惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
J
Java Code Geeks
The GitHub Blog
The GitHub Blog
博客园_首页
U
Unit 42
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
IT之家
IT之家
G
Google Developers Blog
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
爱范儿
爱范儿
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
Martin Fowler
Martin Fowler
Jina AI
Jina AI
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
小众软件
小众软件
H
Help Net Security

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Monitor Twistlock with Datadog
2019-04-22 · via Datadog | The Monitor blog

Twistlock is a platform for managing security and compliance within various environments, including virtual machines, containers, and serverless functions. Ensuring legal and technical security is just as valuable as preventing outages and errors, which is why Datadog is delighted to announce a new integration with Twistlock. With this integration, you can track security and compliance risks within the same platform as the metrics, traces, and logs you already collect with Datadog.

Datadog's out-of-the-box dashboard for Twistlock gives you an overview of vulnerabilities for hosts and container images.
Datadog's out-of-the-box dashboard for Twistlock gives you an overview of vulnerabilities for hosts and container images.
Datadog's out-of-the-box dashboard for Twistlock gives you an overview of vulnerabilities for hosts and container images.

How Twistlock works

Twistlock scans your system for common vulnerabilities and exposures (CVEs) as well as for compliance with external standards and in-house policies. You can then prevent vulnerable applications from reaching production by making CI deployments contingent on passing Twistlock scans. Twistlock can also use machine learning to build a model of typical application behavior and prevent anomalous activity.

Monitor security and compliance risks in context

Knowing which security risks affect your system is the first step toward addressing them. Datadog’s Twistlock integration comes with an out-of-the-box dashboard that shows you the number of vulnerable hosts and container images over time, as well as lists of CVEs, letting you know where your environment is weakest and where to prioritize your security efforts.

The integration allows you to track CVEs by container image (both in a registry and on your system) and host, and compliance risks by container image, host, and container. Twistlock data is tagged by severity, making it possible to focus on the level of risk that matters to your system.

You can then create custom dashboards that display Twistlock metrics alongside metrics, traces, and logs from other integrations, giving you visibility into the health, performance, and security of your system. The custom Twistlock dashboard below shows a summary of CVEs by severity and by container image. Next to these, a container map visualizes each container in your environment. Since the container map is grouped by Docker image, you can compare it to the list of CVEs and understand which parts of your system are vulnerable.

custom-dash

Stay abreast of vulnerability status

Twistlock publishes logs to report new CVEs and CVE fixes, and you can use these to stay abreast of changes in vulnerability status. Datadog enriches your Twistlock logs with attributes automatically (using a built-in log-processing pipeline), letting you analyze trends in your vulnerabilities over time and filter logs to CVEs that impact specific parts of your infrastructure.

Datadog automatically enriches your Twistlock logs with attributes.
Datadog automatically enriches your Twistlock logs with attributes.
Datadog automatically enriches your Twistlock logs with attributes.

For example, you can filter logs to only those containing “fixed” or “open” vulnerabilities, and group the count of these logs by affected image name (as shown below). This lets you know which images to upgrade or downgrade to keep your system safe.

fixed-vs-open

Know when you miss a scan

Datadog checks the last time a scan has taken place and, depending on the interval since the scan, returns a warning or critical status. You can set alerts to notify you that Twistlock has failed to carry out a scan when expected, allowing you to correct any misconfigurations as soon as possible.

late-scan-alert

Security meets observability

Now that Datadog integrates with Twistlock, you can monitor the security, health, and performance of your applications and infrastructure, all in one place. If you haven’t given Datadog a try, see how you can get metrics, traces, and logs from over 1,000 vendor-supported integrations with a free trial.

We wish to thank the Twistlock team for their review of this post.