Blog

Amp Up Your Data Analysis with the new Zeek Kit

Nov 16, 2020 9:30:00 AM / by John Floren posted in Security, docker, Bro, kits, DNS, zeek

Zeek can give you so much insight into what's going on in your network, but it can feel like drinking from the firehose - dozens of files full of terse log entries, and no easy way to cross-reference or merge them. That's where Gravwell's new Zeek kit comes in. It's a suite of pre-built queries, dashboards, and more which can help you make sense of what Zeek's telling you with a few clicks.

Read More

Brewing With Gravwell

Nov 4, 2020 1:12:52 PM / by Kris Watts posted in Case study, Home Operations Center, HOWTO

Overview

Today we are going to talk about something very important - beer.  Homebrewing has a long tradition and many master brewers started by making swill in their basement.  So today, I am going to go over my homebrew setup, how it is instrumented, how I use low-cost sensors to monitor every stage; and how a little bit of automation saved a kegerator and a few carboys.

Read More

What's in a Sysmon Event Pt. 2 - Network Connections

Oct 9, 2020 9:00:50 AM / by Corey Thuen posted in Windows, Sysmon

We're building a Gravwell Kit for Sysmon! This blog series examines some of the event types that Sysmon generates to see what data they contain, opportunities for enhancing security, and example queries with Gravwell. Part 1 covered the Process Creation event type. In part 2 we jump into: Network Connection events!

Read More

Introducing the Gravwell CoreDNS Kit

Sep 15, 2020 2:17:53 PM / by Fritz posted in Security, kits, DNS

What’s in a Domain Name? That which we call a CNAME by any other AAAA record would still be used by malware to steal your data. This article introduces the Gravwell CoreDNS Kit, which provides dashboards, queries, and other resources to help you quickly analyze data from a CoreDNS instance using the Gravwell CoreDNS plugin. 

Read More

What's in a Sysmon Event Pt. 1 - Process creation

Sep 3, 2020 1:09:02 PM / by Corey Thuen posted in Windows, Sysmon

I'm building a Gravwell Kit for Sysmon! This blog series follows the development of that kit for the awesome (free) sensor for Windows EDR, Sysmon. In this series we'll look at each event type that Sysmon generates to see what data it contains, opportunities for enhancing security, and example queries with Gravwell.

Read More

Gravwell Weather Data Kit - Look Ma, No Ingester!

Aug 3, 2020 2:48:20 PM / by John Floren posted in ingester, HOWTO, first time, kits

Maybe you've just signed up for Gravwell Community Edition and are not quite sure where to start. There are a lot of features in Gravwell, and a lot of different ingesters for pulling in data. Gravwell 4.0 includes a kit that can collect data without any external ingester--and it helps you analyze everyone's favorite topic, the weather!

Read More

More Gravwell Fun, Now With Kits

Jul 30, 2020 9:10:00 AM / by Ron Fabela posted in HOWTO, query, first time

Our final HOWTO for this blog series focuses on Kits, a wonderful thing in the Big Bang Release that makes our data journey quick and easy.  To catch up on our previous HOWTOs check out:
Part 1:  Getting Gravwell Installed in 2 Minutes
Part 2:  Getting Data Into Gravwell
Part 3:  First Time With Gravwell 

Read More

First Time with Gravwell

Jul 23, 2020 8:15:00 AM / by Ron Fabela posted in HOWTO, query, first time

In our continuing series of HOWTOs, today we are walking through the user interface and seeing what questions we can answer in our new data, focusing on Netflow
Part 1:  Getting Gravwell Installed in 2 Minutes
Part 2:  Getting Data Into Gravwell

There's a ton of building blocks here and what I've found is that once you learn each, combining them together to get the answers you need is quick and fun. 

Read More

Getting Data Into Gravwell

Jul 14, 2020 9:05:00 AM / by Ron Fabela posted in ingester, HOWTO, setup, netflow, pcap

In our continuing series of HOWTOs, today we are getting some data into our Gravwell instance setup in Getting Gravwell Installed in 2 Minutes

As with install, setting up your data ingesters is quick and easy. 

Read More

Gravwell Installed In 2 Minutes

Jul 9, 2020 9:00:00 AM / by Ron Fabela posted in HOWTO, setup

As resident new guy at Gravwell something struck me right away. So many barriers to entry are removed by good software:  ease of install, straightforward data ingest configuration, powerful UI. First in the series of quick HOWTOs, I present to you installing Gravwell

Read More