OSSEC HIDS Data in Graylog

OSSEC HIDS Data In Graylog

Host-based intrusion detection often lives at the edge of a SOC’s attention, generating a steady stream of file integrity alerts, authentication events, and active response actions that rarely get the same scrutiny as firewall or EDR data. OSSEC HIDS has been quietly filling that role on Unix, Linux, and Windows systems for years, watching log […]

Recognizing and Mitigating Configuration Drift Risks

Recognizing and Mitigating Configuration Drift Risks

Sometimes, driving along an empty, straight stretch of highway can lead you to pay less active attention. As your mind wanders a bit, your car starts slowly drifting toward the lane next to you until a loud “HONK” brings you back to the here and now. In IT, the same thing can happen to systems. […]

Troubleshooting the Top 10 Microservices Issues

Troubleshooting the Top 10 Microservices Issues

In a famous I Love Lucy episode, Lucy and Ethel take jobs at a chocolate factory, tasked with wrapping each piece of candy as it passes by on a conveyor belt. Over time, the conveyor belt speeds up, making it difficult for them to keep pace with the work. As the chocolates start piling up, […]

Understanding Compliance with GDPR Requirements

Understanding Compliance with GDPR Requirements

Since its 2018 implementation, the European Union General Data Protection Regulation (GDPR) has been a foundational data protection law that changed how organizations collect, process, and manage sensitive data. The GDPR is one of the earliest regulations that establishes jurisdiction based on the data subject’s citizenship and residence rather than on the organization’s location. Additionally, […]

Graylog MCP Server How-To Webinar

Graylog MCP Server How-To-Webinar

Most of the time you already know what you are looking for in Graylog. The problem is getting there: building the right search, remembering the field names, narrowing down the stream, formatting the query. It works great, but there is a new way and its conversational. That changes with Graylog’s MCP server. It connects Graylog […]

Lateral Movement: Security Risk and Mitigation Strategies

Lateral Movement: Security Risk and Mitigation Strategies

If you’ve ever played laser tag or paintball, you know that hiding from your adversaries is critical. In the arena, this can look like hiding behind a large structure or crouching on the ground. You want to move stealthily to evade detection, keeping your opponents on the look out while still trying to achieve your […]

Suricata IDS/IPS Data in Graylog

Suricata IDS-IPS Data in Graylog

If you’re running Suricata to watch your network, you already know how much signal lives in its logs. Graylog provides a purpose-built way to make that signal immediately actionable. The Suricata IDS/IPS Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, and a dashboard […]

Unlock Email Threat Visibility with Mimecast and Graylog

Email Threat Visibility with Mimecast and Graylog

Email threats aren’t slowing down. From credential phishing to malware-laced attachments, email remains one of the most exploited entry points for attackers. If you’re already using Mimecast to help mitigate that risk, you’re ahead of the curve — but raw log data only gets you so far. Starting with Graylog 6.2.3, you can pull logs […]

AWS WAF Data in Graylog

AWS WAF Data in Graylog

If you’re running applications behind an Application Load Balancer, Amazon CloudFront, API Gateway, or AWS AppSync, AWS WAF is your first line of defense against malicious web traffic. Graylog provides a purpose-built way to make those enforcement decisions immediately actionable. The AWS WAF Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog […]

Building Efficient Cyber Investigation Workflows

Building Efficient Cyber Investigation Workflows

Treasure hunts can come in two different forms. For fans of pirates, a treasure hunt often implies following a map to a far off, distant location. On the other hand, as a kid, you might have been giving a series of clues, with each hint leading to another one until you reached the final treasure. […]

Microsoft WinRM Data in Graylog

Microsoft WinRM Data in Graylog

If you’re running Windows in your environment, WinRM is one of the most valuable, and most abused channels in your infrastructure. Graylog provides a purpose-built way to make those logs immediately actionable. The Microsoft WinRM Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, […]