant Invalidation: Clicking 🔄 Rotate in the workspace settings or live tailing modal immediately revokes the existing 40-character token and assigns a new cryptographically secure key.
  • Zero Downtime Migration: Shipper agents attempting to post logs with the old token receive an HTTP 401 Unauthorized response until updated with the new token command.
  • Compliance Audit Trail: Every token rotation event is recorded in WorkspaceAuditLog with event action api_token.rotated.

8. Multi-Factor Authentication (TOTP 2FA)

Harden your workspace administration and Sudo Mode controls with **Time-based One-Time Password (TOTP) 2FA** compatible with Google Authenticator, Authy, 1Password, and YubiKey TOTP apps:

🔐 2FA Key Setup & Sudo Mode Enforcement

  • RFC 6238 Standard Compliance: 16-character Base32 secret keys and 6-digit dynamic TOTP codes refreshed every 30 seconds.
  • Sudo Mode Protection: When 2FA is active, updating critical Sudo Mode thresholds, IP blocklists, or security configurations requires valid 6-digit TOTP verification.
  • Emergency Recovery Codes: Generates 8 single-use 8-character recovery codes upon initial setup for emergency access recovery.

📱 How to Enable 2FA on Your Workspace Account:

  1. Open the Sudo Mode Dashboard (/sudomode) or Workspace Management (/projects).
  2. In the 🔐 Multi-Factor Authentication (TOTP 2FA) security card, click Enable 2FA Protection.
  3. Scan the generated QR code using your authenticator app (Google Authenticator, Authy, 1Password, or YubiKey) or enter the 16-character Base32 secret key manually.
  4. Enter the dynamic 6-digit verification code from your authenticator app and click Activate 2FA.
  5. To disable 2FA, click Disable 2FA and confirm your account password alongside a valid 6-digit TOTP code.