Gravwell Resources
Learn about everything from customer success stories, product info, to viewpoints from
the core team.
Blog
Gravwell 5.7.0 introduces Logbot, a Gravwell assistant to help understand logs. Log analysis can feel like deciphering a foreign language–tedious, time-consuming, and frustrating. While we don't have a choice on how any given vendor formats their logs, we don't have to go it alone. Logbot is here to help reduce time reading technical documentation and get right into analysis
All
Threat Hunting, Spaf, Sun Tzu, and You
How to move to Gravwell from Splunk (or another platform)
Add Threat Hunting to your SIEM with Gravwell
HEC Support: Gravwell's HTTP Ingester for Splunk Compatibility
Practical Application of MITRE ATT&CK
What's in a Sysmon Event Pt. 2 - Network Connections
What's in a Sysmon Event Pt. 1 - Process creation
A personal short story about broken pricing models
DOCUMENTATION
All Gravwell documentation is open to everyone.
If you’re just starting out with Gravwell, we recommend reading the Quick Start first, then moving on to the Search pipeline documentation to learn more.