惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
B
Blog
aimingoo的专栏
aimingoo的专栏
酷 壳 – CoolShell
酷 壳 – CoolShell
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
月光博客
月光博客
H
Help Net Security
V
Visual Studio Blog
量子位
A
About on SuperTechFans
博客园 - Franky
人人都是产品经理
人人都是产品经理
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Turn security signals into structured investigations with...
Eitan Moriano, Vera Chan · 2026-05-05 · via Datadog | The Monitor blog

Security operations teams manage a high volume of signals, often across multiple tools. Analysts may triage detections in one system, document progress in another, and coordinate remediation elsewhere. As context becomes fragmented, response times slow and the risk of missed threats increases.

Datadog Cloud SIEM brings detection, investigation, and response into a single, connected workflow. Analysts can move from any security signal in the Cloud SIEM Signal Explorer to a structured case in Case Management without leaving Datadog, collaborate using bidirectionally synced tools such as Jira, and automate response steps using Workflow Automation. Teams can also automate the transition from signal to case, reducing manual handoffs while keeping investigations anchored to the underlying telemetry.

In this post, we’ll look at how you can use Datadog Cloud SIEM to:

  • See case context directly in the Signal Explorer

  • Escalate signals into structured investigations

  • Continue investigations from the Cases workspace

  • Collaborate across ticketing and messaging systems

  • Speed up case creation and response with automation

See case context directly in Signal Explorer

To avoid duplicating work or missing important handoffs, one of the first things an analyst needs to understand during triage is whether a signal is already being investigated. Cloud SIEM surfaces case context directly in the Signal Explorer queue, where analysts can see security detections by severity, time, and affected entities. 

Each signal includes a Cases indicator that shows whether the signal is linked to an existing case. By hovering over the indicator, you can quickly view details such as status, ownership, and timeline, all without halting the triage process.

Signal Explorer displays whether a signal is already linked to an active case so analysts can avoid duplicate investigations.

Escalate signals into structured investigations

When a signal requires a full investigation, analysts can use Cloud SIEM to escalate a signal into a case directly from the signal page. The resulting case in Datadog Case Management is automatically populated with relevant context, including signal metadata and investigation details. This allows teams to move into a structured workflow immediately while preserving the full context of the detection.

Because the relationship between signals and cases is tracked, other analysts can see that work is already in progress. This shared visibility reduces duplicate effort and keeps investigations coordinated across the team.

Creating a case from a signal automatically includes relevant detection context for faster investigation.

Continue investigations from the Cases workspace

Once a signal is escalated, you can immediately start investigating by accessing the Cases workspace directly within Cloud SIEM. Instead of copying information into external tools, you can manage the full life cycle of an investigation alongside the logs, signals, and entity context that informed it.

From the Cases tab in Cloud SIEM, you can track ownership, status, evidence, and activity for all of your cases. This structure makes it easier to organize investigations and maintain a clear record of what has happened. It also gives security leads better visibility into team workload, including which cases are active, blocked, or resolved.

Cases workspace shows investigation status, ownership, and linked signals in a single view.

By keeping investigations in the same platform as detection data, teams reduce context switching and maintain a more complete view of each incident.

Collaborate across ticketing and messaging systems

Investigations often require coordination with teams outside the security organization. For example, engineers may need to deploy fixes, IT teams may need to rotate credentials, and cloud teams may need to update configurations. Datadog brings security analysts and their collaborators together where they already work, whether that’s a ticketing system like Jira or a messaging platform like Slack.

Datadog Case Management supports bidirectional syncing with ticketing systems using a one-to-one mapping between a Datadog case and a ServiceNow or Jira ticket. Updates made in either system, including status changes, assignments, and comments, are reflected in both places. This reduces manual work for analysts and keeps stakeholders informed with a consistent story of the investigation.

Slack is part of the same workflow: Datadog Case Management can automatically send notifications to a Slack channel, and replies in the thread are added to the case timeline in Datadog. This helps ensure that real-time discussions become part of the investigation record instead of being lost across separate tools.

Case timeline includes updates from ticketing systems and Slack to keep all collaborators aligned.

Together, these integrations create a consistent system of record for investigations, regardless of where your team collaborates.

Speed up case creation and response with automation

For high- and critical-severity detections, the decision to open a case often follows a consistent path based on well-defined signals. In these situations, relying on manual steps can delay response and increase analyst workload unnecessarily.

Cloud SIEM enables automatic case creation based on signal criteria through notification settings and automation rules. For example, a high-severity signal can immediately generate a case that is ready for assignment and investigation.

Notification rules can automatically create cases from high-severity signals to help ensure consistent escalation.

When you’re ready to initiate follow-up actions from an investigation, Datadog Workflow Automation reduces manual effort by enabling analysts to execute response steps directly from a case. Workflows can automate common tasks, such as collecting additional information, notifying the right responders, updating downstream tickets, kicking off remediation runbooks, or running custom agents. This helps teams move from investigation to action with fewer clicks and provides a way to standardize response processes across recurring incident scenarios.

Connect signals to investigations with a unified workflow

By connecting detection, investigation, and response workflows, Cloud SIEM reduces the friction that often slows security operations. Analysts can triage signals with full visibility, escalate the right detections into cases, and manage investigations without leaving Datadog. Collaboration across ticketing systems and Slack keeps teams aligned, while automation helps standardize response and reduce manual work.

To learn more, see the documentation for Cloud SIEM. If you’re new to Datadog, sign up for a 14-day free trial.