GRAVWELL
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
SIEM and log analytics platform. Handles structured, unstructured, and binary data. Community edition available for free.
INSTALLATION#
# Community Edition (free, single node) # https://www.gravwell.io/download # Debian/Ubuntu sudo apt install gravwell # Docker docker run -d --name gravwell -p 443:443 gravwell/gravwell # Access web UI: https://localhost # Default login: admin / changeme
SEARCH QUERY LANGUAGE#
# Basic search tag=syslog tag=windows tag=firewall # Filter tag=syslog grep "error" tag=syslog grep -v "info" # Exclude # Time range (set in UI or query) tag=syslog grep "failed" | count tag=windows grep "4625" # Failed logons # Modules (pipe-based) tag=syslog | regex "(?P<ip>\d+\.\d+\.\d+\.\d+)" | count by ip | sort by count desc | table ip count tag=syslog | words | count by word | sort by count desc | table word count tag=json | json hostname ip | count by hostname | table hostname count
KEY MODULES#
grep # String search regex # Regex extraction json # JSON field extraction csv # CSV parsing xml # XML parsing kv # Key-value parsing count # Count entries sum # Sum values mean # Average min / max # Min/max values unique # Unique values sort # Sort results table # Table display chart # Chart display gauge # Gauge display pointmap # Geographic map lookup # Lookup table enrichment anko # Scripting (Go-like) ip # IP address operations subnet # Subnet matching
DASHBOARDS#
# Create via UI: Dashboards > New # Add tiles: search queries rendered as charts/tables/gauges # Auto-refresh for real-time monitoring # Share dashboards across team
INGEST#
# Syslog # Configure rsyslog to forward to Gravwell # Simple Relay ingester (built-in) # File follower (tail files) # Windows Event Log ingester # Netflow/IPFIX ingester # Kafka ingester # AWS/Azure/GCP cloud ingesters # PCAP ingester
TIPS#
- Community edition is free for up to 2GB/day ingest - Pipe-based query language is intuitive - Handles binary data (PCAP, images) natively - Dashboards support real-time auto-refresh - Lookup tables for threat intel enrichment - Anko scripting for complex analysis - Lighter weight than Splunk/ELK for smaller teams - API available for automation - Kits provide pre-built dashboards and queries - Good alternative to ELK for security operations