Elektrine lite

โ† Feed

Graylog

Graylog@infosec.exchange

<p>Centralized <a href="https://infosec.exchange/tags/logmanagement" class="mention hashtag" rel="tag">#<span>logmanagement</span></a> that actually works. <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a></p>

Posts

  • View post

    Ten common micro-services issues, broken down by what to actually look for when debugging each one. Covers distributed tracing gaps, cascade failures, API contract drift, deployment coordination, secrets management, service discovery, and more. https://graylog.org/post/troubleshooting-the-top-10-microservices-issues/ #Microservices #Observability #DevOps #SIEM

  • View post

    Configuration drift happens quietly. A manual fix here, a hotfix there, a deployment that misses part of the fleet. Over time the gap between documented baseline and actual state grows until it surfaces as a security gap, a compliance failure, or an outage. This new blog post covers the root causes and the practices that catch drift early, including baselining, continuous monitoring, and centralized logging. https://graylog.org/post/recognizing-and-mitigating-configuration-drift-risks/

  • View post

    You downloaded Graylog Open. Now what? Zero to Logs: Graylog Open Running Under an Hour walks you through a real install from scratch. Deployment choice, first data source, first search. No slides, no theory. Just a live terminal. Wed Aug 26, 10AM EDT. Register: https://graylog.org/open-webinar/

  • View post

    ๐ŸŒก๏ธ New lab guide: hook up an ESP32 + DHT22 sensor, create a tiny HTTP endpoint, and stream live temperature &amp;amp; humidity data straight into Graylog for a real-time dashboard. Who said log management couldn&amp;#39;t be fun? ๐Ÿ› ๏ธ ๐Ÿ‘‰ https://graylog.org/post/iot-sensor-lab-guide/ #Graylog #IoT #HomeLab #ESP32 #LogManagement #DIY #MakerCommunity

  • View post

    Storing every log forever? That&amp;#39;s not security โ€” that&amp;#39;s a storage bill. Effective log retention means tiering your data: hot for active monitoring, warm for periodic audits, cold for long-term compliance. The right strategy keeps the signal, cuts the noise, and scales without breaking your budget. New guide on building a cost-effective log retention strategy: https://graylog.org/post/how-to-build-a-cost-effective-log-retention-strategy/ #InfoSec #LogManagement #SIEM #Complian...

  • View post

    SaaS-only SIEM fails the moment it assumes connectivity that doesn&amp;#39;t exist. Air-gapped military networks. OT-isolated pipelines and power grids. Government research enclaves. Hard data residency mandates across the EU, GCC, and beyond. In each case the issue isn&amp;#39;t the product โ€” it&amp;#39;s the architecture. New post: the four environments where cloud-first SIEM structurally cannot operate, and what actually works instead โ†’ https://graylog.org/post/the-four-environments-where-...

  • View post

    Audit season doesn&amp;#39;t have to mean panic mode. Organizations that maintain audit readiness year-round spend less time scrambling for evidence, close deals faster, and demonstrate a mature security posture to customers and partners. This blog covers practical steps, centralized log management, saved queries, retention policies, and more that turn audit prep from a fire drill into a repeatable workflow. https://graylog.org/post/why-audit-readiness-accelerates-revenue/

  • View post

    On the Graylog blog: a full breakdown of FERC and NERC CIP compliance for the energy sector. This covers all 13 enforceable standards, from BES Cyber System categorization to supply chain risk management, and how security monitoring ties it together. https://graylog.org/post/ferc-and-nerc/

  • View post

    Singapore&amp;#39;s CCoP 2.0 isn&amp;#39;t a once-a-year audit exercise. It mandates continuous monitoring, behavioral anomaly detection, and integrated IT/OT coverage for good reason. In July 2025, a Chinese-linked APT group was found operating inside all four of Singapore&amp;#39;s major telcos, using techniques that signature-based detection misses entirely. New Graylog blog breaks down what CCoP 2.0 actually requires and includes six indicators to assess your detection posture before your...

  • View post

    The 2026 World Cup is the most complex digital event in history, and the threat window it creates isn&amp;#39;t limited to FIFA. Gaming platforms, payment processors, broadcasters, hospitality providers: all in scope. A 30-second log delay means a stolen credential has 30 seconds of operational freedom before anyone sees the first signal. That&amp;#39;s not a performance issue. That&amp;#39;s a security gap. Link: https://graylog.org/post/the-world-cup-creates-the-worlds-largest-attack-surface...

  • View post

    SOC 2 compliance guide, no fluff: Trust Services Criteria explained, Common Criteria controls mapped, and practical best practices for log collection, anomaly detection, incident response, and access management. Link: https://graylog.org/post/the-definitive-soc-2-compliance-guide/ #SOC2 #Compliance #Cybersecurity #InfoSec

  • View post

    WinRM is built into Windows and beloved by attackers for lateral movement. Graylog&amp;#39;s Microsoft WinRM Content Pack turns raw operational event logs into structured, GIM-tagged security intelligence, with parsing, enrichment, and a dashboard included. Detect brute force, trace attacker paths, meet audit requirements. https://graylog.org/post/microsoft-winrm-data-in-graylog/ #Graylog #WinRM #SIEM

  • View post

    New post: IT Audit: What It Is and How to Prepare for One Covers the security/risk, compliance/governance, and operational continuity objectives auditors assess, plus where IT audits overlap with (and differ from) traditional financial audits. It also digs into the tooling stack auditors expect to see evidence from: SIEM, vulnerability scanners, IAM, EDR, DLP, and audit logging platforms, and how centralized log management (hi, Graylog) cuts down the manual evidence-gathering work for lean secu...

  • View post

    New webinar: Graylog MCP Server How-To. Jeff Darrington shows Graylog Open users how to query streams, indices, and log data through Claude using natural language. July 29th 10AM, 20 min content, 10 min Q&amp;amp;A. Part of our Getting the Most out of Graylog Open series. https://graylog.org/open-webinar/

  • View post

    GDPR compliance isn&amp;#39;t a one time checklist, it&amp;#39;s ongoing monitoring and documentation. Our latest blog walks through the 7 core principles, key articles like breach notification and DPIAs, and how centralized log management helps organizations stay audit ready and respond to incidents within GDPR&amp;#39;s 72-hour window. https://graylog.org/post/understanding-compliance-with-gdpr-requirements/ #GDPR #DataPrivacy #Compliance #InfoSec

  • View post

    When the CI/CD pipeline fails, everyone stops shipping and starts guessing. Environment mismatches, expired credentials, flaky tests, infrastructure issues. The first error message is rarely the real root cause. The fix isn&amp;#39;t faster debugging. It&amp;#39;s a repeatable investigation process: centralize logs from every pipeline stage, confirm scope, identify the failed step, isolate what changed. https://graylog.org/post/building-a-process-for-investigating-deployment-failures-in-the-...

  • View post

    Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections. Most teams treat that as noise. It&#39;s early-warning threat telemetry. The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically. https://graylog.org/post/sendmail-data-in-graylog/ #SIEM #ThreatHunting #EmailSecurity

  • View post

    We are proud to power the NOC at @BSidesLV@infosec.exchange, watching the traffic nobody else gets to see. #BSidesLV #graylog #NOC #cybersecurity #InfoSec

  • View post

    Once attackers gain initial access, lateral movement is how they expand their reach without tripping alarms. They mimic legitimate admin behavior to pivot toward domain controllers, sensitive file shares, and databases. Our latest blog covers the techniques attackers use and the strategies (segmentation, least privilege, MFA, Zero Trust) that help security teams detect and contain it early. https://graylog.org/post/lateral-movement-security-risk-and-mitigation-strategies/ #CyberSecurity #SIEM #...

  • View post

    Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn&#39;t investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #Net...

  • View post

    Email threats aren&#39;t slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack. With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data. New blog covers the inte...

  • View post

    AWS WAF sees every request hitting your ALB, CloudFront, API Gateway, or AppSync, and makes a block/allow/count/CAPTCHA/challenge decision on each one. The question is whether your security team can actually see and search those decisions. The AWS WAF Content Pack for Graylog parses the WAF JSON payload, normalizes the fields, and maps enforcement actions to the Graylog Information Model so they flow straight into detection and investigation workflows. Dashboard included. Details: https://gray...

  • View post

    New blog: Building Efficient Cyber Investigation Workflows A cyber investigation is a structured process, not just reacting to alerts. We cover the 5 key stages (identification, preservation, extraction/analysis, documentation, presentation) and share best practices for centralizing telemetry, reducing alert fatigue, and building repeatable workflows for lean security teams. https://graylog.org/post/building-efficient-cyber-investigation-workflows/ #CyberSecurity #InfoSec #SOC #IncidentRespons...