Full-Time
Ingests and analyzes any data types
No salary listed
Remote in USA
Remote
Bachelor's
See people who can refer or advise you
Gravwell builds a full-stack analytics platform for enterprise data. It ingests any kind of data—text logs, binary data, network traffic, or industrial process data—in its native format without predefined schemas, and then stores, indexes, visualizes, and analyzes it in real time. The product enables threat hunting, incident response, and observability across IT and operational technology environments, with a flexible query language and alerts to support deep investigations. Gravwell differentiates itself by pricing based on the number of deployed indexers (not data volume), encouraging customers to collect and retain all data without penalties for ingestion spikes. This approach supports a wide data intake and avoids forcing data loss to cut costs. Its goal is to help organizations see and understand large, diverse data sets quickly, turning raw information into actionable insights across cybersecurity, IT, manufacturing, and logistics.
Company Size
11-50
Company Stage
Seed
Total Funding
$3M
Headquarters
Hailey, Idaho
Founded
2017
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Flexible Work Hours
Remote Work Options
264% ROI in new Forrester Consulting TEI study. 29 July 2026 Security teams using legacy SIEMs face rising data volumes, limited resources, fragmented tools, and growing operational complexity, while outdated architectures and pricing models make security data costly to collect, difficult to manage, and slow to investigate. Security analysts using legacy SIEMs often move between disconnected tools to piece together evidence while contending with a flood of false positives from poorly tuned detections. At the same time, engineers devote significant time and resources to maintaining brittle ingestion pipelines and parsers, while security leaders must decide which logs they can afford to retain and which visibility gaps they are willing to accept. A new Total Economic Impact(TM) study conducted by Forrester Consulting examines how the Gravwell Security Data Platform helped organizations overcome these constraints, reduced tradeoffs, and strengthened security operations with a more flexible, cost-effective approach to data ingestion, storage, and analysis. Gravwell commissioned Forrester Consulting to interview Gravwell customers and develop a composite mid-sized, regulated organization with four security analysts, tens of thousands of users, more than 9,000 endpoints and cloud resources, and hundreds of gigabytes of daily log volume. Forrester then evaluated the potential costs, benefits, flexibility, and risks of deploying Gravwell over three years. The study found that the composite organization achieved a 264% return on investment, $743,000 in net present value, and payback in less than six months. More importantly, Gravwell helped the security team investigate incidents faster, build better detections, reduce platform maintenance, streamline compliance reporting, and expand visibility without escalating ingest costs. 65% Faster Investigations, From Alert to Evidence Security investigations slow down when the evidence analysts need is scattered across identity, endpoint, SaaS, network, cloud, and infrastructure systems. Before Gravwell, customers interviewed by Forrester described manually gathering logs from multiple portals, requesting data from other teams, and correlating information by hand. Analysts could spend hours, or even multiple business days, collecting and validating evidence before reaching a conclusion. Gravwell centralizes security data in a time-series data lake, giving analysts a single queryable environment where they can move directly from an alert to the underlying evidence without switching tools or piecing together incomplete datasets. For the composite organization, Forrester modeled a 65% reduction in investigation time, enabling analysts to triage alerts, validate suspicious activity, and determine whether escalation was necessary far more quickly. This matters especially for false positives. Gravwell gives analysts the context to resolve them quickly, so low-value activity does not consume hours that should be spent on genuine threats. Build better detections, 70% Faster Legacy SIEM detection engineering often requires analysts to navigate proprietary rule formats, rigid schemas, indexes, preprocessors, and multiple configuration layers. That complexity slows the creation of new detections and makes existing logic difficult to tune. It can also force teams to rely on generic out-of-the-box content that does not reflect how their environment actually operates. Gravwell, with its lauded query capabilities, gives analysts a flexible workflow for creating and modifying detections. Logic can be reused, adapted, and applied across workflows without rebuilding an extensive processing chain. Forrester modeled a 70% reduction in the time required to create or materially modify detections. The benefit extends beyond speed. Customers reported that greater data access allowed them to build more precise detections, expand monitoring coverage, establish earlier thresholds, and reduce the number of irrelevant alerts and false positives reaching analysts. 90% Less SIEM Maintenance Means More Time for Security Before Gravwell, Forrester's composite organization spent 15 hours per week maintaining its legacy SIEM. That included managing ingestion pipelines, troubleshooting formatting problems, patching systems, maintaining schemas, repairing parsers, and responding whenever an upstream data source changed. Gravwell's structure-on-read architecture allows organizations to ingest data in its original form and structure it when queried. Teams do not need to normalize every source before the data becomes searchable. Forrester modeled a 90% reduction in ongoing SIEM administration effort as a result of removing much of the recurring pipeline, parsing, and mapping work associated with traditional SIEMs. Engineers can onboard diverse data sources more quickly and spend more time improving security operations and detections instead of keeping data flowing. Gravwell's Mission Support team also helps customers migrate data, replicate existing use cases, validate ingestion, and transition from legacy platforms. Customers described implementation effort as manageable and praised the hands-on support they received throughout onboarding. Compliance and Audit Made Easier with 80% Reduction in effort Compliance, audit, legal, and regulatory requests may be episodic, but they can consume substantial time when they arrive. Without centralized historical data, teams must coordinate across departments, export information from several systems, validate it, and manually compile it into a usable report. Due to cost, teams are often forced to minimize the time they retain data or move it to cold storage where it's more difficult to retrieve. Gravwell gives organizations a single source of truth for historical security data. Analysts can retrieve, correlate, validate, and export evidence through repeatable queries, dashboards, reports, and automated workflows. Forrester modeled an 80% reduction in effort per compliance, audit, legal, or regulated reporting request. Work that previously required hours of manual collection can be completed through a saved query or automated report, reducing disruption while improving the speed and consistency of the response. 60% Reduction in SIEM Cost Reduces ingest anxiety Many SIEM pricing models turn increased visibility into increased cost. As log volumes grow, organizations are forced to filter data, shorten retention, sample events, or exclude valuable telemetry altogether. Some customers interviewed by Forrester reported exceeding licensed event limits and dropping logs without knowing whether those missing logs contained critical activity. Gravwell removes the direct connection between data ingestion and licensing costs. Organizations can collect and retain the data they need without creating a larger bill every time data volumes increase. Forrester's composite organization replaced a legacy SIEM costing approximately $310,000 annually. The study modeled more than a 60% reduction in SIEM costs and nearly $694,000 in risk-adjusted present-value savings over three years. The result is a more predictable operating model that allows security leaders to plan around business requirements rather than ingestion thresholds. Give security teams room to scale By centralizing more data and reducing manual work, Gravwell helps security teams investigate faster, improve detections, reduce maintenance, accelerate compliance, and control costs without sacrificing visibility. The Forrester study shows how organizations can use Gravwell to strengthen and scale security operations on a single flexible data foundation. Download the complete Total Economic Impact(TM) study to explore the findings. Gravwell commissioned Forrester Consulting to conduct this Total Economic Impact(TM) study. The results are based on interviews with four Gravwell customers and the financial analysis of a composite organization. Results experienced by other organizations may vary.
From raw data to answers: meet the new Logbot. 26 May 2026 Today, Gravwell, Inc. is excited to announce a new and improved Logbot, Gravwell's AI-powered security data assistant, as part of Gravwell v5.9. The release adds deeper platform integration, faster natural-language investigation workflows, instant playbook and automation generation, and bidirectional AI integrations through MCP. These upgrades bring AI-driven assistance directly into daily workflows, helping practitioners get to answers faster and do more with complex security data. Security data is the backbone of today's security operations, but using it effectively at scale is a resource-intensive, time-consuming challenge for even the most seasoned practitioners. At the same time, the domain expertise required in SecOps creates a steep barrier for junior analysts to be impactful, making it no surprise that teams are turning to AI for support. Logbot is Gravwell's answer to those challenges, helping teams work through complexity faster and with less reliance on specialized expertise. Think of it as an embedded security guru that combines the capabilities of an engineer, architect, and analyst in one assistant to help users query, interpret, and act on security data faster. Logbot works with knowledge of your environment and knowledge base, along with broader security best practices, to help with tasks like query writing and working with frameworks such as OCSF. Writing accurate, meaningful queries, translating between query languages, or simply asking questions about your data or Gravwell cluster is as easy as using a natural language prompt. The result is a democratization of knowledge across the organization that drives better understanding, less manual effort, and a major boost in analyst productivity. Here's what to expect from the latest Logbot release: Deep Platform Integration:Logbot connects directly to live Gravwell systems via API and embeds into customer workflows through a natural chat interface. That means users can ask practical questions about their environment, such as "How is my cluster doing?" or "Where can I find this tag?", and get instant answers without digging through menus, documentation, or raw data. In this example, a customer asks Logbot to perform an audit of scheduled searches and alerts to make sure they're executing properly, in sync, and as expected. Logbot identifies enabled jobs that are not actually running, and surfaces the issue in a clear findings table that includes searches with a "Last Run" of never despite being enabled. Logbot checks scheduled searches and alerts, then flags critical issues where expected jobs are not actually running. After checking available flows and alert configuration requirements, Logbot enables the alert and scheduled search, confirms the consumer and schema details, and reports that both are now active. Logbot validates the dependencies needed to turn on alerting, enables the critical alert, then enables the scheduled search and confirms both are successfully running. Efficiency Gains: Logbot helps bridge the gap between raw data and understanding. It turns raw logs into actionable answers that speed up triage, reduce time spent searching for context, and help analysts respond with greater confidence. Logbot also generates playbooks and automations instantly, eliminating manual effort and reducing the need for deep technical expertise. In this example, a customer asks Logbot to create a full "Storage Expansion Action Plan" playbook with monitoring guidance and utilization thresholds. Logbot converts a simple request into a formal storage expansion playbook with decision criteria and operational guidance. The user's natural language prompt results in a structured playbook that recommends how to monitor storage growth and when to start planning for expansion, including utilization context, monitoring objectives, key metrics, and a recommended review schedule. The playbook captures current storage utilization, defines what to monitor, and outlines how to plan for future expansion. Logbot can also boost efficiency by quickly building, refining, and running queries to accelerate investigations, including translating queries from other query languages. This reduces reliance on query language expertise and shifts the focus from "how do I query" to "what do I want to know?" Users can use natural language prompts to translate queries from any query language into Gravwell query language or reconfigure queries to fit frameworks such as OCSF. In this example, Logbot uses saved search context to create a query for "User logged in" events and chart login counts over time that the user can copy and paste. This handy capability saves time and helps level-up more junior analysts who are not yet fluent in the query language. A natural-language prompt becomes a working Gravwell query that tracks user logins and visualizes them in a time-series chart. AI Tool Integration: Logbot functions as both an MCP server and MCP client, enabling bidirectional AI integrations across the security stack. In practice, that means teams can query Gravwell from other MCP-enabled tools or bring data from those tools into Gravwell to enrich investigations in one place. Logbot querying Gravwell through an MCP-enabled AI tool to check cluster health in plain language, showing how teams can bring live security platform context directly into their AI workflows. Logbot data is private and local: Logbot is based on open weight models hosted on Gravwell-owned infrastructure. Conclusion Logbot helps teams move from raw data to real answers faster, with less manual effort and less reliance on specialized expertise. By combining deep platform integration, natural language interaction, and private deployment within your environment, it gives practitioners a more accessible and efficient way to investigate, automate, and understand their security data. The new Logbot is another step toward making security operations faster, smarter, and easier to scale. Learn more about Logbot here, and take a deeper dive into Logbot on its docs page here.
Gravwell raises $15.4 million in Series A to redefine data analytics for security and IT operations. Gravwell, a next-generation data analytics and observability platform, has announced a $15.4 million Series A funding round, led by Two Bear Capital, with participation from Gula Tech Adventures, Next Frontier Capital, and other strategic investors. The funding marks a pivotal step in Gravwell's mission to provide enterprises and government organizations with a faster, more flexible, and cost-efficient way to search, analyze, and act on massive volumes of data without the limitations of traditional systems. Founded by Corey Thuen, Gravwell was built out of frustration with legacy data tools that restricted access through expensive licensing, rigid query structures, and slow performance. The company's platform reimagines data ingestion and analytics from the ground up, offering full-fidelity data capture, query-anything flexibility, and scalable analysis for security, IT, and operations teams alike. Why Gravwell exists: breaking free from legacy limitations. Data is growing faster than ever - but traditional tools like Splunk and Elasticsearch weren't designed for the scale, speed, and cost constraints today's organizations face. Gravwell addresses these pain points head-on with a platform that eliminates data sampling, arbitrary storage limits, and restrictive pricing models. At its core, Gravwell allows teams to ingest any data - structured or unstructured - at full fidelity, ensuring that no detail is lost during analysis. Its query engine empowers users to search raw binary, text, or event data in real time, regardless of format or source. "Security analysts and engineers shouldn't have to choose between insight and affordability," said Corey Thuen, CEO of Gravwell. "We built Gravwell to restore control to the teams closest to the data, so they can explore, investigate, and innovate without constraint." A data platform built for the real world. Gravwell's approach is refreshingly pragmatic - it focuses on real-world problems faced by modern data teams, especially those working in cybersecurity, DevOps, and critical infrastructure. * Unlimited data ingestion and retention, allowing users to keep and query all their logs without compression losses. * Flexible data parsing, enabling analysis of any format - from network packets to machine telemetry. * Powerful visualizations and automation tools, empowering both technical and non-technical teams to extract value from complex datasets. * Self-hosted and hybrid deployment options, giving organizations total sovereignty over sensitive data. This combination makes Gravwell particularly valuable for defense contractors, critical infrastructure operators, and Fortune 500 companies, where data privacy, performance, and control are non-negotiable. Where Gravwell truly shines: security at scale. Security teams live in the trenches of data overload. Every day, they face terabytes of network telemetry, endpoint logs, and threat intelligence - often scattered across siloed systems. Gravwell unifies these data streams, enabling rapid correlation and threat hunting across diverse sources. The platform's real-time querying and full data retention help analysts uncover hidden attack paths and detect anomalies that traditional systems might miss. Moreover, Gravwell's cost-efficient storage model means that teams can store 10 - 100x more data for the same price, extending the window for forensic investigation and compliance audits. This "total observability" model gives enterprises a strategic advantage in defending against modern cyber threats - a growing necessity as global cybercrime costs are expected to hit $13 trillion annually by 2028 (Cybersecurity Ventures). The founder's vision: data freedom as a right. Before founding Gravwell, Corey Thuen worked in security operations and intelligence environments where he saw first-hand how limited data access hindered mission success. He envisioned a world where analysts, not vendors, controlled how data was collected, stored, and queried. "Our philosophy is simple," Thuen explains. "You own your data. You should decide how to use it - not the pricing tier of a SaaS tool." That conviction shaped Gravwell's entire architecture - open ingestion pipelines, flexible data schemas, and transparent pricing. It's a model that resonates deeply with both private sector teams and public institutions struggling under data gravity and compliance pressure. Founder insight: the hidden leverage of full-fidelity data. For founders building in data infrastructure or cybersecurity, Gravwell's playbook contains a powerful lesson: data constraints are often market opportunities in disguise. Many enterprise tools are built on limitations - whether in storage, pricing, or access - because those limits create predictable business models. But startups that can remove these constraints and offer freedom without complexity are poised to win loyalty and scale fast. By making full-fidelity data analysis affordable and accessible, Gravwell is not just selling software - it's selling empowerment. It gives customers the ability to answer any question, anytime, from any dataset, which translates directly into better decisions, faster response times, and deeper trust. Founders should take note: the future belongs to platforms that make data more usable, not more expensive. A strong investor coalition for the next stage. The Series A round unites some of the most respected names in tech and cybersecurity investment: * Two Bear Capital, known for backing high-impact, technical founders who build defensible platforms in cybersecurity and healthtech. * Gula Tech Adventures, led by former Tenable co-founder Ron Gula, who brings unmatched expertise in scaling cybersecurity ventures. * Next Frontier Capital, a champion of mission-driven companies growing from America's innovation hubs. Together, these investors are fueling Gravwell's global expansion, product innovation, and customer success initiatives, setting the stage for accelerated adoption in enterprise and government markets. Market outlook: the data explosion and analytics opportunity. The timing of Gravwell's funding couldn't be better. According to IDC, global data creation is expected to surpass 180 zettabytes by 2025, with cybersecurity, IoT, and automation driving a majority of that growth. Simultaneously, data observability and analytics are projected to reach a market size of $70 billion by 2030, expanding at a CAGR of 18% (MarketsandMarkets). Organizations are desperate for tools that help them retain, manage, and make sense of their data in real time - without skyrocketing costs. This creates a perfect storm for Gravwell's growth. Its hybrid-friendly, full-fidelity analytics engine sits squarely at the intersection of cybersecurity, compliance, and data operations - three sectors now converging under regulatory and technological pressure. What's next for Gravwell. With $15.4 million in new funding, Gravwell plans to: * Expand its engineering and customer success teams, particularly in cybersecurity and analytics R&D. * Enhance integrations with SIEM, SOAR, and cloud-native observability platforms. * Invest in AI-assisted analysis, enabling faster pattern recognition and anomaly detection. * Grow its footprint in both the U.S. public sector and international enterprise markets. The company will also continue to strengthen its partnerships with government agencies and Fortune 100 customers, focusing on large-scale deployments that prove the power of full-fidelity analytics in mission-critical environments. A new era of data empowerment. As data continues to grow exponentially, the ability to analyze everything - not just samples - becomes a competitive necessity. Gravwell is betting that the next generation of analytics platforms will be defined not by how much they simplify data, but by how much freedom they give to those who use it. In a world where insight is power, Gravwell isn't just building a product - it's building a philosophy of total data ownership and operational transparency. And with this new round of funding, that vision is set to scale globally. Growth & scaling insights. Latest additions.
Gravwell closes $15.4M funding round to expand data analytics and Security platform. The Series A round was led by Two Bear Capital and included participation from Gula Tech Adventures, Next Frontier Capital, and others. IT Security
Gravwell raises $15.4M in Series A funding. Gravwell, a Minneapolis, MN-based full-stack data analytics and security platform provider, closed a $15.4m Series A funding round. The round was led by Two Bear Capital with participation from Gula Tech Adventures, Next Frontier Capital, and others. The company intends to use the funds to expand its product offering, and go-to-market strategies to grow the business. Led by Corey Thuen, CEO, Gravwell provides a full-stack data analytics and security platform that enables organizations to collect, observe, and analyze ground data from IT and OT systems to stay operational and secure. Enterprises use it to centralize massive volumes of logs, accelerate cybersecurity threat hunting, and gain unprecedented visibility across their environments, including the emerging challenge of auditing AI agent activity. By ingesting and analyzing every event, command, and interaction, the system helps organizations detect anomalies, investigate threats, and ensure AI systems behave as intended.