Skip to content

Gravwell

A data-agnostic log fusion and analytics platform that lets security teams ingest and query any data type natively, positioned as a threat-hunting alternative to schema-constrained SIEMs.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

Gravwell is a data fusion platform built for security teams that need to search and correlate data Splunk-style tools struggle with once volume and variety grow past what a fixed schema can absorb. Rather than forcing logs into a predefined format at ingest time, Gravwell stores data in its native form — PCAP, NetFlow, Sysmon, binary telemetry, JSON, even video — and applies structure only when a query runs (schema-on-read). That architecture is the company’s core pitch: unlimited data types and retention without the parsing and normalization bottleneck that drives up cost and slows down investigations in conventional SIEM deployments.

Founded in 2017 and based in Coeur d’Alene, Idaho, Gravwell spent years as a bootstrapped, engineering-heavy shop selling primarily into government, defense, and critical-infrastructure environments that need air-gapped or on-premises deployment options alongside cloud. The company publicized early threat-hunting work at events like SC18’s SCinet, where its platform was used to help a network security team identify and respond to a large-scale DDoS attack in real time. In October 2025, Gravwell closed a $15.4 million Series A led by Two Bear Capital — a notably late first institutional round for a company founded in 2017, suggesting a long capital-efficient build before seeking outside growth capital.

The company competes against both entrenched SIEM incumbents and newer cloud-native log analytics platforms, and its differentiation rests almost entirely on ingest flexibility and query-time processing rather than a large pre-built detection content library. That makes it a fit for security teams with unusual or high-volume data sources (industrial control systems, packet capture, sensor telemetry) who have been burned by SIEM licensing costs tied to data volume, but it also means prospective buyers should weigh Gravwell’s smaller ecosystem and content library against the incumbents it displaces.

Innovation Matrix Assessment

Innovation Velocity 6/10

Gravwell has shipped incremental platform releases (e.g., version 4.1.0) since its 2017 founding and maintains cloud, on-premises, and air-gapped deployment options, but as a small team its release cadence is modest compared to venture-scaled SIEM competitors.

Operational Value 6/10

The platform is architected for genuinely difficult operational environments — air-gapped government and industrial networks — and supports arbitrary data types out of the box, but the vendor discloses little about uptime, scale limits, or support SLAs for a prospective enterprise buyer to evaluate independently.

Market Momentum 6/10

Gravwell operated for roughly eight years on bootstrapped/angel funding before closing a $15.4M Series A in October 2025 led by Two Bear Capital, a real external validation event, though the long pre-institutional runway suggests slower historical growth than venture-track peers.

Category Disruption 7/10

Schema-on-read ingestion of arbitrary data types (PCAP, NetFlow, Sysmon, binary, video) without upfront parsing is a genuine architectural departure from schema-on-write SIEM design, directly targeting the ingest-cost and normalization pain points that drive SIEM migrations.

Real-World Efficacy 5/10

The clearest documented efficacy evidence is a 2018 SC18/SCinet case study where a network security team used Gravwell to help identify and respond to a multi-terabit DDoS attack; beyond that, published proof points are vendor blog posts and customer testimonials rather than independent third-party evaluations.

Enduring Relevance 6/10

Demand for lower-cost, higher-flexibility log analytics remains strong as SOC teams push back on volume-based SIEM pricing, but Gravwell competes in a crowded field against far larger incumbents with deeper detection-content ecosystems.

Why CISOs Should Care

For organizations with unusual, high-volume, or non-standard data sources (ICS telemetry, packet capture, sensor data) that have outgrown what their SIEM can affordably ingest, Gravwell offers a way to retain and query that data without a costly re-architecture.

What Makes It Different

Most competitors require data normalization at ingest; Gravwell stores data natively and applies structure only at query time, which removes a major cost and latency bottleneck for high-volume or heterogeneous data environments.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A technically differentiated data fusion platform with a genuine architectural edge for hard ingestion problems, but still small-scale with thin independent validation of security outcomes beyond a handful of published case studies; worth evaluating for teams with data-diversity pain, not yet a default SIEM replacement.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: throughput/scale superlatives and most case study framing on Gravwell's own site. Independently verifiable: the October 2025 $15.4M Series A led by Two Bear Capital (reported by SecurityWeek/PR Newswire) and the 2017 founding date/Idaho headquarters.

Sources