Start over is the last card in the panel’s Settings. It deletes both Loghound indexes from your Opensolr account, with every document in them, removes this installation’s configuration and sends you back to the installer. Nothing is kept.
Every hit and every session Loghound has recorded is deleted, and there is no undo. The only way to keep the data is a backup of the two indexes in Opensolr, taken before you press the button.
Want to set Loghound up again on the same data? Use the shell command loghound-setup --reset instead: it keeps both indexes and everything in them. The command reference explains it.
- Stop ingestion first. Recommended, not required: while the run deletes the indexes, the reader keeps trying to write to them and fills your log with errors.
sudo systemctl stop loghound-tail.service loghound-score.timer loghound-retention.timer
- Open Settings in the panel and go to the last card, Start the installation over. Read the list of what happens to each thing.
- If two-factor is on, type the code from your app into Code from your authenticator.
- Type
DELETE EVERYTHINGinto the confirmation field. Upper or lower case both work. - Press Delete everything and start setup and leave the tab open while the steps run.
- You land on the installer. Your confirmation counts as proof of who you are, so for the next half hour this browser is not asked for the setup token. Set Loghound up again, then start the units you stopped in step 1.
The confirmation is held in your browser session for fifteen minutes and is used up the moment the run starts, so a page reload never starts a second run. If the run stops half way, confirm again: nothing on this machine is removed until both indexes are proven gone, so running it again from the start is safe.
- Proves your account owns these indexes. Only the two names this installation created are touched, and only after the platform’s own index list confirms your account holds them.
- Deletes the two Loghound indexes from your Opensolr account.
- Confirms they are gone by reading your account’s index list again.
- Deletes the credentials and local data under
var/. - Removes the configuration and reports what was not removed. Then the installer opens.
- Both Loghound indexes and every document in them. Opensolr index names are unique across the whole platform and are never released, so neither name can be created again. Setup makes a new pair under a new installation id.
- Your Opensolr account details in Loghound: the email, the API key and the region. Setup asks for them again.
- The configuration file, with the beacon signing key, the address salt and your panel password in it. Overwriting a file is not a guarantee on every disk, so treat the API key as exposed and rotate it in your Opensolr account.
- The sign-in: username, password, two-factor and its recovery codes. Every browser that stayed signed in is signed out, this one included.
- The chosen log files and their formats are forgotten. Setup scans for them again.
- Everything under
var/: the local state database, the reader’s position in each log, open sessions, saved checks and sign-in records. When ingestion starts again each log is read from its end, so nothing already on disk is replayed. - The beacon signing key. Tokens already in visitors’ browsers stop validating, and until each browser gets a fresh one the scorer reads the old token as a bot signal. This sorts itself out on each visitor’s next visit.
- Everything else on your Opensolr account. Only the two names this installation created are deleted.
- Your access log files. Loghound has never written to, truncated or rotated one.
- The
LogFormatline you added to your web server. It lives in a file Loghound does not own. - The beacon tag on your website. It works again on its own once setup is finished.
- The service, the timers, the vhost, the PHP-FPM pool, the command links, the service user and the install tree. Setup runs on them. To take Loghound off the machine instead, use the uninstaller.
| What happens to | Settings › Start over | loghound-setup --reset | uninstall.sh |
|---|---|---|---|
| Both indexes and their data | Deleted | Kept | Kept, unless you type DELETE |
| Opensolr account details | Deleted | Kept | Removed with the credentials |
| Sign-in and two-factor | Removed | Removed | Removed |
| Log sources and index names | Forgotten | Forgotten | Removed |
| Beacon key and address salt | Replaced | Kept | Removed |
| Units, vhost, pool, user, tree | Left in place | Left in place | Removed |
| Your access logs | Untouched | Untouched | Untouched |
The button is switched off while the panel shows demo data, so it can never act on a real account from a fabricated one.