The Island of Misfit Logs: Logging the Weird Stuff

Apr 6, 2026

Follow Joel Duffield while he talks about why some systems just don’t want to be logged. Whether it’s your backup tool that only sends email alerts, your budget IoT device that wasn’t built for enterprises, or that one SaaS app stuck on the free tier—there’s no clean way to get their messages into your SIEM.

But sometimes, the most important clue isn’t what was sent—it’s what wasn’t. In this talk, we’ll explore creative ways to turn even email alerts (and their silence) into structured, actionable logs using tools like Graylog. Because visibility isn’t just about noise—it’s also about noticing when it goes quiet.

0:00 Introduction & Speaker Background

0:40 What Is "The Island of Misfit Toys"?

1:30 The Problem: Logging the "Everything Else" in Your Environment

3:00 Examples of Misfit Log Sources (Backup Software, PDQ Deploy, Canary Tokens, Cloudflare)

5:45 Prosumer Hardware & IoT Devices (NAS, Cameras, Door Locks)

7:18 How to Get Emails Into Graylog (Power Automate, Zapier, Cloud Mailin, Logstash)

10:06 Detecting the Absence of Logs — The Silent Failure Problem

12:45 Using Graylog's Cron Scheduling to Monitor for Missing Messages

15:02 Aggregation Events: Alerting When Count Is Less Than One

16:46 Wrap-Up & Key Takeaways

19:29 Closing Remarks & Conference Notes