Logstail
Skip to Content

Logstail Documentation

What do you want to secure today?

Use Logstail to collect telemetry, monitor infrastructure, triage alerts, automate response, manage external exposure, enrich investigations with threat intelligence, and train teams with hands-on cybersecurity workflows.

Product areas

Pick the Logstail module that matches the workflow you are building.

Common use cases

Role-based paths that map real security operations work to the right docs.

SOC Teams

Detect, triage, investigate, and respond from one workflow.

Start with telemetry collection, search suspicious activity in Analytics, prioritize SOAR alerts, and turn validated alerts into cases.

Information you need

  • Install agents and confirm telemetry is flowing.
  • Search events and pivot through dashboards during triage.
  • Prioritize alerts by severity, MITRE mapping, status, and affected asset.
  • Create cases and track ownership, affected agents, context, and response progress.
Incident Response

Standardize response with cases, playbooks, integrations, and notifications.

Use cases for investigation tracking, playbooks for repeatable response, integrations for enrichment and action, and notification channels for escalation.

Information you need

  • Group one or more alerts into a case.
  • Build repeatable response workflows for common incident types.
  • Run integration actions for enrichment, blocking, checks, or log collection.
  • Route escalations to Slack, email, webhooks, or external channels.
Threat Hunting

Search telemetry, detect anomalies, and enrich suspicious indicators.

Use Discover, Insights, dashboards, and CTI observables to move from raw event data to validated threat context.

Information you need

  • Search logs by host, user, process, IP address, event type, or timestamp.
  • Review anomaly detection output and unusual behavior patterns.
  • Search file hashes, IPs, domains, and other suspicious observables.
  • Use adversary tooling context to support hunting and investigations.
Vulnerability & Exposure Management

Find internet-facing risk and track remediation evidence.

Run authorized EASM scans against domains, subdomains, public IPs, URLs, web apps, and external services, then review findings and reports.

Information you need

  • Define an approved target and select scan behavior.
  • Monitor running, scheduled, and completed scans.
  • Review exposed services, open ports, weak TLS, security headers, WAF gaps, and misconfigurations.
  • Export executive and technical PDF reports for stakeholders.
Compliance & GRC

Turn security data into audit-ready context and reporting.

Use compliance views, reports, dashboards, account data, and EASM evidence to support audit preparation and stakeholder communication.

Information you need

  • Maintain governance, risk, controls, vulnerabilities, and risk register data.
  • Generate reports from dashboards, visualizations, saved searches, or notebooks.
  • Track account usage, retention, subscription, and stack details.
  • Use EASM reports as external posture evidence.
IT & Network Operations

Monitor endpoints, network devices, collector health, and operational telemetry.

Use agent inventory, SNMP monitoring, pre-built dashboards, and saved objects to keep monitoring coverage operational.

Information you need

  • Monitor Windows and Unix/Linux agents by status, OS, group, or health.
  • Review endpoint hardware, software, services, processes, network data, issues, and vulnerabilities.
  • Monitor network device health, interfaces, traffic, alarms, and polling performance.
  • Deploy ready-made dashboards and manage reusable analytics objects.
Platform Administrators

Manage users, account context, runners, credentials, and operational settings.

Administer access, profile preferences, SOAR runners, integration credentials, CTI settings, and account-level details.

Information you need

  • Invite users and assign roles during onboarding.
  • Review account, subscription, usage, retention, and stack details.
  • Register and manage SOAR runners and runner groups.
  • Maintain integration credentials and CTI data source settings.
Security Enablement

Train analysts with guided paths, knowledge checks, and practical labs.

Use Logstail Academy to onboard SOC analysts, standardize security operations training, and practice attacker and defender workflows.

Information you need

  • Follow structured SIEM, SOAR, EASM, and investigation learning paths.
  • Validate knowledge with courses and quizzes.
  • Practice inside controlled Kali Linux, Debian, and Windows VM labs.
  • Build confidence before handling production security operations.

Fast paths

Not sure where to start? Jump straight into the highest-signal docs.