惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
C
Cybersecurity and Infrastructure Security Agency CISA
美团技术团队
J
Java Code Geeks
博客园 - 聂微东
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
小众软件
小众软件
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
雷峰网
雷峰网
爱范儿
爱范儿
阮一峰的网络日志
阮一峰的网络日志
V
Visual Studio Blog
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
有赞技术团队
有赞技术团队
Google DeepMind News
Google DeepMind News
The Cloudflare Blog
博客园 - Franky
Engineering at Meta
Engineering at Meta
IT之家
IT之家
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
The Register - Security
The Register - Security
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
The Exploit Database - CXSecurity.com
I
Intezer
V
Vulnerabilities – Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
NISL@THU
NISL@THU
S
Security @ Cisco Blogs
T
Tenable Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Project Zero
Project Zero
H
Hacker News: Front Page
SecWiki News
SecWiki News
L
LINUX DO - 最新话题
Hacker News: Ask HN
Hacker News: Ask HN
Forbes - Security
Forbes - Security
C
CERT Recently Published Vulnerability Notes
T
Threatpost
N
News and Events Feed by Topic
Webroot Blog
Webroot Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
V2EX - 技术
V2EX - 技术

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis Monitor Aruba Central in Datadog How we centralize and remediate risks with Datadog Case Management Accelerate incident response with Datadog and ServiceNow Monitor your application and network load balancer logs Understanding Karpenter architecture for Kubernetes autoscaling Tools for collecting metrics and logs from Karpenter Monitor Karpenter with Datadog What your product data is actually saying Key metrics for monitoring Karpenter Securing Datadog’s platform in the AI age: The role of observability data Four ways engineering teams use the Datadog MCP Server to power AI agents Approaching your observability migration with the right mindset Meet the new Bits AI SRE: Deeper reasoning, twice as fast Key learnings from the 2026 State of DevSecOps study Use plain English to query your multi-cloud infrastructure in Resource Catalog Simplifying troubleshooting across the user journey with Datadog Synthetic Monitoring Protect your OCI resources with Datadog Cloud Security This Month in Datadog - February 2026 Amazon EC2 security: How misconfigured and public AMIs expand your cloud attack surface Enable end-to-end visibility into your Java apps with a single command Measure and improve mobile app startup performance with Datadog RUM Evaluating our AI Guard application to improve quality and control cost Identify untested code across every level of your codebase Make use of guardrail metrics and stop babysitting your releases Monitor Versa Networks SD-WAN performance in Datadog Improve performance and reliability with APM Recommendations Remediate transitive vulnerabilities faster with Datadog Software Composition Analysis Generate audit-ready vulnerability and compliance reports with Datadog Sheets Monitor Fortinet FortiManager performance in Datadog Improve test coverage across codebases with Datadog Code Coverage Move fast, don’t break things: Consistent testing standards at scale Enrich logs with ServiceNow CMDB context before routing to any SIEM or logging tool Monitor Lustre with Datadog Make faster, better product decisions with Datadog Product Analytics Surface and remediate runtime posture issues with Workload Protection Findings Protect agentic AI applications with Datadog AI Guard How to optimize JavaScript code with CSS Trace Google Pub/Sub workloads in Cloud Run with Datadog Detect human names in logs with ML in Sensitive Data Scanner How we cut our NLQ agent debugging time from hours to minutes with LLM Observability Debug PostgreSQL query latency faster with EXPLAIN ANALYZE in Datadog Database Monitoring Datadog acquires Propolis Unify and correlate frontend and backend data with retention filters Scale compliance across global frameworks with Datadog Cloud Security Monitor Arista VeloCloud SD-WAN performance with Datadog Building reliable dashboard agents with Datadog LLM Observability Simplify log collection and aggregation for MSSPs with Datadog Observability Pipelines Mitigation for Node.js denial-of-service vulnerability affecting Datadog APM Automate flaky test fixes with the Bits AI Dev Agent and Test Optimization How we built an AI SRE agent that investigates like a team of engineers Datadog integrations 2025 recap: Observability for AI, security, and hybrid cloud Design effective executive dashboards with Datadog Implement dbt data quality checks with dbt-expectations Bring faster visibility into AWS Lambda functions with remote instrumentation Troubleshoot faster with the GitLab Source Code integration in Datadog How Cambia Health Solutions saved $30,000 monthly with Cloud Cost Management and the Datadog Resource Catalog Normalize any logs for Cloud SIEM with Datadog's OCSF processor Optimizing Datadog at scale: Cost-efficient observability at Zendesk Detect, diagnose, and resolve network issues easily with CNM Network Health Connect engineering errors to user impact in early-stage products Cilium configuration for Kubernetes operations at scale Designing feedback loops for progressive delivery Ship features faster and safer with Datadog Feature Flags Choosing the right OpenTelemetry Collector distribution Route your monitor alerts with Datadog monitor notification rules Automate Cloud SIEM investigations with Bits AI Security Analyst Cloud threat detection: How to identify risky activity across control and data planes Collecting Kafka performance metrics Monitoring Kafka with Datadog Monitoring Kafka performance metrics
How state, local, and education organizations can manage logs flexibly and efficiently using Datadog Observability Pipelines
2025-03-19 · via Datadog | The Monitor blog
Abe Rosloff

Abe Rosloff

State, local, and education (SLED) organizations need their logs to provide clear, structured insights into system performance, user behavior, and security risks. But often, the picture becomes scattered and chaotic instead, with critical log data buried in noise and gaps that make logs difficult to interpret. As a result, problem-solving issues across the stack becomes a drawn-out process—teams need to create custom queries across multiple specialized tools, taking time away from maintaining public services and executing on new policies and initiatives.

In this post, we’ll show you how SLED organizations can use Datadog Observability Pipelines to add simplicity and flexibility to logging by centralizing analytics, enrichment, and deduplication while leaving existing tools in place. After we discuss the unique challenges of log management in SLED, we’ll look at how Observability Pipelines can help you:

Challenges for log management in SLED

SLED organizations face some unique hurdles when it comes to effectively managing log data, as they are often structured in ways that limit visibility and increase risk.

In many cases, security, application, and networking teams don’t directly communicate and rely on separate tools, which slows collaboration and makes incidents harder to resolve. With siloed tools and infrastructure, logs are scattered across servers, with no unified way to track how data flows through systems, leaving gaps where critical information gets lost. Compounding this lack of visibility, logs are often noisy and unprocessed, burying critical insights and turning routine troubleshooting into a drain on already limited resources.

For SLED, these issues aren’t just inconvenient—they can be dangerous. Protecting sensitive data like PII, criminal justice information (CJIS), and HIPAA/COPPA-protected information demands airtight security and compliance. At the same time, SLED systems must be highly available as any outage or delay can have real-world consequences for the communities they serve. Meanwhile, teams are small, budgets are tight, and resources are limited, despite the fact that policy changes and initiatives require timeliness and proactivity.

Many teams address these issues by increasing the volume of logs they collect, purchasing more team-specific logging tools, or both. Instead of improving visibility, these options often just make matters worse while increasing costs. Teams spend time procuring multiple tools instead of working on actual SLED initiatives. If a new tool fails to meet team needs, switching vendors is a lengthy, expensive process, which often results in vendor lock-in. When an issue arises, having multiple, disconnected log management tools becomes not an asset but a roadblock, as teams must request logs from one another, often without the full context needed to investigate the problem.

Centralize log ingestion, enrichment, and analytics

Many SLED teams wish they could rebuild their logging infrastructure from scratch, but this usually isn’t a practical option. Existing tooling and workflows are often just too ingrained into daily operations to make dramatic changes like this.

Datadog Observability Pipelines provides a centralized platform for ingesting, routing, and transforming log data across multiple sources and destinations, giving SLED organizations flexibility they need while making it easier to obtain insights from logs. Observability Pipelines allows you to install local workers on your own infrastructure that can generate analytics, enrich, and deduplicate logs before then sending them to your existing logging tools, SIEMs, storage, or Datadog. Datadog-backed integrations allow you to route your logs with minimal setup and without the need for a complex query language.

Overview of Datadog Observability Pipelines

You can configure your pipelines directly in the Datadog UI. This allows you to visualize your routes and specify key-value pairs for Observability Pipeline Workers to use for filtering and enriching your logs. Once set up, logs will flow to the log destinations you specify, including Datadog log indexes if desired.

Example pipelines in Datadog Observability Pipelines

You can also use Observability Pipelines to enrich your logs in ways that go beyond simply structuring and adding tags to them. For instance, you can use reference tables for tasks like GeoIP lookup or other types of cross-referencing. This allows SLED teams to enrich logs so that they contain metadata that helps all teams during an investigation, not just the team generating the logs.

Dual-ship logs to keep existing tooling in place

Dual shipping logs to existing sources and Datadog is a great way to begin the process of centralizing your organization’s logging without creating abrupt disruptions to daily operations by switching platforms all at once. By dual shipping logs, you can continue using specialized log destinations as needed while also sending logs to Datadog so you can generate metrics from them, share them across all teams, present log data on dashboards, and investigate logs without a complex query language.

For example, you may be sending network and security logs to Splunk for your security team’s use cases. Typically, only the security team will have direct access to these logs in an aggregated place, and other teams must reach out to them to request queries to aid in an investigation. This process is slow and painful, especially when troubleshooting a live production issue.

In this scenario, using Observability Pipeline to dual-ship your logs allows non-security teams to find the relevant log data without dedicated engineering support, while allowing the security team to continue comfortably leveraging Splunk.

Pipeline that dual-ships logs to Datadog and Splunk

Reduce noise and manage costs

Observability Pipelines also enables you to filter and deduplicate logs before sending them to Datadog or other destinations. For example, you may have an application that generates an overwhelming number of logs, many of which are duplicates. Other times, the duplication may come from different logging tools reporting on the same data but as distinct logs. This not only increases the effort it takes for different teams to correlate their findings but also increases logging costs—a major concern for SLED organizations that have to stay within tight budgetary constraints.

With Observability Pipelines, you can configure filtering rules to drastically reduce the total number of logs being sent to your destinations. This can result in substantial cost savings, as many platforms—such as SIEMs, for example—charge based on log volume. Additionally, centralizing your log filtering gives individual teams and collaborators less to sift through when an incident occurs.

Establish cross-team investigation workflows with Datadog Observability Pipelines

By centrally processing logs through Observability Pipelines, SLED organizations can facilitate collaborative investigations, even if they are using multiple logging and SIEM solutions. Deploying Observability Pipelines and the example flows we’ve discussed in this post enables you to standardize logs across sources and destinations, enrich them with context that makes collaboration easier, and store critical logs in Datadog for all teams to access without needing a query language.

Check out our documentation to get started. If you’re not yet using Datadog, sign up for a 14-day free trial.