Graylog MCP Server How-To Webinar

Graylog MCP Server How-To-Webinar

Most of the time you already know what you are looking for in Graylog. The problem is getting there: building the right search, remembering the field names, narrowing down the stream, formatting the query. It works great, but there is a new way and its conversational. That changes with Graylog’s MCP server. It connects Graylog […]

Lateral Movement: Security Risk and Mitigation Strategies

Lateral Movement: Security Risk and Mitigation Strategies

If you’ve ever played laser tag or paintball, you know that hiding from your adversaries is critical. In the arena, this can look like hiding behind a large structure or crouching on the ground. You want to move stealthily to evade detection, keeping your opponents on the look out while still trying to achieve your […]

Suricata IDS/IPS Data in Graylog

Suricata IDS-IPS Data in Graylog

If you’re running Suricata to watch your network, you already know how much signal lives in its logs. Graylog provides a purpose-built way to make that signal immediately actionable. The Suricata IDS/IPS Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, and a dashboard […]

Unlock Email Threat Visibility with Mimecast and Graylog

Email Threat Visibility with Mimecast and Graylog

Email threats aren’t slowing down. From credential phishing to malware-laced attachments, email remains one of the most exploited entry points for attackers. If you’re already using Mimecast to help mitigate that risk, you’re ahead of the curve — but raw log data only gets you so far. Starting with Graylog 6.2.3, you can pull logs […]

AWS WAF Data in Graylog

AWS WAF Data in Graylog

If you’re running applications behind an Application Load Balancer, Amazon CloudFront, API Gateway, or AWS AppSync, AWS WAF is your first line of defense against malicious web traffic. Graylog provides a purpose-built way to make those enforcement decisions immediately actionable. The AWS WAF Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog […]

Building Efficient Cyber Investigation Workflows

Building Efficient Cyber Investigation Workflows

Treasure hunts can come in two different forms. For fans of pirates, a treasure hunt often implies following a map to a far off, distant location. On the other hand, as a kid, you might have been giving a series of clues, with each hint leading to another one until you reached the final treasure. […]

Microsoft WinRM Data in Graylog

Microsoft WinRM Data in Graylog

If you’re running Windows in your environment, WinRM is one of the most valuable, and most abused channels in your infrastructure. Graylog provides a purpose-built way to make those logs immediately actionable. The Microsoft WinRM Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, […]

The World Cup Creates the World’s Largest Attack Surface

The World Cup Creates the World's Largest Attack Surface

When 48 teams, 104 matches, 16 host cities, and a broadcast audience approaching half the planet converge across six weeks, something else converges at the same time: opportunity for the people trying to exploit it. The 2026 FIFA World Cup is the most complex digital event in history, and the security challenge it creates is […]

What Singapore’s CCoP 2.0 Requires of Critical Infrastructure Owners

What Singapore's CCoP 2.0 Requires of Critical Infrastructure Owners

Picture Singapore’s largest telecommunications network. It carries the financial transactions, emergency communications, and government data of a city-state of nearly six million people. Now picture that infrastructure silently infiltrated for months by a state-linked espionage group, undetected until the telcos’ own security teams found it. That is not a scenario exercise. In July 2025, Singapore’s […]

FERC and NERC: Cyber Security Monitoring for The Energy Sector

FERC and NERC Cybersecurity Monitoring for the Energy Sector

As cyber threats targeting critical infrastructure continue to evolve, the energy sector remains a prime target for malicious actors. Protecting the electric grid requires a strong regulatory framework and robust cybersecurity monitoring practices. In the United States, the Federal Energy Regulatory Commission (FERC) and the North American Electric Reliability Corporation (NERC) play key roles in […]

Why Audit Readiness Accelerates Revenue

Why Audit Readiness Accelerates Revenue

At 3am, you wake up in a cold sweat from a nightmare. The dream? You showed up to test for your most difficult class without having studied. Unprepared, your dream self sat in an uncomfortable desk, staring at a piece of paper and panicking. In the corporate world, an audit can induce the same sense […]

The Four Environments Where SaaS-Only SIEM Fails

The Four Environments Where SaaS Only SIEM Fails

Picture a cybersecurity team responsible for protecting a classified military installation in a remote operational theater. No internet connection. No cloud services. Classified and unclassified networks running on physically separate infrastructure. Their security information and event management system has to detect threats, correlate events, and generate alerts with zero external connectivity, for the entire deployment. […]