Blog

Introducing the Gravwell CoreDNS Kit

Sep 15, 2020 2:17:53 PM / by Fritz posted in Security, kits, DNS

0 Comments

What’s in a Domain Name? That which we call a CNAME by any other AAAA record would still be used by malware to steal your data. This article introduces the Gravwell CoreDNS Kit, which provides dashboards, queries, and other resources to help you quickly analyze data from a CoreDNS instance using the Gravwell CoreDNS plugin. 

Read More

What's in a Sysmon Event Pt. 1 - Process creation

Sep 3, 2020 1:09:02 PM / by Corey Thuen posted in Windows, Sysmon

0 Comments

I'm building a Gravwell Kit for Sysmon! This blog series follows the development of that kit for the awesome (free) sensor for Windows EDR, Sysmon. In this series we'll look at each event type that Sysmon generates to see what data it contains, opportunities for enhancing security, and example queries with Gravwell.

Read More

Gravwell Weather Data Kit - Look Ma, No Ingester!

Aug 3, 2020 2:48:20 PM / by John Floren posted in ingester, HOWTO, first time, kits

0 Comments

Maybe you've just signed up for Gravwell Community Edition and are not quite sure where to start. There are a lot of features in Gravwell, and a lot of different ingesters for pulling in data. Gravwell 4.0 includes a kit that can collect data without any external ingester--and it helps you analyze everyone's favorite topic, the weather!

Read More

More Gravwell Fun, Now With Kits

Jul 30, 2020 9:10:00 AM / by Ron Fabela posted in HOWTO, query, first time

0 Comments

Our final HOWTO for this blog series focuses on Kits, a wonderful thing in the Big Bang Release that makes our data journey quick and easy.  To catch up on our previous HOWTOs check out:
Part 1:  Getting Gravwell Installed in 2 Minutes
Part 2:  Getting Data Into Gravwell
Part 3:  First Time With Gravwell 

Read More

First Time with Gravwell

Jul 23, 2020 8:15:00 AM / by Ron Fabela posted in HOWTO, query, first time

0 Comments

In our continuing series of HOWTOs, today we are walking through the user interface and seeing what questions we can answer in our new data, focusing on Netflow
Part 1:  Getting Gravwell Installed in 2 Minutes
Part 2:  Getting Data Into Gravwell

There's a ton of building blocks here and what I've found is that once you learn each, combining them together to get the answers you need is quick and fun. 

Read More

Getting Data Into Gravwell

Jul 14, 2020 9:05:00 AM / by Ron Fabela posted in ingester, HOWTO, setup, netflow, pcap

0 Comments

In our continuing series of HOWTOs, today we are getting some data into our Gravwell instance setup in Getting Gravwell Installed in 2 Minutes

As with install, setting up your data ingesters is quick and easy. 

Read More

Gravwell Installed In 2 Minutes

Jul 9, 2020 9:00:00 AM / by Ron Fabela posted in HOWTO, setup

0 Comments

As resident new guy at Gravwell something struck me right away. So many barriers to entry are removed by good software:  ease of install, straightforward data ingest configuration, powerful UI. First in the series of quick HOWTOs, I present to you installing Gravwell

Read More

PCAP collection and analysis on-demand with Gravwell Packet Fleet

May 27, 2020 8:30:00 AM / by Fritz posted in Network Analytics

0 Comments

Gravwell is designed to work with your data, in your infrastructure, and within your constraints. Whether you have petabytes of packet capture, data-at-rest sensitivity requirements, or are simply integrating existing infrastructure, Gravwell is built to enable a workflow that meets your needs. Today we’ll look at an example integration with multiple Google Stenographer installations, our new Gravwell Packet Fleet ingester, and a powerful new feature in Gravwell Big Bang - Actionables. 

Read More

Gravwell 3.3.11

May 8, 2020 2:27:58 PM / by John Floren posted in Community Edition

0 Comments

Today we released Gravwell 3.3.11, hot on the heels of last week's 3.3.10. In our previous post, we'd said that 3.3.9 was the final planned release before our big 3.4.0 version, but there were a few important fixes we wanted to get out ASAP! These two releases were almost entirely bug-fixes, except for two little features we snuck in; we'll start by talking about the bug-fixes first and save the fun stuff for the end!

Read More

Smarter Gardening with Gravwell

Apr 17, 2020 10:27:47 AM / by Mike Wisely posted in Integrations, IoT

0 Comments

Some time back, I built a small, hydroponic garden in my garage to grow fresh veggies year round. Although I avoided a few hazards of traditional gardening, moving my garden inside proved to have its own set of challenges. I eventually realized that I could better manage my plants if I had a means to continually monitor their condition. Using an Arduino, a few sensors, and a tiny web server, I started collecting and accumulating data about my garden. It didn't take long before the amount of accumulated sensor data became cumbersome to look through. However, after importing the data into Gravwell, I was able to quickly visualize historical sensor information and gain new insights to make my thumb a little greener.

Read More