← All cheat sheets

GRAVWELL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

SIEM and log analytics platform. Handles structured, unstructured,
and binary data. Community edition available for free.

INSTALLATION#

# Community Edition (free, single node)
# https://www.gravwell.io/download

# Debian/Ubuntu
sudo apt install gravwell

# Docker
docker run -d --name gravwell -p 443:443 gravwell/gravwell

# Access web UI: https://localhost
# Default login: admin / changeme

SEARCH QUERY LANGUAGE#

# Basic search
tag=syslog
tag=windows
tag=firewall

# Filter
tag=syslog grep "error"
tag=syslog grep -v "info"                   # Exclude

# Time range (set in UI or query)
tag=syslog grep "failed" | count
tag=windows grep "4625"                     # Failed logons

# Modules (pipe-based)
tag=syslog | regex "(?P<ip>\d+\.\d+\.\d+\.\d+)" | count by ip | sort by count desc | table ip count
tag=syslog | words | count by word | sort by count desc | table word count
tag=json | json hostname ip | count by hostname | table hostname count

KEY MODULES#

grep          # String search
regex         # Regex extraction
json          # JSON field extraction
csv           # CSV parsing
xml           # XML parsing
kv            # Key-value parsing
count         # Count entries
sum           # Sum values
mean          # Average
min / max     # Min/max values
unique        # Unique values
sort          # Sort results
table         # Table display
chart         # Chart display
gauge         # Gauge display
pointmap      # Geographic map
lookup        # Lookup table enrichment
anko          # Scripting (Go-like)
ip            # IP address operations
subnet        # Subnet matching

DASHBOARDS#

# Create via UI: Dashboards > New
# Add tiles: search queries rendered as charts/tables/gauges
# Auto-refresh for real-time monitoring
# Share dashboards across team

INGEST#

# Syslog
# Configure rsyslog to forward to Gravwell
# Simple Relay ingester (built-in)

# File follower (tail files)
# Windows Event Log ingester
# Netflow/IPFIX ingester
# Kafka ingester
# AWS/Azure/GCP cloud ingesters
# PCAP ingester

TIPS#

  - Community edition is free for up to 2GB/day ingest
  - Pipe-based query language is intuitive
  - Handles binary data (PCAP, images) natively
  - Dashboards support real-time auto-refresh
  - Lookup tables for threat intel enrichment
  - Anko scripting for complex analysis
  - Lighter weight than Splunk/ELK for smaller teams
  - API available for automation
  - Kits provide pre-built dashboards and queries
  - Good alternative to ELK for security operations