What does Gravwell do and what problem does it solve?
Gravwell is a unified observability and analysis platform that provides advanced log ingestion, detection, and investigation capabilities. It solves the problem of reacting to cyber threats by enabling proactive threat hunting through its AI-powered Logbot AI for log analysis. Evidence supports it as a security data platform.
What features, surfaces, or integrations does Gravwell offer?
Gravwell offers features including an analytics 'pipeline' query language, the ability to ingest any data source like PCAP in raw form, high availability, multi-tenancy, and AI-powered analysis via Logbot AI. It supports automated workflows, data visualization, and cloud deployment.
How is Gravwell priced or packaged?
Gravwell uses an indexer-based pricing model. For self-hosted deployments, pricing is based on the number of indexers, each with unlimited ingest capacity. There are Community, Pro ($35k+), and Enterprise ($70k+) editions. A Cloud Edition is also available.
What is Gravwell used for and in what situations?
Gravwell is used for real-time security alerting, incident response, and security data analysis in organizations of all sizes. It is suitable for on-prem, cloud, or hybrid environments, and for security teams looking to switch from SIEM to a Security Data Platform (SDP).
Who is Gravwell for?
Gravwell is for organizations of all sizes, specifically security teams and analysts who need to collect, analyze, and investigate security logs and data. It is designed for Enterprise SOCs and critical environments, but also offers a Community Edition for small commercial projects.
What is Gravwell?
Gravwell is a unified observability and analysis platform providing advanced log ingestion, detection, and investigation capabilities. It supports real-time security alerts and incident response for organizations of all sizes.