惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threatpost
O
OpenAI News
Forbes - Security
Forbes - Security
W
WeLiveSecurity
Engineering at Meta
Engineering at Meta
Stack Overflow Blog
Stack Overflow Blog
P
Privacy & Cybersecurity Law Blog
The Register - Security
The Register - Security
T
Tor Project blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
S
Secure Thoughts
D
DataBreaches.Net
Vercel News
Vercel News
D
Docker
T
The Blog of Author Tim Ferriss
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
M
MIT News - Artificial intelligence
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
L
LangChain Blog
博客园_首页
S
Schneier on Security
宝玉的分享
宝玉的分享
Project Zero
Project Zero
V
Visual Studio Blog
Attack and Defense Labs
Attack and Defense Labs
量子位
P
Proofpoint News Feed
The GitHub Blog
The GitHub Blog
B
Blog
V2EX - 技术
V2EX - 技术
T
Troy Hunt's Blog
N
Netflix TechBlog - Medium
H
Hacker News: Front Page
Cloudbric
Cloudbric
云风的 BLOG
云风的 BLOG
Latest news
Latest news
P
Proofpoint News Feed
Help Net Security
Help Net Security
Schneier on Security
Schneier on Security
H
Heimdal Security Blog
Hacker News: Ask HN
Hacker News: Ask HN
有赞技术团队
有赞技术团队
B
Blog RSS Feed
Last Week in AI
Last Week in AI
C
Cyber Attacks, Cyber Crime and Cyber Security
I
Intezer
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Webroot Blog
Webroot Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Microsoft Security Blog
Microsoft Security Blog

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis Monitor Aruba Central in Datadog How we centralize and remediate risks with Datadog Case Management Accelerate incident response with Datadog and ServiceNow Monitor your application and network load balancer logs Understanding Karpenter architecture for Kubernetes autoscaling Tools for collecting metrics and logs from Karpenter Monitor Karpenter with Datadog What your product data is actually saying Key metrics for monitoring Karpenter Securing Datadog’s platform in the AI age: The role of observability data Four ways engineering teams use the Datadog MCP Server to power AI agents Approaching your observability migration with the right mindset Meet the new Bits AI SRE: Deeper reasoning, twice as fast Key learnings from the 2026 State of DevSecOps study Use plain English to query your multi-cloud infrastructure in Resource Catalog Simplifying troubleshooting across the user journey with Datadog Synthetic Monitoring Protect your OCI resources with Datadog Cloud Security This Month in Datadog - February 2026 Amazon EC2 security: How misconfigured and public AMIs expand your cloud attack surface Enable end-to-end visibility into your Java apps with a single command Measure and improve mobile app startup performance with Datadog RUM Evaluating our AI Guard application to improve quality and control cost Identify untested code across every level of your codebase Make use of guardrail metrics and stop babysitting your releases Monitor Versa Networks SD-WAN performance in Datadog Improve performance and reliability with APM Recommendations Remediate transitive vulnerabilities faster with Datadog Software Composition Analysis Generate audit-ready vulnerability and compliance reports with Datadog Sheets Monitor Fortinet FortiManager performance in Datadog Improve test coverage across codebases with Datadog Code Coverage Move fast, don’t break things: Consistent testing standards at scale Enrich logs with ServiceNow CMDB context before routing to any SIEM or logging tool Monitor Lustre with Datadog Make faster, better product decisions with Datadog Product Analytics Surface and remediate runtime posture issues with Workload Protection Findings Protect agentic AI applications with Datadog AI Guard How to optimize JavaScript code with CSS Trace Google Pub/Sub workloads in Cloud Run with Datadog Detect human names in logs with ML in Sensitive Data Scanner How we cut our NLQ agent debugging time from hours to minutes with LLM Observability Debug PostgreSQL query latency faster with EXPLAIN ANALYZE in Datadog Database Monitoring Datadog acquires Propolis Unify and correlate frontend and backend data with retention filters Scale compliance across global frameworks with Datadog Cloud Security Monitor Arista VeloCloud SD-WAN performance with Datadog Building reliable dashboard agents with Datadog LLM Observability Simplify log collection and aggregation for MSSPs with Datadog Observability Pipelines Mitigation for Node.js denial-of-service vulnerability affecting Datadog APM Automate flaky test fixes with the Bits AI Dev Agent and Test Optimization How we built an AI SRE agent that investigates like a team of engineers Datadog integrations 2025 recap: Observability for AI, security, and hybrid cloud Design effective executive dashboards with Datadog Implement dbt data quality checks with dbt-expectations Bring faster visibility into AWS Lambda functions with remote instrumentation Troubleshoot faster with the GitLab Source Code integration in Datadog How Cambia Health Solutions saved $30,000 monthly with Cloud Cost Management and the Datadog Resource Catalog Normalize any logs for Cloud SIEM with Datadog's OCSF processor Optimizing Datadog at scale: Cost-efficient observability at Zendesk Detect, diagnose, and resolve network issues easily with CNM Network Health Connect engineering errors to user impact in early-stage products Cilium configuration for Kubernetes operations at scale Designing feedback loops for progressive delivery Ship features faster and safer with Datadog Feature Flags Choosing the right OpenTelemetry Collector distribution Route your monitor alerts with Datadog monitor notification rules Automate Cloud SIEM investigations with Bits AI Security Analyst Cloud threat detection: How to identify risky activity across control and data planes Collecting Kafka performance metrics Monitoring Kafka with Datadog Monitoring Kafka performance metrics
Optimize EDR logs and route them to SentinelOne with Observability Pipelines
2025-02-25 · via Datadog | The Monitor blog
Pratik Parekh

Pratik Parekh

Endpoint detection and response (EDR) systems such as SentinelOne Singularity Endpoint, CrowdStrike, and Microsoft Defender monitor IT infrastructure such as computers, mobile devices, and network devices to detect, alert on, and respond to cyber threats. These EDR systems record data about the endpoints to identify abnormal behavior, block malicious activity, and provide remediation suggestions with contextual information. But these services come at a cost: EDR systems record high volumes of log data, making the data expensive to store and difficult to extract actionable information from.

To help solve these challenges, Datadog Observability Pipelines now integrates with platforms such as SentinelOne Singularity Data Lake. With Observability Pipelines, you can collect and process security logs and then route them cost-effectively. Using the SentinelOne Singularity platform, you can collect and correlate logs from various endpoints to identify and respond to threats in real time.

In this post, we’ll cover how Observability Pipelines can help you:

Collect a variety of EDR logs

Observability Pipelines aggregates EDR logs directly from EDR vendors and from cloud storage such as Amazon S3 buckets. Security teams often use Observability Pipelines to collect various types of EDR logs, including the following:

  • Activity logs record data for management activities, such as when a user is added or deleted, or when authentication rules are changed. Likewise, EDR systems generate log events when a threat is mitigated or stays unmitigated. Engineers can use these logs for investigations and threat hunting.
  • Threat logs indicate malicious activities, risky practices, brute-force attacks, and password spray attempts.
  • Alert logs are generated and distributed when specific conditions are met. The conditions typically involve a metric that exceeds a threshold value, the occurrence of an event, or the occurrence of multiple events in a period of time.
  • File and registry change logs reveal any updates, creation, or deletions of file or system registry contents.

Parse, standardize, and enrich EDR logs for routing to SentinelOne

Observability Pipelines scales with your infrastructure to process high volumes of incoming logs. You can use Observability Pipelines to centralize log processing and standardize your security logs before you send them to SentinelOne Singularity Data Lake. By using the Grok Parser, you can write custom rules or use the more than 150 preconfigured parsing rules to convert logs into a standard format. For destinations such as SentinelOne Singularity Data Lake, you can also automatically convert your logs into the industry-standard OCSF format.

Conversion of Splunk logs to OCSF format.

As your log volume increases, so does the difficulty of identifying threats from unknown IP addresses and locations. By using the Enrichment Table processor in Observability Pipelines, you can identify logs from known malicious IP addresses and tag all incoming logs with GeoIP information to create a map of your request origin. You can also replace IDs, hostnames, and cluster names with human-readable contextual information for ease of querying.

If you work in regulated industries that require you to mask data to comply with privacy regulations, you face additional challenges. Your logs can contain usernames, IP addresses, and other critical data such as credit card information that needs to be secured on-premises before the data leaves your infrastructure. You can use Sensitive Data Scanner in Observability Pipelines to identify and redact this data.

Filter EDR logs and generate metrics to control log volumes

Identifying a threat from potentially billions of log events daily is a challenging task. To mitigate this problem, you can use Observability Pipelines to identify logs generated from known sources or users and to flag other logs for further investigation. By filtering, deduping, and sampling logs in addition to enforcing quotas, you can reduce the volume of logs that you send to SentinelOne Singularity Data Lake.

You can also decrease the volume of your logs by generating metrics, such as number of API requests, unique file access requests, and amount of network traffic. If you need to know only the number of unique logins to your application, you don’t need to route the logs for every unique login to SentinelOne Singularity Data Lake. Instead, you can route these low-value logs to archival storage for long-term retention while routing only the actionable logs to SentinelOne Singularity Data Lake.

A pipeline that migrates logs from Splunk to SentinelOne.

Start routing data to SentinelOne with Observability Pipelines

With Observability Pipelines, you can choose your preferred logging platform and security solutions, such as SentinelOne, to support enhanced analytics, improve threat detection, and avoid vendor lock-in. You can begin routing your logs to SentinelOne Singularity Data Lake by setting up the SentinelOne destination and environment variables. For more information, visit the Observability Pipelines documentation.

If you don’t already have a Datadog account, you can sign up for a 14-day free trial to get started.