Gravwell Resources
Learn about everything from customer success stories, product info, to viewpoints from
the core team.
Blog
Security teams using legacy SIEMs face rising data volumes, limited resources, fragmented tools, and growing operational complexity, while outdated architectures and pricing models make security data costly to collect, difficult to manage, and slow to investigate.
All
Add Threat Hunting to your SIEM with Gravwell
HEC Support: Gravwell's HTTP Ingester for Splunk Compatibility
Practical Application of MITRE ATT&CK
What's in a Sysmon Event Pt. 2 - Network Connections
What's in a Sysmon Event Pt. 1 - Process creation
A personal short story about broken pricing models
Windows DNS threat hunting with Sysmon and Gravwell
Monitoring Vehicle CANBus Activity with Gravwell
DOCUMENTATION
All Gravwell documentation is open to everyone.
If you’re just starting out with Gravwell, we recommend reading the Quick Start first, then moving on to the Search pipeline documentation to learn more.







