{"id":16393,"date":"2026-06-29T20:48:26","date_gmt":"2026-06-29T14:48:26","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=16393"},"modified":"2026-09-18T12:13:02","modified_gmt":"2026-09-18T04:13:02","slug":"may-the-logs-be-with-you-graylog-7-1-is-here-2","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/may-the-logs-be-with-you-graylog-7-1-is-here-2\/","title":{"rendered":"May the Logs Be With You: Graylog 7.1 Is Here"},"content":{"rendered":"<div class=\"et_pb_section_0 et_pb_section et_section_regular et_flex_section\">\n<div class=\"et_pb_row_0 et_pb_row et_flex_row\">\n<div class=\"et_pb_column_0 et_pb_column et-last-child et_flex_column et_pb_css_mix_blend_mode_passthrough et_flex_column_24_24 et_flex_column_24_24_tablet et_flex_column_24_24_phone\">\n<div class=\"et_pb_text_0 et_pb_text et_pb_bg_layout_light et_pb_module et_flex_module\"><div class=\"et_pb_text_inner\"><figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2026\/06\/image-8-1024x576.png\" alt=\"\" class=\"wp-image-16394\"\/><\/figure>\n<p>A long time ago, in a SOC far, far away\u2026analysts were drowning in alerts, chasing context across fragmented screens, and watching real threats slip past detection gaps. Today, the Rebellion fights back.<\/p>\n<p>This isn\u2019t a release built around a single marquee feature. It\u2019s the result of our team listening to you on the front lines with an ear for removing the friction that makes your jobs harder than they need to be. Graylog\u2019s R&amp;D team has outdone themselves, and I cannot wait for you to get your hands on what they\u2019ve built.<\/p>\n<p>Let\u2019s walk through it.<\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>A New Hope<\/strong>&nbsp;for<strong>&nbsp;Ending Alert Fatigue<\/strong><\/h2>\n<p>If there\u2019s one thing I hear from lean security teams more than anything else, it\u2019s this:&nbsp;<em>\u201cI can\u2019t see the signal through the noise.\u201d<\/em>&nbsp;Alert fatigue is the dark side of a well-instrumented environment, and the more you monitor, the more you risk burying what matters.<\/p>\n<p>In 7.1, we attacked this problem from multiple angles.<\/p>\n<p><strong>Fundamental in 7.1 is a shift from an event-based triage experience to a case-based methodology.<\/strong><\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/graylog.org\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-16-at-2.39.44-PM.png\" alt=\"Workflow\"\/><\/figure>\n<p><strong>When we triage an individual alert, it\u2019s up to us to capture the context of what happened and connect it to other disparate alerts. This is all before we even know if it is a false positive.<\/strong><\/p>\n<p><strong>Automatic Investigation Creation creates investigations&nbsp;<\/strong>using your Asset Risk thresholds, with options to nuance risk thresholds by your user and machine groups to effectively capture where your risk appetite differs.<\/p>\n<p>Triage stays on the alert page with an added twist.<\/p>\n<p>7.1\u2019s Slice-By allows you to quickly filter on a column\u2019s values. For example, slice by<\/p>\n<ul class=\"wp-block-list\">\n<li>Investigation, sorted by Investigation Priority, to begin analyzing all the events of the investigations Graylog has created for you.<\/li>\n<li>Asset, sorted by Asset Risk, to see any other assets accumulating a higher risk score prior to hitting its threshold<\/li>\n<li>Status, sorted by Event Risk, to see if you have any re-occurring events that require tuning.<\/li>\n<\/ul>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/graylog.org\/wp-content\/uploads\/2026\/04\/View-Slide-By.png\" alt=\"View Slice By\"\/><\/figure>\n<p><strong>Back to our Investigation that Graylog has created for us, bulk select the events and hit replay.<\/strong><\/p>\n<p><strong>The Context Sidebar&nbsp;<\/strong>provides details on the event, procedure steps, and associated assets that stay with you as you progress your investigation.<\/p>\n<p>Additional features have been added to reduce the amount of scrolling and clicking needed to wrap up your investigation.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/graylog.org\/wp-content\/uploads\/2026\/04\/Context-Sidebar.png\" alt=\"Context Sidebar\"\/><\/figure>\n<ul class=\"wp-block-list\">\n<li><strong>Event Summary Templates<\/strong>\u00a0on the Alerts page surfaces key details in the description field, such as the user and system, removing the need to open the Event row to see these details<strong>.<\/strong><\/li>\n<li><strong>Favorite Fields bubbles up the most vital fields to the top, in any order you specify.<\/strong><\/li>\n<li><strong>Bulk Add to Investigation quickly<\/strong>\u00a0adds all pertinent logs in one fell swoop?<\/li>\n<li>In the full-page view of the Investigation Merged Event Procedures, displays a deduplicated list of steps and groups similar actions together into a single click.<\/li>\n<\/ul>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/graylog.org\/wp-content\/uploads\/2026\/04\/Bulk-Add-To-Investigation.png\" alt=\"Bulk Add To Investigation Quickly\"\/><\/figure>\n<p>These aren\u2019t incremental improvements. They combine to provide demonstrable reduction in your detection and response times focused on the areas that represent the highest probability of compromise.<\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>Behavior Analysis Strikes Back<\/strong><\/h2>\n<p>We\u2019ve enhanced Graylog\u2019s&nbsp;<strong>Anomaly Detectors<\/strong>&nbsp;with greater flexibility, adding vendor agnostics, more tuning options, and faster resolution time with search replay.<\/p>\n<p>We have also added new baselining techniques for recognizing&nbsp;<strong>Impossible Travel&nbsp;<\/strong>v\u00e0&nbsp;<strong>Log Fluctuations.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\"><strong>The Infrastructure That Keeps the Hyperdrive Running<\/strong><\/h2>\n<p>None of the analyst-facing improvements matter if the platform underneath them is slow or fragile. The engineering team has made substantial investments in the data layer in 7.1 that I want to make sure don\u2019t get overlooked.<\/p>\n<p><strong>Dynamic Shard Sizing<\/strong>&nbsp;sets shard counts to their optimal value automatically \u2014 this is a meaningful improvement to search performance that many large customers will feel immediately. And&nbsp;<strong>Dynamic Shard Count for Restored Index Sets<\/strong>&nbsp;means that data lake restores now scale with the shard count, making retrieval significantly faster.<\/p>\n<p>For administrators managing large environments:&nbsp;<strong>MongoDB nodes are now visible on the Cluster Configuration page<\/strong>, and a full Inputs Page Revamp makes managing dozens of Inputs and Forwarder Input manageable.<\/p>\n<p>We also added&nbsp;<strong>License Usage Alerts<\/strong>, so you will never be surprised by where you stand against your ingest limits.<\/p>\n<p>This is the hyperspace jump your infrastructure didn\u2019t know it needed.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p><strong>Ch\u00fang t\u00f4i h\u1ed7 tr\u1ee3 nh\u01b0 th\u1ebf n\u00e0o<\/strong><\/p>\n<p>If you need to know more about May the Logs Be With You: Graylog 7.1 Is Here, you\u2019re in the right place, we\u2019re here to help! DTA is Graylog\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Nh\u1ea5n v\u00e0o \u0111\u00e2y \u0111\u1ec3 t\u00ecm hi\u1ec3u th\u00eam:&nbsp;<a href=\"https:\/\/dtasiagroup.com\/vi\/graylog\/\">https:\/\/dtasiagroup.com\/graylog\/<\/a><\/p>\n<\/div><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A long time ago, in a SOC far, far away\u2026analysts were drowning in alerts, chasing context across fragmented screens, and watching real threats slip past detection gaps. Today, the Rebellion fights back.<\/p>","protected":false},"author":11,"featured_media":16394,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-16393","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/16393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=16393"}],"version-history":[{"count":2,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/16393\/revisions"}],"predecessor-version":[{"id":17353,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/16393\/revisions\/17353"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/16394"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=16393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=16393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=16393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}