Critical Windows Event ID’s to Monitor
Like most organizations, your company likely invested in various Microsoft products. The Microsoft ecosystem provides businesses with nearly every kind of technology necessary, from workstation operating systems to Azure to Windows 365 that includes cloud-native versions of their traditional Office tools and the communication platform Teams. However, attackers are just as invested in the Microsoft […]
India’s Data Protection Law: The Digital Personal Data Protection Act
In 2023, India’s Parliament approved and published The Digital Personal Data Protection Act (DPDPA). In many ways, the DPDPA is similar to other regulations, like the General Data Protection Regulation (GDPR). It establishes a similar data subject, or in this case Data Principal, rights of notice, consents, access, correction, and erasure. In other ways, the […]
The Value of a Robust Vulnerability Management Program
Back before live security video feeds in homes, people would walk around at night checking to make sure they locked every window and door. They took these precautions because they knew that a single open lock gave burglars an opportunity to steal from them. For organizations, vulnerability management programs are a way to lock the […]
What To Know About Parsing JSON
If you grew up in the 80s and 90s, you probably remember your most beloved Trapper Keeper. The colorful binder contained all the folders, dividers, and lined paper to keep your middle school and high school self as organized as possible. Parsing JSON, a lightweight data format, is the modern, IT environment version of that […]
Data Pipeline Management for Security and Observability

In a lot of role-playing video games, the items that you can collect along your journey help you later in the narrative. A few branches can help you build a fire while you might use some logs to construct a boat. Some people have a strategy that relies on looting every item in an area, […]
25 Linux Logs to Collect and Monitor

While “America runs on Dunkin”, IT increasingly runs on Linux. Between being open-source and highly customizable, everything from video games to enterprise servers can run on Linux. When cloud services took over the corporate IT environment, they brought Linux with them in the form of virtual servers and containers. Meanwhile, developers increasingly use Linux-based Docker […]
Suricata IDS/IPS Data in Graylog
If you’re running Suricata to watch your network, you already know how much signal lives in its logs. Graylog provides a purpose-built way to make that signal immediately actionable. The Suricata IDS/IPS Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, and a dashboard […]
What Is Application Performance Management? A Cloud-Native Guide for Engineering Leaders

It’s five o’clock on a Friday night, and as you head onto the highway, you realize that traffic has come to a full and complete crawl. While grumbling to yourself, “I could walk home faster than this,” you look out all your windows. All you can see in either direction are long lines of cars, […]
A Practical Guide for Managing Linux Syslog

As a child, playing hide-and-seek was fun. As the hider, you knew all the best places to avoid being found. As the seeker, you knew your friends well-enough to guess at their locations. The biggest prize as the seeker was finding someone quickly so that you could get back to the fun of hiding. In […]
Kubernetes Troubleshooting: The Complete Guide

You’re walking into a cineplex to meet up with a friend you haven’t seen in a few years. However, the movie you agreed to see is showing in three different theaters. Your friend arrived first, and sent you a cryptic text saying “on the left.” The problem is that you don’t know if he means […]
Graylog Academy: Free On-Demand Training Available

Free Online Graylog Analyst Training Efficient log management and analysis are crucial for maintaining robust IT infrastructures. To empower IT professionals and enthusiasts with the skills needed to harness the power of log data. Sign up at the Graylog Academy and take our Free Online Graylog Analyst Training! Why Graylog? Graylog is a […]
OSSEC HIDS Data in Graylog

Host-based intrusion detection often lives at the edge of a SOC’s attention, generating a steady stream of file integrity alerts, authentication events, and active response actions that rarely get the same scrutiny as firewall or EDR data. OSSEC HIDS has been quietly filling that role on Unix, Linux, and Windows systems for years, watching log […]