Gravwell Resources

Learn about everything from customer success stories, product info, to viewpoints from
the core team.

Resource (1)

Detection Engineering In Gravwell

Video
Phishing Attack

Hunting Down A Phishing Attack

Video
Rapid Deployment

How To: Rapid Deployment

Video
System Health

How To: Systems & Health Overview

Video
Gravwell-Video-Auto-Extractors-1

How To: Auto Extractors [AX]

Video
Gravwell Platform Basics How to Macros Thumbnail

How To: Macros

Video
Gravwell Platform Basics How to Actionables

How To: Actionables

Video
Gravwell-Video-Triage-Intro

How To: Compound Queries In Gravwell

Video
Introducing_ Alerts Thumbnail

Introducing Alerts

Video
Scheduled Searches

Scheduled Searches

Video
Field Values

Field Values vs Lookup Tables

Video
Aggregate Functions

Aggregate Functions

Video
Macros

Macros

Video
If Else

If/Else Statements

Video
Sub Search

Sub Search Functionality

Video
Transactions

Transactions

Video
JSON Stuff

JSON Stuff

Video
Fine Grain Permissions

Fine Grain Permissions

Video
Deduplication

Deduplication

Video
Parsing Fields

Parsing New Fields

Video
Out of The Box

Out of The Box

Video
API Calls

API Calls

Video
Data Fusion-1

Data Fusion & Joins

Video
Regex Matching

Regex Matching

Video
Lookup Tables

Lookup Tables

Video
Creating New Fields

Creating New Fields

Video
On Prem Self Hosting

Self Hosting

Video
Visualizations

Visualizations

Video
Automation_ Outputting Data

Automation: Outputting Data Through Flows

Video
Documentation

Documentation

Video
Automation Alerts

Automation and Alerting

Video
Supercharge Your Asset Tracking

Supercharge Your Asset Tracking and Analysis

PDF
PCAP At Scale

PCAP at Scale

PDF
Redacted Storage Whitepaper

Storage Whitepaper

PDF
RFP Questions

SIEM and Data Lake RFP Questions

PDF

DOCUMENTATION

All Gravwell documentation is free and open to everyone. 

If you’re just starting out with Gravwell, we recommend reading the Quick Start first, then moving on to the Search pipeline documentation to learn more.