Sign in

Graylog

@graylog.bsky.social
2.8K followers 1.5K following 621 posts

🌍 Trusted Threat Detection & Incident Response solutions. Experience the difference with our unmatched capabilities. #SIEM #APISecurity #LogManagement #InfoSec

PostsRepliesMedia
Graylog @graylog.bsky.social · 6h
JSON is the standard format for structured logging. Parsing it turns raw text into objects you can filter, correlate, and act on. Our new blog covers parsing in JavaScript, Python, PHP, and Java, plus best practices for JSON logs. graylog.org/post/what-to...
graylog.org
What To Know About Parsing JSON
Parsing JSON involves transforming structured information into a format that can be used within various programming languages.
010
Graylog @graylog.bsky.social · 28/09/2026
WatchGuard Firebox Firewall Data in Graylog. The Illuminate content pack parses Fireware syslog, maps events to GIM, and surfaces IPS, GAV, and APT detections as network detections. Setup takes three steps. graylog.org/post/watchgu... #Graylog #WatchGuard #SIEM
graylog.org
WatchGuard Firebox Firewall Data in Graylog
Graylog's WatchGuard Firebox Content Pack parses Firebox syslog, normalizes traffic, auth, IPS, and DHCP events, mapping them to GIM for detection.
012
Graylog @graylog.bsky.social · 24/09/2026
SIEM and observability costs scale with data volume. Pipeline management is how you keep collecting the telemetry you need while routing low-value logs to cheaper storage. graylog.org/post/data-pi...
graylog.org
Data Pipeline Management for Security and Observability
Learn how data pipeline management helps security and IT teams control SIEM costs, reduce alert fatigue, and stay audit-ready without losing visibility.
000
Graylog @graylog.bsky.social · 23/09/2026
Miss the Graylog Inputs Demystified webinar? Watch it here: graylog.org/post/inputs-...
012
Graylog @graylog.bsky.social · 21/09/2026
New on the blog: 25 Linux logs worth collecting and monitoring, from auth.log to audit.log, with a rundown of terminal commands (grep, awk, journalctl) for reading them. graylog.org/post/25-linu...
graylog.org
25 Linux Logs to Collect and Monitor
Knowing what Linux logs to collect and monitor can help you correlate event information for improved operations and security insights.
010
Graylog @graylog.bsky.social · 17/09/2026
If you're running Suricata, you already have the data. The question is whether it's usable. Graylog's Suricata IDS/IPS Content Pack parses EVE JSON, normalizes it to GIM, and gives you a ready to use dashboard for alerts and more. graylog.org/post/suricat... #Graylog #Suricata #SIEM #NetworkSecurity
graylog.org
Suricata IDS/IPS Data in Graylog
Graylog Suricata IDS/IPS Content Pack parses, enriches, and maps EVE JSON logs for instant network security visibility and threat detection.
000
Graylog @graylog.bsky.social · 15/09/2026
Application performance management in cloud-native environments is harder than it looks. Containers disappear before you can investigate them. Alerts pile up until nobody trusts them anymore. New guide: 5 best practices for engineering leaders. graylog.org/post/what-is...
graylog.org
What Is Application Performance Management? A Cloud-Native Guide for Engineering Leaders
A practical guide to application performance management for VPs of Engineering: real costs, cloud-native challenges, and proven best practices.
011
Graylog @graylog.bsky.social · 11/09/2026
Getting logs into Graylog doesn't require a PhD in syslog or other log sources. Sept 23, 10AM EDT: The Input Wizard, and the inputs pages 20 min content + 10 min Q&A. Make sure you're on the latest version. Register here: graylog.org/post/inputs-...
graylog.org
Inputs Demystified: Connect Anything with the Input Wizard
Get the most out of Graylog inputs. Join Jeff Darrington Sept 23 for Inputs Demystified webinar: connect log sources fast with the Input Wizard.
011
Graylog @graylog.bsky.social · 10/09/2026
Linux syslog varies wildly by distro: rsyslog, syslog-ng, journald, different file paths, different defaults. Our new guide covers how to locate, configure, and centralize this data so troubleshooting doesn't mean guessing where the logs live. graylog.org/post/a-pract...
graylog.org
A Practical Guide for Managing Linux Syslog
A complete guide to Linux syslog: what it is, how to access and configure it, common challenges, and best practices for centralized log monitoring.
020
Graylog @graylog.bsky.social · 09/09/2026
Protecting the electric grid means complying with NERC CIP, 13 standards covering physical security, patch management, incident response, and more. Our blog explains what each standard requires and how a SIEM supports compliance without the overhead. graylog.org/post/ferc-an...
graylog.org
FERC and NERC: Cyber Security Monitoring for The Energy Sector
NERC CIP provides the basic cybersecurity control requirements for North American energy companies. Follow this blog for more info.
021
Graylog @graylog.bsky.social · 03/09/2026
Kubernetes spreads failures across pods, nodes, and the control plane, which makes root-causing them slow. Our troubleshooting guide covers the most common errors (CrashLoopBackOff, ImagePullBackOff, OOMKilled, stuck rollouts) with the commands to fix each one fast. graylog.org/post/kuberne...
graylog.org
Kubernetes Troubleshooting: The Complete Guide
Troubleshoot CrashLoopBackOff, ImagePullBackOff, OOMKilled, and other common Kubernetes errors with step-by-step fixes for pods, nodes, and clusters.
000
Graylog @graylog.bsky.social · 02/09/2026
SIEM shopping in 2026? Start here. Our State of SIEM Report ranks the year's Top 10 threats and lays out a 12-point checklist for lean security teams chasing faster detection without runaway costs. Full report: graylog.org/resources/st...
graylog.org
Ebook: State of SIEM Report
2026 State of SIEM report ranks top threats, buying criteria, and practical guidance for lean security teams seeking faster detection and cost control.
000
Graylog @graylog.bsky.social · 01/09/2026
An audit trail without integrity can be altered. Without confidentiality, it's exposed to anyone. Both failures defeat the purpose. This new post covers audit log vs. audit trail, the 7 types of trails, and a 7-step implementation framework: graylog.org/post/protect...
graylog.org
Protection of the Audit Trail Involves Both Integrity and Confidentiality
Audit trail protection requires both integrity and confidentiality. Learn the types, benefits, and step-by-step process to build audit trails that hold up.
000
Graylog @graylog.bsky.social · 31/08/2026
Getting logs into Graylog doesn't require a PhD in syslog or other log sources. Sept 23, 10AM EDT: The Input Wizard, and the inputs pages 20 min content + 10 min Q&A. Make sure you're on the latest version. Register here: graylog.org/open-webinar
021
Graylog @graylog.bsky.social · 27/08/2026
Check out free Graylog Academy. Self-paced courses covering log ingestion, pipeline rules, dashboards, and more. Built by the team behind the product. No catch. Start Learning: graylog.org/post/graylog...
graylog.org
Graylog Academy: Free On-Demand Training Available
Go to the Graylog Academy and sign up for on demand free training. Learn the analyst fundamentals of Graylog!
021
Graylog @graylog.bsky.social · 26/08/2026
Did you miss the webinar Zero to Logs with Graylog? - Installing Graylog in a Docker container - Getting logs into Graylog - Routing logs into dedicated streams Check out the replay here: graylog.org/resources/ze...
graylog.org
Videos: Zero to Logs: Get Graylog Open Running in Under an Hour
000
Graylog @graylog.bsky.social · 20/08/2026
A login anomaly: risk-5. Ignored. Credential access five minutes after that: risk-72. Risk scoring turns 10,000 alerts into 10 critical investigations. Analysts investigate 3x more efficiently. Does your SIEM connect the dots, or just count them? Watch it happen: www.youtube.com/watch?v=O3Qc...
051
Graylog @graylog.bsky.social · 18/08/2026
You downloaded Graylog Open. Now what? Zero to Logs: Graylog Open Running Under an Hour walks you through a real install from scratch. Deployment choice, first data source, first search. No slides, no theory. Just a live terminal. Wed Aug 26, 10AM EDT. Register: graylog.org/graylog-open...
110
Graylog @graylog.bsky.social · 12/08/2026
Configuration drift is quiet. No alarms go off when a system slowly stops matching its documented baseline. It just shows up later as a security gap, a failed audit, or an outage that takes hours to explain. This new blog post on why it happens and how to catch it early: graylog.org/post/recogni...
graylog.org
Recognizing and Mitigating Configuration Drift Risks
Configuration drift silently breaks systems, creates security gaps, and fails audits. Learn what causes it, the risks it creates, and how to get it under control.
000
Graylog @graylog.bsky.social · 10/08/2026
A service can be individually healthy and still be the reason everything else is timing out. Broke down 10 common micro-services issues and the specific signs that point to root cause, from cascade failures to contract drift to secrets management: graylog.org/post/trouble...
graylog.org
Troubleshooting the Top 10 Microservices Issues
Distributed systems are powerful but notoriously hard to debug. Learn the 10 most common microservices troubleshooting challenges and what to look for when things go wrong in production.
021
Graylog @graylog.bsky.social · 06/08/2026
When the CI/CD pipeline fails, nobody ships. Environment mismatch. Expired credential. Flaky test. Full disk. The first error is rarely the trigger. Centralize logs. Confirm scope. Isolate what changed. Fix one variable at a time. graylog.org/post/buildin...
graylog.org
Building a Process for Investigating Deployment Failures In the CI/CD Pipeline
A CI/CD deployment failure can lead to features not shipping and customer dissatisfaction. Learn the most common causes of deployment failures and how to investigate and resolve them faster.
031
Graylog @graylog.bsky.social · 04/08/2026
Sendmail logs auth failures, forged relay hostnames, TLS rejections, and Milter actions on every mail transaction. It's one of the most overlooked sources of threat telemetry out there. The Sendmail Content Pack for Graylog parses it. graylog.org/post/sendmai...
graylog.org
Sendmail Data In Graylog
Graylog Sendmail Content Pack parses, enriches, and maps mail server logs to GIM, turning routine MTA data into real threat detection signal."
000
Graylog @graylog.bsky.social · 03/08/2026
We are proud to power the NOC at @bsideslv.org, watching the traffic nobody else gets to see. #BSidesLV #graylog #NOC #cybersecurity #InfoSec
030
Graylog @graylog.bsky.social · 30/07/2026
Graylog SIEM is working overtime in the NOC at @bsideslv.org 2026. Live conference traffic, real time processing, August 3-5 at The Tuscany. #BSidesLV #BSidesLV2026 #SIEM
010
Graylog @graylog.bsky.social · 29/07/2026
Couldn't make it to our live session on the Graylog MCP Server? Good news, the recording is up. We showed how Graylog Open users can query logs using natural language through Claude. Check it out. Watch the replay: graylog.org/resources/co...
161
Graylog @graylog.bsky.social · 28/07/2026
New blog: Understanding Compliance with GDPR Requirements. We cover the 7 GDPR principles, the articles that matter most, and how log monitoring helps organizations demonstrate compliance and catch incidents faster. graylog.org/post/underst... #GDPR #DataPrivacy #Compliance
graylog.org
Understanding Compliance with GDPR Requirements
Understand GDPR requirements in plain terms: what data is covered, who must comply, key articles, and how to monitor for compliance.
020
Graylog @graylog.bsky.social · 17/07/2026
Our next Graylog Open webinar covers the Graylog MCP Server: connect Claude, and query streams, indices, and login data with plain language prompts. July 29th 10am EDT. 20 min content + 10 min Q&A. Save your spot: graylog.org/open-webinar/
020
Graylog @graylog.bsky.social · 16/07/2026
Lateral movement is how attackers quietly expand access after that first foothold, moving toward domain controllers, file shares, and databases while blending into legitimate traffic. This blog covers common techniques and the mitigation strategies to reduce risk graylog.org/post/lateral...
graylog.org
Lateral Movement: Security Risk and Mitigation Strategies
Learn how lateral movement enables attackers to expand access across enterprise systems and how strong security controls can reduce dwell time and limit the impact of cyber attacks, phishing attacks, and ransomware attacks.
011
Graylog @graylog.bsky.social · 14/07/2026
If you're running Suricata, you already have the data. The question is whether it's usable. Graylog's Suricata IDS/IPS Content Pack parses EVE JSON, normalizes it to GIM, and gives you a ready to use dashboard for alerts and more. graylog.org/post/suricat... #Graylog #Suricata #SIEM #NetworkSecurity
graylog.org
Suricata IDS/IPS Data in Graylog
Graylog Suricata IDS/IPS Content Pack parses, enriches, and maps EVE JSON logs for instant network security visibility and threat detection.
000
Graylog @graylog.bsky.social · 09/07/2026
Credential phishing and malware attachments aren't going away. If you're using Mimecast for email security, Graylog 6.2.3+ lets you pull those logs in directly via API v2.0, with prebuilt Illuminate Dashboards ready on day one. New blog on setup and what you get: graylog.org/post/unlock-...
graylog.org
Unlock Email Threat Visibility with Mimecast and Graylog
Integrate Mimecast with Graylog to centralize email threat logs, speed investigations, and gain instant insights via Illuminate Dashboards.
011
Graylog @graylog.bsky.social · 07/07/2026
Remember cramming for exams, pulling together every note so you'd have the right info when it mattered? That's basically what preparing for an IT audit feels like, just with higher stakes. Check it out! graylog.org/post/it-audi...
graylog.org
IT Audit: What It Is and How to Prepare for One
Learn what an IT audit is, its core objectives, key differences from financial audits, and the tools organizations use to improve security, compliance, and audit readiness.
012
Graylog @graylog.bsky.social · 02/07/2026
New from Graylog Labs: the AWS WAF Content Pack. It parses your WAF JSON logs, normalizes HTTP request and enforcement fields, and maps block/allow/CAPTCHA/challenge events to GIM so they show up as real detections, not just raw JSON. graylog.org/post/aws-waf...
graylog.org
AWS WAF Data in Graylog
Graylog's AWS WAF Content Pack parses, enriches, and maps WAF block, allow, and challenge events for instant application security visibility.
010
Graylog @graylog.bsky.social · 30/06/2026
New on the Graylog blog: Building Efficient Cyber Investigation Workflows. We break down the 5 stages of a cyber investigation (identification, preservation, analysis, documentation, presentation) plus best practices for centralizing telemetry and reducing alert fatigue. graylog.org/post/buildin...
graylog.org
Building Efficient Cyber Investigation Workflows
Learn how to build efficient cyber investigation workflows for lean security teams by centralizing telemetry, improving threat detection, and streamlining incident response.
000
Graylog @graylog.bsky.social · 26/06/2026
WinRM is built into Windows and beloved by attackers for lateral movement. Graylog's Microsoft WinRM Content Pack turns raw operational event logs into structure with security intelligence, parsing, enrichment, and a dashboard included. graylog.org/post/microso... #Graylog #WinRM #SIEM
graylog.org
Microsoft WinRM Data in Graylog
Graylog Microsoft WinRM log monitoring content parses, enriches, and maps Windows Remote Management logs giving your team instant security visibility.
010
Graylog @graylog.bsky.social · 25/06/2026
SOC 2 isn't a point-in-time exercise, it's continuous. Our definitive guide walks through every criteria, control, and best practice your team needs to stay audit-ready and demonstrate operating effectiveness all year long. Link: graylog.org/post/the-def...
graylog.org
The Definitive SOC 2 Compliance Guide
A complete guide to SOC 2 compliance that covers the Trust Services Criteria, Common Criteria, Type 1 vs. Type 2 reports, and best practices for maintaining audit readiness year-round.
011
Graylog @graylog.bsky.social · 22/06/2026
48 teams. Half the planet watching. The World Cup creates conditions that financially motivated attackers exploit by design. Your security infrastructure either matches that preparation, or it doesn't. Link: graylog.org/post/the-wor...
graylog.org
The World Cup Creates the World's Largest Attack Surface
48 teams, 104 matches, half the planet watching—and threat actors ready. Is your security infrastructure built for what that window demands?
010
Graylog @graylog.bsky.social · 18/06/2026
CCoP 2.0 sets continuous monitoring requirements for Singapore's critical infrastructure — but most orgs are still treating compliance as a checkbox. In July 2025, a Chinese-linked APT operated inside all four major Singapore telcos, undetected. New blog: Link: graylog.org/post/what-si...
graylog.org
What Singapore's CCoP 2.0 Requires of Critical Infrastructure Owners
Understand CCoP 2.0's continuous monitoring and OT security requirements—and why Singapore's CII owners can't treat compliance as a checkbox.
011
Graylog @graylog.bsky.social · 16/06/2026
Protecting the electric grid means complying with NERC CIP, 13 standards covering physical security, patch management, incident response, and more. Our blog explains what each standard requires and how a SIEM supports compliance without the overhead. graylog.org/post/ferc-an...
graylog.org
FERC and NERC: Cyber Security Monitoring for The Energy Sector
NERC CIP provides the basic cybersecurity control requirements for North American energy companies. Follow this blog for more info.
000
Graylog @graylog.bsky.social · 11/06/2026
Audit readiness is a sales strategy, not just a security one. When your controls, logs, and evidence are always organized and accessible, audits move faster, costs drop, and customers sign sooner. New post from on making audit readiness a business advantage: graylog.org/post/why-aud...
graylog.org
Why Audit Readiness Accelerates Revenue
Discover how audit readiness accelerates revenue by reducing delays, streamlining compliance, strengthening controls, and building trust with customers, auditors, and stakeholders.
000
Graylog @graylog.bsky.social · 08/06/2026
SaaS-only SIEM doesn't fail because the product is bad. It fails because the architecture assumes connectivity that some environments structurally cannot provide. Four of those environments — and what "run anywhere" actually requires 👇 graylog.org/post/the-fou...
graylog.org
The Four Environments Where SaaS-Only SIEM Fails
Air-gapped deployments, critical infrastructure, and data residency mandates expose the limits of SaaS SIEM. See the four environments where on-premises wins.
031
Graylog @graylog.bsky.social · 04/06/2026
Most orgs either over-retain logs (expensive) or under-retain them (risky). The sweet spot? Tiered storage + clear policies + automated lifecycle management. New guide: how to build a cost-effective log retention strategy that actually scales 👇 graylog.org/post/how-to-...
graylog.org
How to Build a Cost-Effective Log Retention Strategy
Log retention policies help organizations control how long logs are kept, where they’re stored, and when they’re deleted or archived. Learn the key steps, common challenges, and best practices for com...
041
Graylog @graylog.bsky.social · 03/06/2026
Turns out Graylog makes a surprisingly great IoT dashboard 🌡️ New lab guide: ESP32 + DHT22 sensor → HTTP API → live Graylog dashboard. Low cost, hands-on fun, and you'll actually learn something. 🔧 graylog.org/post/iot-sensor-lab-guide/ #IoT #HomeLab #ESP32 #Graylog
graylog.org
IoT Sensor Data into Graylog: A Lab Guide
Here's a howto for an IoT Sensor and sending data into Graylog. Attached is a DIY Lab Guide With an ESP32 Board for your next lab project.
052
Graylog @graylog.bsky.social · 01/06/2026
Graylog is recognized as an Aspiring vendor in the 2026 Gartner®️ SIEM Voice of the Customer report, with an 86% willingness to recommend (based on 52 reviews as of Jan 2026). Access the report. Link: graylog.org/post/graylog...
graylog.org
Graylog Recognized by Users in the 2026 Gartner®️ SIEM VOC
Graylog recognized as an Aspiring vendor in the 2026 Gartner®️ SIEM Voice of the Customer report, with an 86% willingness to recommend (based on 52 reviews as of Jan 2026). Access the report.
032
Graylog @graylog.bsky.social · 29/05/2026
Audit season got you anxious? We just dropped a whitepaper on 15 IT audit risks — covering identity, asset management, monitoring gaps, and config drift. Practical mitigations, not just theory. Built for lean teams in complex environments. Read it here → graylog.org/resources/15...
graylog.org
Ebook: 15 IT Audit Risks and Tactical Mitigation Strategies
Preparing for an IT audit? This Graylog guide covers 15 of the most common IT audit risks across identity and access management, asset management, security monitoring, and change and configuration man...
000
Graylog @graylog.bsky.social · 28/05/2026
Misconfigured cloud? That's how most breaches start. We mapped out 15 of the riskiest cloud misconfigurations — from overpermissive IAM roles to public S3 buckets to disabled logging — plus how to find and fix each one. graylog.org/post/15-risk...
graylog.org
15 Risky Cloud Misconfigurations and How To Mitigate Them
Learn the most common cloud misconfigurations, why they are risky, and practical ways security teams can identify and remediate cloud security risks.
041
Graylog @graylog.bsky.social · 26/05/2026
Most Windows environments are logging, but not watching the right things. Logons, privilege use, account changes, scheduled tasks, policy tampering, AD trust changes, AV telemetry. What's your SIEM actually alerting on? Link: graylog.org/post/critica... #CyberSecurity #BlueTeam #SIEM
graylog.org
Critical Windows Event ID's to Monitor
MIcrosoft offers a wide array of business critical technology solutions and logging capabilities to help manage security which can become overwhelming. This list of critical Event IDs to monitor can h...
041
Graylog @graylog.bsky.social · 21/05/2026
India's Digital Personal Data Protection Act (DPDPA) is here — and it applies to any org handling Indian residents' data. Link: graylog.org/post/indias-... #DPDPA #DataPrivacy #Cybersecurity
graylog.org
India's Data Protection Law: The Digital Personal Data Protection Act
Understand India’s Digital Personal Data Protection Act (DPDPA), including key rights, obligations, and practical steps organizations can take to achieve compliance and strengthen data security.
031
Graylog @graylog.bsky.social · 19/05/2026
Missed the Graylog 7.1 webinar? 🎬 The replay is live! Case-based triage, automatic investigations, Impossible Travel detection, dynamic sharding & more — all in 30 minutes. Watch on-demand → graylog.org/resources/we... #Graylog #LogManagement #Cybersecurity
graylog.org
Webinars: Webinar: What's New in 7.1
Graylog 7.1 is built for lean security and IT operations teams who need real outcomes, not more tools, more add-ons, or more manual work. This 30-minute deep dive session covers what's new and what it...
020
Graylog @graylog.bsky.social · 14/05/2026
The Australian Information Security Manual (ISM) was updated in Dec 2025, now covering AI, cloud, and modern threats. It's a risk-based framework across 6 principles: Govern, Identify, Protect, Detect, Respond, and Recover. link: graylog.org/post/underst... #CyberSecurity #InfoSec #ISM
graylog.org
Understanding the Australian Information Security Manual (ISM)
Master Australian ISM compliance with centralized logging, real-time dashboards, and incident workflows. Discover must-have SIEM capabilities for audit logging, threat detection, and forensic readines...
020
Graylog @graylog.bsky.social · 11/05/2026
OWASP dropped in 2026, the Top 10 for Agentic AI 🚨 The threat landscape for agentic systems goes way beyond prompt injection. Worth a read if you're building with AI agents. 🔗 graylog.org/post/what-is... #AgenticAI #OWASP #CyberSecurity #AppSec #LLMSecurity
graylog.org
What is the OWASP Top 10 Agentic AI
Explore OWASP’s 2025 Agentic AI Threats & Mitigations Guide. View the top risks of autonomous AI agent and strategies to secure multi-agent systems and safeguard data.
041