Skip to content

Graylog Helm Chart Beta V.1.0.0 Announcement

2025-12-22   A log correlation engine automates the process of linking fragmented event data across diverse systems, transforming raw logs into real-time, actionable insights. By normalizing data and applying correlation rules, it reduces alert fatigue, accelerates incident detection (MTTD), and enables faster root cause analysis for improved security and operational efficiency.

Continue reading

SIEM Automation for Threat Detection & Response

2025-12-22   A log correlation engine automates the process of linking fragmented event data across diverse systems, transforming raw logs into real-time, actionable insights. By normalizing data and applying correlation rules, it reduces alert fatigue, accelerates incident detection (MTTD), and enables faster root cause analysis for improved security and operational efficiency.

Continue reading

Cloud vs. On-Premises SIEM: Choosing the Right Deployment

2025-12-22   A log correlation engine automates the process of linking fragmented event data across diverse systems, transforming raw logs into real-time, actionable insights. By normalizing data and applying correlation rules, it reduces alert fatigue, accelerates incident detection (MTTD), and enables faster root cause analysis for improved security and operational efficiency.

Continue reading

Supervised AI: The Fastest Path to Better Threat Triage ROI

2025-12-22   A log correlation engine automates the process of linking fragmented event data across diverse systems, transforming raw logs into real-time, actionable insights. By normalizing data and applying correlation rules, it reduces alert fatigue, accelerates incident detection (MTTD), and enables faster root cause analysis for improved security and operational efficiency.

Continue reading

Understanding Ransomware Email Threats

2025-12-22   A log correlation engine automates the process of linking fragmented event data across diverse systems, transforming raw logs into real-time, actionable insights. By normalizing data and applying correlation rules, it reduces alert fatigue, accelerates incident detection (MTTD), and enables faster root cause analysis for improved security and operational efficiency.

Continue reading

Understanding How a Log Correlation Engine Enables Real-Time Insights

2025-12-22   A log correlation engine automates the process of linking fragmented event data across diverse systems, transforming raw logs into real-time, actionable insights. By normalizing data and applying correlation rules, it reduces alert fatigue, accelerates incident detection (MTTD), and enables faster root cause analysis for improved security and operational efficiency.

Continue reading

Why a Cloud SIEM Just Makes Sense

2025-12-15   Cloud SIEMs solve the scalability and cost issues of traditional on-premises SIEMs by leveraging cloud-native resources. They offer flexibility, improved cost-effectiveness, and massive scalability for security data analysis. This enables robust threat detection, incident response automation (MITRE ATT&CK), and better insights across complex hybrid environments.

Continue reading

MCP ROI in a New Era of AI Orchestrated Threats

2025-12-08   The Model Context Protocol (MCP) inside Graylog delivers explainable AI assistance to the SOC, addressing the failure of fully autonomous tools. MCP enables faster, friction-free investigations by linking natural language queries to logs, enforcing governance, and providing verifiable context. This system helps security teams combat AI-orchestrated threats efficiently, yielding tangible ROI.

Continue reading

Announcing Graylog Illuminate v7.0


ADDED: New Content Packs & Features

  • Symantec Proxysg (419)

    Added alert_severity_level mapping based on event_action where applicable.

  • Checkpoint FW (2917)

    Added support for additional vendor_event_action values, including encrypt and decrypt. Restructured existing vendor fields to better align with log output: vendor_event_outcome is now vendor_event_action; vendor_event_outcome_reason is now vendor_event_action_reason; vendor_event_action is now vendor_event_operation.

  • Bitdefender GravityZone (3059)

    Added support for New Extended Incident logs. Included basic parsing for RPC formatted GravityZone logs for possible future extension via Filebeat testing.

  • Windows Security (2836)

    Added support for status code 0xC0000413 – STATUS_AUTHENTICATION_FIREWALL_DENIED.

  • Microsoft IIS Content Pack (1067)

    New content pack for Microsoft IIS (Internet Information Services), which is used for hosting web applications and services on Windows. Integrates tightly with ASP.NET and Windows Server ecosystem.

  • AWS Kinesis Content Pack (3076)

    New pack for Amazon Kinesis, supporting the parsing and categorization of AWS VPC Flow logs via AWS Kinesis for real-time data streaming and analysis. Future support for other log types may be added.

  • 1password Content Pack (2993)

    New content pack for 1Password logs, supporting the centralized storage and management of credentials, API keys, and sensitive information for improved security and simplified credential management.

  • Cisco Business 350 Series (CBS) (2263)

    New content pack for Cisco Business 350 Series Switches, supporting managed Layer 3 network switches designed for small and medium-sized businesses.

  • F5 BIG-IP (1137)

    Added a Content Pack that supports the AFM and ASM module.

FIXED: Bugs and Issues

  • NetFlow (2851)

    Fixed IPFIX message identification and added support for different set fields.

  • Bitdefender (3115)

    Fixed wrong input name.

  • Cisco ISE (3004)

    Modified base extraction regex to make syslog header info optional, enabling sending to a syslog or raw tcp input.

  • Symantec ProxySG (3125)

    Moved alert_severity_level lookup data to its own .csv to address lookup complaint of duplicate values.

  • Linux Auditbeat (2928)

    Corrected issue mapping vendor_event_type: changed-promiscuous-mode-on-device.

  • Cisco ISE (3019)

    Fixed CmdSet parsing so the full command is returned as vendor_cmdset, dropping CmdAV and CmdArgAV.

  • Bitdefender GravityZone (3007)

    Fixed wrong search path in the New Incidents Count widget.

  • Curated Alerts (2583)

    Improved rule: Illuminate – Windows Security – Active Directory Database Snapshot Via ADExplorer. The detector now covers execution of the 64-bit variant of ADExplorer.

  • Core DNS Processing (2675)

    Fixed filter causing inconsistent results in the dashboard.

CHANGED: Updates and Streamlining

  • NetFlow (3074)

    Changed NetFlow IPv4/IPv6 renames and field types.

  • Cisco IOS (2823)

    Streamlined identification rule logic to be more efficient.

  • PowerShell, Postfix, Meraki, SEPM, Sophos, Sonicwall, Cisco Meraki, Symantec Endpoint (Multiple IDs)

    Converted the use of multiple grok patterns per rule to use multi_grok for efficiency. Also, standardized gim_event_type_code mappings to align with detection categories and reclassified subtypes from alert to detection across multiple packs (e.g., Defender, Snort, Stormshield, Palo Alto, Fortigate, etc.).

  • Palo Alto (2824)

    Renamed spotlight title.

  • Schema (1940)

    Modified index templates to copy hash related fields (e.g., hash_md5, file_hash_) to associated_hash. This provides additional context to hash objects.

  • Palo Alto 11 (687)

    Updated colors for widgets that reference event_action to reflect schema.

  • AWS Security Lake (2314)

    Changed gim_event_category from alert to detection. The dashboard now supports both categories.

  • Bitdefender Telemetry (2950)

    Changed GIM codes for network events from 129999 (default) to 120200 (open) and 120300 (close).

  • Illuminate Core (3008)

    Disabled dynamic date detection for all Illuminate indices to fix mapping errors caused by inconsistent field formats.

  • Zeek (2618)

    Changed DNS request categorization to exclude NBSTAT.

  • Core (1711)

    Added support for MITRE ATT&CK Enterprise attacks_technique_uid & attacks_tactic_uid string values.

REMOVED / DEPRECATED Content

  • o365 (2957)

    Removed redundant type assignment in 22-o365_scc_categorize_alerts rule.

  • Bitdefender GravityZone (3058)

    Removed a possible leading forward slash for the source field (fixes issue when hostname is empty).

  • Compliance Content (2959)

    Removed deprecated ‘Compliance Content Spotlight (Deprecated)’ spotlight.

  • Palo Alto 9.1x (2716)

    DEPRECATED: The Palo Alto 9.1x Spotlight and associated processing content have been deprecated. Users should transition to the Palo Alto 11 Content Pack.

About Graylog
At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Graylog Redefines the Modern SOC with Explainable AI that Delivers Speed, Clarity, and Control

 

HOUSTON — Nov. 3, 2025 — Graylog, a leading provider of SIEM and threat detection solutions, today launched its Graylog Security Fall 2025 release (Version 7.0). The latest version introduces AI-driven insights, Model Context Protocol (MCP) Server Access, and Amazon Security Data Lake integration, enabling Security Operations Centers (SOCs) to operate with greater clarity, speed, and cost efficiency.

The new platform features AI-enabled dashboards for instant, explainable insights into threats. It provides MCP Server access, which securely connects Large Language Models (LLMs) directly to Graylog data for natural language queries. These capabilities deliver measurable efficiency gains for teams that need to accomplish more with fewer resources.

“Our focus is on helping them take back control, with practical AI that drives faster insights, smarter investigations, and measurable efficiency. With this release, we’re giving teams explainable AI they can trust. By combining innovation with simplicity, and AI with human insight, organizations can meet security challenges head-on with technology that works for them.”

— Seth Goldhammer, Vice President of Product Management at Graylog

Expanding Access to Security Data Through Natural Language

This release introduces Graylog MCP Server Access, a secure new way for teams to interact with their Graylog environment through natural language. The MCP Server securely connects user-approved AI agents or LLMs to Graylog, adding a conversational layer for querying and analysis—fully governed by user permissions and license tier.

Analysts (or their AI agents) can ask questions like:

  • “Show me assets that increased in risk score over the past week and are linked to open investigations.”
  • “Summarize the top five MITRE techniques detected across failed logins in the last 24 hours.”
  • “Which indices are nearing rotation thresholds, and how much storage is currently in use across the cluster?”

This capability boosts productivity and awareness by providing a faster, more intuitive way to interpret and act on security data.

Reducing Cost and Complexity with AWS Security Data Lake Integration

Graylog 7.0 introduces support for external data lake connectors to AWS Security Data Lake. This feature is crucial for controlling costs and managing complexity in hybrid cloud environments.

Key Capabilities:

  • Filtered Inputs: Ingest only the specific data required for active monitoring.
  • Preview and Selective Retrieval: Maintain visibility across AWS services without redundant storage.

This capability allows customers to reduce unnecessary transfer costs, storage usage, and licensing impact by keeping log messages not aligned with active analytics in AWS.

Redefining the SOC for the Real World

Built for lean, outcome-driven teams, Graylog unifies log management, SIEM, and AI-powered threat detection and investigation in a single, scalable platform. Unlike legacy SIEMs weighed down by cost and complexity, Graylog Security delivers transparent and understandable AI.

Every alert, summary, and recommendation is explainable, empowering security teams with clear context and control to respond faster and smarter.

The Graylog Security Fall 2025 release is available today. Visit Graylog to explore new features or talk to Graylog’s AI Concierge Arti.

About Graylog
At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.