SyslogWatch on a server (no display)
====================================

The desktop app needs a graphical session. This folder also ships a headless
mode that does not — it receives, stores and alerts exactly the same way, and
shows the same screen in your browser instead of a window.

What a minimal server still needs
---------------------------------
Headless mode opens no window and contacts no X server, but the program is one
binary and the system loads every library that binary is linked against before
it starts. So GTK, X11, NSS and ALSA have to be installed even though nothing
draws. The .deb package lists them as dependencies and your package manager
installs them for you — on Debian and Ubuntu that is the easier route. If you
unpacked the .tar.gz instead, install them yourself:

    # Debian / Ubuntu
    sudo apt-get install -y libgtk-3-0 libnotify4 libnss3 libxss1 libxtst6 \
        xdg-utils libatspi2.0-0 libuuid1 libsecret-1-0 libgbm1 libasound2
    # on Ubuntu 24.04 and Debian trixie or newer, libasound2 is libasound2t64

    # RHEL / Rocky / Alma / Fedora
    sudo dnf install -y gtk3 libnotify nss libXScrnSaver libXtst xdg-utils \
        at-spi2-atk libuuid libsecret mesa-libgbm alsa-lib

If any are missing, syslogwatch-headless says so and prints the list rather
than leaving you with a bare "error while loading shared libraries".

Try it in the foreground first:

    /opt/SyslogWatch/syslogwatch-headless

It prints the web UI address, including a one-time token:

    web UI   http://127.0.0.1:8514/?token=...

Open that address once; afterwards http://127.0.0.1:8514/ is enough (a cookie
remembers you). Send a test message from the same machine to see it arrive:

    logger -n 127.0.0.1 -P 1514 -d "hello from $(hostname)"

Run it as a service: see syslogwatch-headless.service in this folder — the
commands are at the top of that file.

Options: syslogwatch-headless --help
Lost the address: syslogwatch-headless --show-url

Reaching the UI from another machine
------------------------------------
By default the UI only listens on 127.0.0.1. Either tunnel to it:

    ssh -L 8514:127.0.0.1:8514 user@server        # then open http://127.0.0.1:8514/

or put an HTTPS reverse proxy (nginx, Caddy) in front and start with
--ui-host 127.0.0.1 --ui-port 8514 as before. Do not expose the plain HTTP
port to an untrusted network: logs, SMTP credentials and the Central token
pass through it.

Secrets on a server
-------------------
There is no keyring on a server, so the licence key, SMTP password and Central
token are stored as plain files readable only by the service user (mode 0600)
under the data folder. The screen says so in Settings.

Same data as the desktop app
----------------------------
Headless and desktop use the same folder (~/.config/SyslogWatch for the user
that runs it), so a licence activated in one is active in the other.
