I can’t think of many people who got into security because they fell in love with Splunk’s query language or some proprietary platform only a large enterprise can afford. More often, they found themselves immersed in Linux, networking, or a cloud platform, and it progressed from there. Yet too many security job descriptions still lead with product names, asking whether you know Meraki, Splunk, or a vendor’s latest console before asking whether you understand the systems underneath.
That’s where the Hermes agent helps: you give it an objective, access to the relevant systems, and limits on what it can change, and it handles the API calls and commands while you direct the work. It isn’t a replacement for a security professional, but it lets one person cover far more ground across a mixed stack, which matters most for smaller companies that can’t afford a full security team and need to consolidate.
For example, you could use Hermes to manage OPNsense firewall rules and query Splunk logs from a single desktop, without switching between consoles or building every API call and search query by hand. Below is how I set it up and a few things I’ve used it for.
Setup: Ubuntu server
My Hermes backend runs on an Ubuntu server, and I work through Hermes Desktop on Arch Linux. The server holds the credentials and executes the work, while the desktop is where I give instructions and review the results.
For a Linux source installation, make sure Git, curl, tar, and SHA-256 utilities are available. Download the official installer, read through it, and run it as the user Hermes will run under:
curl -fsSL https://hermes-agent.nousresearch.com/install.sh -o hermes-install.sh
less hermes-install.sh
bash hermes-install.sh
Then open a new terminal to configure and check the installation:
hermes setup # initial configuration
hermes model # select or change the provider/model
hermes doctor # check the installation
After a source installation, hermes desktop launches the desktop setup. If your backend is on a separate machine like mine, connect the desktop to it through the gateway settings. Keep that endpoint on a trusted network or VPN, or use the documented OAuth setup instead of exposing an unauthenticated listener.
Giving it access without pasting secrets into chat
In OPNsense, go to System → Access → Users, select a user, and generate a key in its API section. Save the key and secret somewhere secure, since you can download the secret only once. Use a dedicated account with only the privileges the intended tasks require.
Credentials go in the active profile’s .env file on the machine that executes the work. For a profile called security:
# ~/.hermes/profiles/security/.env
OPN_KEY=<your-key>
OPN_SECRET=<your-secret>
SPLUNK_API_USER=<your-api-user>
SPLUNK_API_PASSWORD=<your-api-password>
Tell Hermes the Splunk API address separately, using the configuration value SPLUNK_API_URL. Restrict access to the credentials file:
chmod 600 ~/.hermes/profiles/security/.env
These are variable names my API scripts use, not built-in integrations, so you’ll need to tell Hermes which systems to use and where their credentials live. A profile organizes the agent’s state but is not a security sandbox.
Use case: Setting up syslog
Hermes added a syslog output in OPNsense and created a TCP input in Splunk for the opnsense index and opnsense:filterlog sourcetype. It also verified that firewall logs were arriving in Splunk. That gives me somewhere to check the results of a firewall change without manually switching between the two systems.
Use case: “Block the agents network from reaching the DC network”
I gave Hermes that instruction from the desktop. It created and applied a logged IPv4 block rule from the Agents network to the DC network, then pinged a domain controller from the agent host:
3 packets transmitted, 0 received, 100% packet loss
Hermes checked Splunk and found three firewall events matching the new rule’s identifier, verifying that the rule blocked the test traffic. It then removed the temporary rule and confirmed it was gone.
Use case: Asking Splunk a question
With logs available, you can ask practical questions in plain language:
Which countries rank highest as external sources and permitted external destinations over the last hour?
Hermes queried Splunk and returned:
| External source country | Events | Permitted destination country | Events |
|---|---|---|---|
| United States | 1,182 | United States | 29,700 |
| Bulgaria | 159 | Canada | 25,120 |
| United Kingdom | 129 | United Kingdom | 1,404 |
These are counts of logged IPv4 events with a country lookup, not bandwidth or unique connections. The point is that we can ask the question from the desktop and get a useful answer without building the search by hand first.
Beyond the firewall
The same approach can help with administering AWS, Azure, and Google Cloud, building Splunk dashboards, or diagnosing problems in a Kubernetes cluster. If the software exposes an API, a CLI, or an MCP integration, Hermes has a way to work with it. A well-rounded IT or security professional can direct that work without already being an expert in every product involved.
Hermes handles the product-specific work, while you decide what’s allowed, review the changes, and check the evidence. That’s the split I want: hire for fundamentals and judgment, then give that person tools that let them act on both. Less time navigating consoles leaves more time for the systems, problems, and security work that drew us into the field in the first place.
Something to run OPNsense on
If you’re sizing this for a small business, budget usually decides it. A desktop-class box like a Dell OptiPlex 9010 SFF looks like the obvious safe pick, but used units aren’t actually cheap — you can end up paying close to what a full 1U rackmount server costs. Older enterprise gear tends to be the better value if a dedicated firewall box is all you need:
Rack-mountable, server-grade NICs, and on the used market this class of box is routinely cheaper than a comparable SFF desktop. It’s also what I actually run my own OPNsense firewall on. The tradeoff is noise — 1U chassis fans run small and high-RPM, and they’re loud. Fine in a closet or a rack room; not something you want sitting next to a desk.
Quiet and small enough to sit in an office, and it can double as a Splunk host or a couple of VMs instead of running single-purpose. Just don’t assume it’s the cheap option — check current prices on both before deciding.