Gravwell Resources
Learn about everything from customer success stories, product info, to viewpoints from
the core team.
Blog
Not everyone is comfortable handing over the keys to their cybersecurity program to agents, and one reason is that many SIEM AI capabilities are still surface-deep. They draw conclusions solely from limited, preassembled context such as alerts, cases, and preconfigured integrations.
All
Add Threat Hunting to your SIEM with Gravwell
HEC Support: Gravwell's HTTP Ingester for Splunk Compatibility
Practical Application of MITRE ATT&CK
What's in a Sysmon Event Pt. 2 - Network Connections
What's in a Sysmon Event Pt. 1 - Process creation
A personal short story about broken pricing models
Windows DNS threat hunting with Sysmon and Gravwell
Monitoring Vehicle CANBus Activity with Gravwell
DOCUMENTATION
All Gravwell documentation is open to everyone.
If you’re just starting out with Gravwell, we recommend reading the Quick Start first, then moving on to the Search pipeline documentation to learn more.







