Gravwell Resources
Learn about everything from customer success stories, product info, to viewpoints from 
the core team.
Blog
Gravwell 5.7.0 introduces Logbot, a Gravwell assistant to help understand logs. Log analysis can feel like deciphering a foreign language–tedious, time-consuming, and frustrating. While we don't have a choice on how any given vendor formats their logs, we don't have to go it alone. Logbot is here to help reduce time reading technical documentation and get right into analysis
All
The Shift from SIEM to Cybersecurity Data Platform
Gravwell 5.6.0 New License Tiers
Gravwell 5.4.0 New Feature: Updated Eval Module
Gravwell 5.4.0 released - New alerting features
Using lookup to invert matches
Accelerated Filtering with Eval
Home Assistant Integration: Analyzing Smart Homes with Gravwell
Kris Trust Issues: Gravwell's Capability-Based Access Control
Debunking Myths: IT, OT, ICS Security from an Engineer's Perspective
Gravwell 5.2 gets a query editing environment
Visualizing Custom Data from a CSV
Gravwell + SCinet at Supercomputing 22
Click to Victory in Gravwell 5.1
Jupyter + Gravwell=Unleash the Power of Python
Splunk Integrations for Gravwell
Making things awk-ward: Gravwell and AWK
The basics of Gravwell API Access Tokens
Tracking BART Trains with Gravwell
Gravwell Flows: Leveraging Best Buy API for Sony Playstation 5
Kit: Palo Alto Networks Next-Generation Firewall
Hello world! With Gravwell Flows
Announcing Gravwell 5.0.0 Orion
CSV over Syslog? How to analyze nested data formats
Did that BIOS Update Do Anything?
Four Tips to optimize your search through enhanced query structure
Expanding Gravwell Community Edition - Major Changes
Anomaly Detection: Correlating Weak Signals in Log Analysis
CVE-2021-44228 Log4J does not impact Gravwell products
Get Your Kits into Git with Kitctl
What's in a Sysmon Event - Windows Registry EventIDs 12, 13, 14
What's in a sysmon event - eventid 5, process termination
Gravwell 4.2.4 and Query Studio Tour
Delve into Apache Logs with Gravwell Data Explorer
Announcing Gravwell 4.2.0 - Voyager Release
The Sky is no longer the limit. Gravwell blasts off into space.
Back-up to Backblaze with Gravwell Automations
Gravwell 4.2 Sneak Peek - Data Explorer
Top 5 Questions to Ask when Considering Log Management Solutions
Hosts that have both succeeded and failed at SSH logins
Windows External Storage Audit
Threat Hunting, Spaf, Sun Tzu, and You
Exploring Absurdity: Windows Event Logs and Binary Logs
How to move to Gravwell from Splunk (or another platform)
Add Threat Hunting to your SIEM with Gravwell
Monitor Daily Temperature Swings
IPMI and Gravwell Part 2: Making an IPMI Kit
HEC Support: Gravwell's HTTP Ingester for Splunk Compatibility
IPMI and Gravwell Part 1: Building an IPMI Ingester
Grouping Related Entries with the Transaction Module
Monitoring HomeLab and Network with Gravwell Community Edition
Practical Application of MITRE ATT&CK
Announcing the Gravwell Sysmon Kit
Slice it Like Roast Beef: Parsing Raw ARP Messages in Gravwell
Easy Custom Implementations with Gravwell Client Library
Enable Data Fusion & Pivot on Dataset Properties with Enrich Module
4.1.0 Feature Spotlight: Upload Data from the Gravwell UI
Master Dataset Fusion: Introducing Gravwell 4.1 & Compound Queries
Amp Up Your Data Analysis with the new Zeek Kit
What's in a Sysmon Event Pt. 2 - Network Connections
Introducing the Gravwell CoreDNS Kit
What's in a Sysmon Event Pt. 1 - Process creation
Gravwell Weather Data Kit - Look Ma, No Ingester!
More Gravwell Fun, Now With Kits
Gravwell Installed In 2 Minutes
PCAP collection and analysis on-demand with Gravwell Packet Fleet
Smarter Gardening with Gravwell
Gravwell Ingester Preprocessors
New Release with Netflow v9 Support for Gravwell
Announcing Gravwell's Office 365 Management Log Ingester
Gravwell 3.3.0 - Overwatch Release
Go Devs: Our Experience Transitioning to Go Modules from Dep
Introducing the Key-Value Search Module
Version 3.2.3 - Performance Improvements
Version 3.2.2! Do you grok it?
A personal short story about broken pricing models
Announcing Gravwell Version 3.2
Windows DNS threat hunting with Sysmon and Gravwell
Benchmarking Gravwell's Hybrid Indexing
Monitoring Vehicle CANBus Activity with Gravwell
New Gravwell Feature: Introducing Autoextractors
Fighting social media propaganda
Announcing the new Gravwell HTTP Ingester
Super Computing 2018: A Threat Hunting Case Study
Combat Unpredictable Analytics Costs: All-You-Can-Ingest Pricing
Getting Started With Bro and Gravwell
DNS Security Audit With CoreDNS and Gravwell
Monitoring Netflow with Gravwell Community Edition
Monitoring infrastructure metrics with Gravwell and Collectd
Gravwell Community Edition-Free of Charge
Gravwell in the ICS Village and announcing Nozomi Integration
Ingesting Google Cloud Platform PubSub
Distributed Webserver Frontends in Gravwell
Gravwell And Docker Deployment
Gravwell Release Update: Version 2 Lands
Gravwell and Windows Event Logging
Amazon Kinesis Streams and Gravwell
Gravwell releases version 1 and attracts notable investor
We're thankful for big data analytics
How NOT to Launch a Product Around Black Friday
OT Security Analytics - Finding the ground truth
Gravwell wifi analytics roundup of the Wild West Hackin' Fest
Unveiling Truth: Analyzing FCC Comments Online
Using Data Fusion to hunt infrastructure capacity issues
Hunting torrent machines with network analytics
Reddit Relationship Analytics: Mayweather vs McGregor Discourse
DOCUMENTATION
All Gravwell documentation is open to everyone. 
If you’re just starting out with Gravwell, we recommend reading the Quick Start first, then moving on to the Search pipeline documentation to learn more.













































































































