Graylog
Graylog@infosec.exchange
<p>Centralized <a href="https://infosec.exchange/tags/logmanagement" class="mention hashtag" rel="tag">#<span>logmanagement</span></a> that actually works. <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a></p>
Posts
-
View post
Ten common micro-services issues, broken down by what to actually look for when debugging each one. Covers distributed tracing gaps, cascade failures, API contract drift, deployment coordination, secrets management, service discovery, and more. https://graylog.org/post/troubleshooting-the-top-10-microservices-issues/ #Microservices #Observability #DevOps #SIEM
-
View post
Configuration drift happens quietly. A manual fix here, a hotfix there, a deployment that misses part of the fleet. Over time the gap between documented baseline and actual state grows until it surfaces as a security gap, a compliance failure, or an outage. This new blog post covers the root causes and the practices that catch drift early, including baselining, continuous monitoring, and centralized logging. https://graylog.org/post/recognizing-and-mitigating-configuration-drift-risks/
-
View post
You downloaded Graylog Open. Now what? Zero to Logs: Graylog Open Running Under an Hour walks you through a real install from scratch. Deployment choice, first data source, first search. No slides, no theory. Just a live terminal. Wed Aug 26, 10AM EDT. Register: https://graylog.org/open-webinar/
-
View post
๐ก๏ธ New lab guide: hook up an ESP32 + DHT22 sensor, create a tiny HTTP endpoint, and stream live temperature &amp; humidity data straight into Graylog for a real-time dashboard. Who said log management couldn&#39;t be fun? ๐ ๏ธ ๐ https://graylog.org/post/iot-sensor-lab-guide/ #Graylog #IoT #HomeLab #ESP32 #LogManagement #DIY #MakerCommunity
-
View post
Storing every log forever? That&#39;s not security โ that&#39;s a storage bill. Effective log retention means tiering your data: hot for active monitoring, warm for periodic audits, cold for long-term compliance. The right strategy keeps the signal, cuts the noise, and scales without breaking your budget. New guide on building a cost-effective log retention strategy: https://graylog.org/post/how-to-build-a-cost-effective-log-retention-strategy/ #InfoSec #LogManagement #SIEM #Complian...
-
View post
SaaS-only SIEM fails the moment it assumes connectivity that doesn&#39;t exist. Air-gapped military networks. OT-isolated pipelines and power grids. Government research enclaves. Hard data residency mandates across the EU, GCC, and beyond. In each case the issue isn&#39;t the product โ it&#39;s the architecture. New post: the four environments where cloud-first SIEM structurally cannot operate, and what actually works instead โ https://graylog.org/post/the-four-environments-where-...
-
View post
Audit season doesn&#39;t have to mean panic mode. Organizations that maintain audit readiness year-round spend less time scrambling for evidence, close deals faster, and demonstrate a mature security posture to customers and partners. This blog covers practical steps, centralized log management, saved queries, retention policies, and more that turn audit prep from a fire drill into a repeatable workflow. https://graylog.org/post/why-audit-readiness-accelerates-revenue/
-
View post
On the Graylog blog: a full breakdown of FERC and NERC CIP compliance for the energy sector. This covers all 13 enforceable standards, from BES Cyber System categorization to supply chain risk management, and how security monitoring ties it together. https://graylog.org/post/ferc-and-nerc/
-
View post
Singapore&#39;s CCoP 2.0 isn&#39;t a once-a-year audit exercise. It mandates continuous monitoring, behavioral anomaly detection, and integrated IT/OT coverage for good reason. In July 2025, a Chinese-linked APT group was found operating inside all four of Singapore&#39;s major telcos, using techniques that signature-based detection misses entirely. New Graylog blog breaks down what CCoP 2.0 actually requires and includes six indicators to assess your detection posture before your...
-
View post
The 2026 World Cup is the most complex digital event in history, and the threat window it creates isn&#39;t limited to FIFA. Gaming platforms, payment processors, broadcasters, hospitality providers: all in scope. A 30-second log delay means a stolen credential has 30 seconds of operational freedom before anyone sees the first signal. That&#39;s not a performance issue. That&#39;s a security gap. Link: https://graylog.org/post/the-world-cup-creates-the-worlds-largest-attack-surface...
-
View post
SOC 2 compliance guide, no fluff: Trust Services Criteria explained, Common Criteria controls mapped, and practical best practices for log collection, anomaly detection, incident response, and access management. Link: https://graylog.org/post/the-definitive-soc-2-compliance-guide/ #SOC2 #Compliance #Cybersecurity #InfoSec
-
View post
WinRM is built into Windows and beloved by attackers for lateral movement. Graylog&#39;s Microsoft WinRM Content Pack turns raw operational event logs into structured, GIM-tagged security intelligence, with parsing, enrichment, and a dashboard included. Detect brute force, trace attacker paths, meet audit requirements. https://graylog.org/post/microsoft-winrm-data-in-graylog/ #Graylog #WinRM #SIEM
-
View post
New post: IT Audit: What It Is and How to Prepare for One Covers the security/risk, compliance/governance, and operational continuity objectives auditors assess, plus where IT audits overlap with (and differ from) traditional financial audits. It also digs into the tooling stack auditors expect to see evidence from: SIEM, vulnerability scanners, IAM, EDR, DLP, and audit logging platforms, and how centralized log management (hi, Graylog) cuts down the manual evidence-gathering work for lean secu...
-
View post
New webinar: Graylog MCP Server How-To. Jeff Darrington shows Graylog Open users how to query streams, indices, and log data through Claude using natural language. July 29th 10AM, 20 min content, 10 min Q&amp;A. Part of our Getting the Most out of Graylog Open series. https://graylog.org/open-webinar/
-
View post
GDPR compliance isn&#39;t a one time checklist, it&#39;s ongoing monitoring and documentation. Our latest blog walks through the 7 core principles, key articles like breach notification and DPIAs, and how centralized log management helps organizations stay audit ready and respond to incidents within GDPR&#39;s 72-hour window. https://graylog.org/post/understanding-compliance-with-gdpr-requirements/ #GDPR #DataPrivacy #Compliance #InfoSec
-
View post
When the CI/CD pipeline fails, everyone stops shipping and starts guessing. Environment mismatches, expired credentials, flaky tests, infrastructure issues. The first error message is rarely the real root cause. The fix isn&#39;t faster debugging. It&#39;s a repeatable investigation process: centralize logs from every pipeline stage, confirm scope, identify the failed step, isolate what changed. https://graylog.org/post/building-a-process-for-investigating-deployment-failures-in-the-...
-
View post
Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections. Most teams treat that as noise. It's early-warning threat telemetry. The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically. https://graylog.org/post/sendmail-data-in-graylog/ #SIEM #ThreatHunting #EmailSecurity
-
View post
We are proud to power the NOC at @BSidesLV@infosec.exchange, watching the traffic nobody else gets to see. #BSidesLV #graylog #NOC #cybersecurity #InfoSec
-
View post
Once attackers gain initial access, lateral movement is how they expand their reach without tripping alarms. They mimic legitimate admin behavior to pivot toward domain controllers, sensitive file shares, and databases. Our latest blog covers the techniques attackers use and the strategies (segmentation, least privilege, MFA, Zero Trust) that help security teams detect and contain it early. https://graylog.org/post/lateral-movement-security-risk-and-mitigation-strategies/ #CyberSecurity #SIEM #...
-
View post
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #Net...
-
View post
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack. With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data. New blog covers the inte...
-
View post
AWS WAF sees every request hitting your ALB, CloudFront, API Gateway, or AppSync, and makes a block/allow/count/CAPTCHA/challenge decision on each one. The question is whether your security team can actually see and search those decisions. The AWS WAF Content Pack for Graylog parses the WAF JSON payload, normalizes the fields, and maps enforcement actions to the Graylog Information Model so they flow straight into detection and investigation workflows. Dashboard included. Details: https://gray...
-
View post
New blog: Building Efficient Cyber Investigation Workflows A cyber investigation is a structured process, not just reacting to alerts. We cover the 5 key stages (identification, preservation, extraction/analysis, documentation, presentation) and share best practices for centralizing telemetry, reducing alert fatigue, and building repeatable workflows for lean security teams. https://graylog.org/post/building-efficient-cyber-investigation-workflows/ #CyberSecurity #InfoSec #SOC #IncidentRespons...