Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
AWS WAF sees every request hitting your ALB, CloudFront, API Gateway, or AppSync, and makes a block/allow/count/CAPTCHA/challenge decision on each one. The question is whether your security team can actually see and search those decisions.
The AWS WAF Content Pack for Graylog parses the WAF JSON payload, normalizes the fields, and maps enforcement actions to the Graylog Information Model so they flow straight into detection and investigation workflows. Dashboard included.
Details: https://graylog.org/post/aws-waf-data-in-graylog/
#SIEM #AWS #CloudSecurity #Graylog
New blog: Building Efficient Cyber Investigation Workflows
A cyber investigation is a structured process, not just reacting to alerts. We cover the 5 key stages (identification, preservation, extraction/analysis, documentation, presentation) and share best practices for centralizing telemetry, reducing alert fatigue, and building repeatable workflows for lean security teams.
https://graylog.org/post/building-efficient-cyber-investigation-workflows/
#CyberSecurity #InfoSec #SOC #IncidentResponse #Graylog
You've seen all posts