惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
S
SegmentFault 最新的问题
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
U
Unit 42
GbyAI
GbyAI
B
Blog RSS Feed
博客园 - Franky
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 三生石上(FineUI控件)
Microsoft Azure Blog
Microsoft Azure Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Monitor Teleport with Datadog
2024-06-28 · via Datadog | The Monitor blog

The Teleport Access Platform delivers on-demand, least-privileged access to infrastructure (for SSH, Kubernetes, RDP, Web, databases, and clouds) on a foundation of cryptographic identity and zero trust, which eliminates the attack surfaces of both shared secrets and standing privileges. Teleport also improves the efficiency of engineering teams, makes infrastructure resilient to human error, improves compliance and audit reporting, and defends infrastructure and applications against identity provider compromise.

We’re excited to announce our Agent-based integration with the Teleport platform, enabling you to easily monitor your Teleport services and audit user session activity.

Monitor Teleport services

The primary components of a Teleport cluster—the auth and proxy services and agents—all need to run efficiently in order to keep your infrastructure secure. If one of these components fails, your users may not be able to access your infrastructure, and its internal resources may become vulnerable to threats. Datadog’s Teleport integration collects a suite of metrics for monitoring the health and performance of each critical service, which you can visualize in an out-of-the-box dashboard.

Teleport Dashboard

The dashboard enables you to track any significant changes in key Teleport metrics. For example, a sudden spike in the number of failed login attempts could signify an issue with the auth service, which manages the Teleport cluster’s local users and configuration resources. Conversely, a sudden high volume of concurrent sessions could indicate a brute-force attack against your servers. You can mitigate this kind of activity by modifying the cluster’s max_sessions setting, which limits the number of sessions allowed for a single connection.

Closely audit user sessions

Knowing who is accessing your infrastructure resources, such as Kubernetes clusters and databases, is another critical part of ensuring Teleport’s performance and security. Datadog Cloud SIEM enables you to closely audit user sessions via Teleport audit logs and detect any unusual behavior. For example, you can create a custom signal via Datadog Cloud SIEM that surfaces spikes in the number of login attempts per workstation, which is a common starting point for attacks.

Teleport Cloud SIEM signal

When Datadog detects an event like this, it will generate a security signal with relevant audit logs, which include the necessary information for investigation, such as the user’s overall network activity, code execution, and file transfers. This data can help you determine if an attacker is using a workstation to access servers. You can also create custom security signals to automatically detect other types of activity captured in audit logs, giving you comprehensive monitoring coverage for your Teleport services.

Stay on top of infrastructure access with Teleport and Datadog

With Datadog’s Teleport integration, you can ensure that your Teleport services are working as expected. It also enables you to monitor access across your entire infrastructure, so you can detect and prevent any suspicious activity. Check out our documentation to learn more about enabling the Teleport integration for the Datadog Agent. If you don’t already have a Datadog account, you can sign up for a free 14-day trial.