Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Graylog

@Graylog@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Centralized #logmanagement that actually works. #cybersecurity #infosec

396 Followers
325 Following
34 Posts
Joined November 14, 2022
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago

GDPR compliance isn't a one time checklist, it's ongoing monitoring and documentation.

Our latest blog walks through the 7 core principles, key articles like breach notification and DPIAs, and how centralized log management helps organizations stay audit ready and respond to incidents within GDPR's 72-hour window.

https://graylog.org/post/understanding-compliance-with-gdpr-requirements/

#GDPR #DataPrivacy #Compliance #InfoSec

graylog.org
1
0
1
0
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
Suricata IDS/IPS Data in Graylog
Graylog

Suricata IDS/IPS Data in Graylog

Graylog Suricata IDS/IPS Content Pack parses, enriches, and maps EVE JSON logs for instant network security visibility and threat detection.

1
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 4mo ago

🌡️ New lab guide: hook up an ESP32 + DHT22 sensor, create a tiny HTTP endpoint, and stream live temperature & humidity data straight into Graylog for a real-time dashboard.

Who said log management couldn't be fun? 🛠️

👉 https://graylog.org/post/iot-sensor-lab-guide/

#Graylog #IoT #HomeLab #ESP32 #LogManagement #DIY #MakerCommunity

graylog.org
1
0
1
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

Audit trails need two things working together: integrity (nothing alters the record) and confidentiality (only authorized people see it). Miss either one and the trail stops being useful evidence.

New post covers the difference between audit logs and audit trails, seven types of audit trails organizations generate, and a seven-step framework for building trail protection in from the start.

Read here:
https://graylog.org/post/protection-of-the-audit-trail-involves-both-integrity-and-confidentiality/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago

New webinar: Graylog MCP Server How-To.

Jeff Darrington shows Graylog Open users how to query streams, indices, and log data through Claude using natural language.

July 29th 10AM, 20 min content, 10 min Q&A. Part of our Getting the Most out of Graylog Open series.
https://graylog.org/open-webinar/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3w ago

Cloud-native APM comes with challenges monolithic systems didn't have: ephemeral infrastructure, tool sprawl, telemetry costs outpacing budget, and alert fatigue that buries the signal that matters.

Our new guide covers what APM is, how it differs from monitoring and observability, the direct and hidden costs of getting it wrong, and 5 best practices for engineering teams running distributed systems.
https://graylog.org/post/what-is-application-performance-management/
#APM #Observability #CloudNative #DevOps

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

New post: IT Audit: What It Is and How to Prepare for One
Covers the security/risk, compliance/governance, and operational continuity objectives auditors assess, plus where IT audits overlap with (and differ from) traditional financial audits.

It also digs into the tooling stack auditors expect to see evidence from: SIEM, vulnerability scanners, IAM, EDR, DLP, and audit logging platforms, and how centralized log management (hi, Graylog) cuts down the manual evidence-gathering work for lean security teams.
https://graylog.org/post/it-audit-what-it-is-and-how-to-prepare-for-one/
#ITAudit #Cybersecurity #Compliance #SIEM

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

On the Graylog blog: a full breakdown of FERC and NERC CIP compliance for the energy sector.

This covers all 13 enforceable standards, from BES Cyber System categorization to supply chain risk management, and how security monitoring ties it together.

https://graylog.org/post/ferc-and-nerc/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1w ago

WatchGuard Firebox Firewall Data in Graylog:
Your Firebox records every allowed and denied connection, user logon, IPS detection, and configuration change. The Graylog Illuminate content pack parses that Fireware syslog using message IDs and maps it to GIM.
https://graylog.org/post/watchguard-firebox-firewall-data-in-graylog/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

SOC 2 compliance guide, no fluff: Trust Services Criteria explained, Common Criteria controls mapped, and practical best practices for log collection, anomaly detection, incident response, and access management.

Link: https://graylog.org/post/the-definitive-soc-2-compliance-guide/

#SOC2 #Compliance #Cybersecurity #InfoSec

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago
We are proud to power the NOC at @BSidesLV@infosec.exchange, watching the traffic nobody else gets to see. #BSidesLV #graylog #NOC #cybersecurity #InfoSec
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago
AWS WAF sees every request hitting your ALB, CloudFront, API Gateway, or AppSync, and makes a block/allow/count/CAPTCHA/challenge decision on each one. The question is whether your security team can actually see and search those decisions. The AWS WAF Content Pack for Graylog parses the WAF JSON payload, normalizes the fields, and maps enforcement actions to the Graylog Information Model so they flow straight into detection and investigation workflows. Dashboard included. Details: https://graylog.org/post/aws-waf-data-in-graylog/ #SIEM #AWS #CloudSecurity #Graylog
AWS WAF Data in Graylog
Graylog

AWS WAF Data in Graylog

Graylog's AWS WAF Content Pack parses, enriches, and maps WAF block, allow, and challenge events for instant application security visibility.

0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack. With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data. New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools. Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/ #Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife
Unlock Email Threat Visibility with Mimecast and Graylog
Graylog

Unlock Email Threat Visibility with Mimecast and Graylog

Integrate Mimecast with Graylog to centralize email threat logs, speed investigations, and gain instant insights via Illuminate Dashboards.

0
1
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

The 2026 World Cup is the most complex digital event in history, and the threat window it creates isn't limited to FIFA.

Gaming platforms, payment processors, broadcasters, hospitality providers: all in scope.
A 30-second log delay means a stolen credential has 30 seconds of operational freedom before anyone sees the first signal.

That's not a performance issue. That's a security gap.
Link: https://graylog.org/post/the-world-cup-creates-the-worlds-largest-attack-surface/
#CyberSecurity #SIEM #SecurityOperations

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

New guide: Kubernetes Troubleshooting, The Complete Guide.
Covers the most common Kubernetes errors (CrashLoopBackOff, ImagePullBackOff, OOMKilled, Node Not Ready, stuck rollouts, DNS resolution failures) with root causes and diagnostic commands for each.

Also breaks down the three pillars of troubleshooting: understanding, management, and prevention, plus best practices for centralizing logs and building alerts that catch failures early.

https://graylog.org/post/kubernetes-troubleshooting-the-complete-guide/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 4mo ago

SaaS-only SIEM fails the moment it assumes connectivity that doesn't exist.

Air-gapped military networks. OT-isolated pipelines and power grids. Government research enclaves. Hard data residency mandates across the EU, GCC, and beyond.

In each case the issue isn't the product — it's the architecture.

New post: the four environments where cloud-first SIEM structurally cannot operate, and what actually works instead → https://graylog.org/post/the-four-environments-where-saas-only-siem-fails/

#InfoSec #SIEM #OTSecurity #DataSovereignty

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1w ago
Data pipeline management for security and observability comes down to five stages: collection, processing, routing, storage, and retrieval. Get them right and you control ingestion costs, cut alert fatigue with cleaner data, meet retention requirements for frameworks like SOC 2 and PCI DSS, and keep archived logs searchable when you need them. Full post: https://graylog.org/post/data-pipeline-management-for-security-and-observability/ #SIEM #Observability #LogManagement #InfoSec
Data Pipeline Management for Security and Observability
Graylog

Data Pipeline Management for Security and Observability

Learn how data pipeline management helps security and IT teams control SIEM costs, reduce alert fatigue, and stay audit-ready without losing visibility.

0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

Audit season doesn't have to mean panic mode.
Organizations that maintain audit readiness year-round spend less time scrambling for evidence, close deals faster, and demonstrate a mature security posture to customers and partners.

This blog covers practical steps, centralized log management, saved queries, retention policies, and more that turn audit prep from a fire drill into a repeatable workflow.
https://graylog.org/post/why-audit-readiness-accelerates-revenue/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 4mo ago

Storing every log forever? That's not security — that's a storage bill.

Effective log retention means tiering your data: hot for active monitoring, warm for periodic audits, cold for long-term compliance.

The right strategy keeps the signal, cuts the noise, and scales without breaking your budget.

New guide on building a cost-effective log retention strategy: https://graylog.org/post/how-to-build-a-cost-effective-log-retention-strategy/

#InfoSec #LogManagement #SIEM #Compliance

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

Getting logs into Graylog doesn't require a PhD in syslog or other log sources.

Sept 23, 10AM EDT: The Input Wizard, and the inputs pages

20 min content + 10 min Q&A. Make sure you're on the latest version.
Register here:

https://graylog.org/open-webinar

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 4w ago

On the Graylog blog:

a full breakdown of FERC and NERC CIP compliance for the energy sector. Covers all 13 enforceable standards, from BES Cyber System categorization to supply chain risk management, and how security monitoring ties it together.

https://graylog.org/post/ferc-and-nerc/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

Configuration drift happens quietly. A manual fix here, a hotfix there, a deployment that misses part of the fleet. Over time the gap between documented baseline and actual state grows until it surfaces as a security gap, a compliance failure, or an outage.

This new blog post covers the root causes and the practices that catch drift early, including baselining, continuous monitoring, and centralized logging.

https://graylog.org/post/recognizing-and-mitigating-configuration-drift-risks/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

WinRM is built into Windows and beloved by attackers for lateral movement.

Graylog's Microsoft WinRM Content Pack turns raw operational event logs into structured, GIM-tagged security intelligence, with parsing, enrichment, and a dashboard included.

Detect brute force, trace attacker paths, meet audit requirements.
https://graylog.org/post/microsoft-winrm-data-in-graylog/
#Graylog #WinRM #SIEM

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2w ago

Linux logs live in /var/log with no consistent naming convention, which makes them easy to overlook.

We rounded up 25 worth collecting and monitoring, along with the commands to read them.
https://graylog.org/post/25-linux-logs-to-collect-and-monitor/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2w ago

Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.

The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity

Suricata IDS/IPS Data in Graylog
Graylog

Suricata IDS/IPS Data in Graylog

Graylog Suricata IDS/IPS Content Pack parses, enriches, and maps EVE JSON logs for instant network security visibility and threat detection.

0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago

Singapore's CCoP 2.0 isn't a once-a-year audit exercise. It mandates continuous monitoring, behavioral anomaly detection, and integrated IT/OT coverage for good reason.

In July 2025, a Chinese-linked APT group was found operating inside all four of Singapore's major telcos, using techniques that signature-based detection misses entirely.

New Graylog blog breaks down what CCoP 2.0 actually requires and includes six indicators to assess your detection posture before your next audit.

Link: https://graylog.org/post/what-singapores-ccop-2-0-requires-of-critical-infrastructure-owners/

#Cybersecurity #SIEM #Singapore #CriticalInfrastructure

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3mo ago
New blog: Building Efficient Cyber Investigation Workflows A cyber investigation is a structured process, not just reacting to alerts. We cover the 5 key stages (identification, preservation, extraction/analysis, documentation, presentation) and share best practices for centralizing telemetry, reducing alert fatigue, and building repeatable workflows for lean security teams. https://graylog.org/post/building-efficient-cyber-investigation-workflows/ #CyberSecurity #InfoSec #SOC #IncidentResponse #Graylog
Building Efficient Cyber Investigation Workflows
Graylog

Building Efficient Cyber Investigation Workflows

Learn how to build efficient cyber investigation workflows for lean security teams by centralizing telemetry, improving threat detection, and streamlining incident response.

0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

Ten common micro-services issues, broken down by what to actually look for when debugging each one.

Covers distributed tracing gaps, cascade failures, API contract drift, deployment coordination, secrets management, service discovery, and more.

https://graylog.org/post/troubleshooting-the-top-10-microservices-issues/

#Microservices #Observability #DevOps #SIEM

Troubleshooting the Top 10 Microservices Issues
Graylog

Troubleshooting the Top 10 Microservices Issues

Distributed systems are powerful but notoriously hard to debug. Learn the 10 most common microservices troubleshooting challenges and what to look for when things go wrong in production.

0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago
Once attackers gain initial access, lateral movement is how they expand their reach without tripping alarms. They mimic legitimate admin behavior to pivot toward domain controllers, sensitive file shares, and databases. Our latest blog covers the techniques attackers use and the strategies (segmentation, least privilege, MFA, Zero Trust) that help security teams detect and contain it early. https://graylog.org/post/lateral-movement-security-risk-and-mitigation-strategies/ #CyberSecurity #SIEM #InfoSec #ThreatDetection
Lateral Movement: Security Risk and Mitigation Strategies
Graylog

Lateral Movement: Security Risk and Mitigation Strategies

Learn how lateral movement enables attackers to expand access across enterprise systems and how strong security controls can reduce dwell time and limit the impact of cyber attacks, phishing attacks, and ransomware attacks.

0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 3w ago

New guide: managing Linux syslog across mixed environments.

This covers the daemons (syslogd, rsyslog, syslog-ng, journald), where each distro stores logs, common challenges like permission issues and log rotation data loss, and best practices for configuring and centralizing syslog data.

https://graylog.org/post/a-practical-guide-for-managing-linux-syslog/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

Check out free Graylog Academy.

Whether you are new to Graylog or looking to level up your skills, Academy offers self-paced training on log ingestion, pipeline rules, dashboards, and log source onboarding. It is built by the people who build the product.

No catch.

Start learning: https://graylog.org/post/graylog-academy-free-training-available/
#Graylog #SIEM #LogManagement #FreeTraining

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago

When the CI/CD pipeline fails, everyone stops shipping and starts guessing.

Environment mismatches, expired credentials, flaky tests, infrastructure issues. The first error message is rarely the real root cause.

The fix isn't faster debugging. It's a repeatable investigation process: centralize logs from every pipeline stage, confirm scope, identify the failed step, isolate what changed.

https://graylog.org/post/building-a-process-for-investigating-deployment-failures-in-the-ci-cd-pipeline/

#DevOps #CICD #LogManagement #Observability

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 1mo ago

You downloaded Graylog Open. Now what?

Zero to Logs: Graylog Open Running Under an Hour walks you through a real install from scratch. Deployment choice, first data source, first search. No slides, no theory. Just a live terminal.
Wed Aug 26, 10AM EDT.
Register: https://graylog.org/open-webinar/

graylog.org
0
0
0
0
Open post
Graylog @Graylog@infosec.exchange
· 2mo ago
Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections. Most teams treat that as noise. It's early-warning threat telemetry. The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically. https://graylog.org/post/sendmail-data-in-graylog/ #SIEM #ThreatHunting #EmailSecurity
Sendmail Data In Graylog
Graylog

Sendmail Data In Graylog

Graylog Sendmail Content Pack parses, enriches, and maps mail server logs to GIM, turning routine MTA data into real threat detection signal."

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:47:10 UTC