惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
腾讯CDC
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
博客园_首页
D
DataBreaches.Net
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
月光博客
月光博客
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
Vercel News
Vercel News
WordPress大学
WordPress大学
J
Java Code Geeks
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
U
Unit 42

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Analyze security logs from Amazon Security Lake with Datadog
Jordan Obey · 2022-11-29 · via Datadog | The Monitor blog
Jordan Obey

Jordan Obey

Senior Technical Content Writer

Amazon Security Lake allows customers to build security data lakes from integrated cloud and on-premises data sources as well as from their private applications. Directing your security telemetry into a unified data lake makes it easier to manage, analyze, and route security-log and event data to third-party SIEM solutions that leverage that telemetry.

We are pleased to announce that security logs and events stored in Amazon Security Lake can be easily forwarded to Datadog and analyzed by Datadog Cloud SIEM, providing you with a simplified way to analyze security logs from various sources for real-time threat detection.

Setting up the Amazon Security Lake integration is quick and easy, so you can start using Datadog to analyze your security logs within minutes. Simply install Datadog’s AWS integration, add Datadog as a subscriber in the Amazon Security Lake console, and update your IAM role permissions to enable Datadog to fetch security-log files. See our documentation for more details.

In this post, we’ll look at how this integration helps improve your security posture by enabling you to identify and investigate threats from across your environment with out-of-the-box security detection rules, dashboards, and Datadog Log Management tools.

Analyze security logs from Security Lake with OOTB detection rules and dashboards

Datadog Cloud SIEM provides out-of-the-box (OOTB) detection rules and threat intelligence that map security-related logs and events against suspicious IP addresses and attack patterns that bad actors have previously leveraged. Once you set up our integration and Datadog begins ingesting Security Lake logs and events, you will automatically receive signals associated with suspicious activity. This way, instead of needing to forward logs and events separately, you can forward all security-related telemetry data from your Security Lake directly to Datadog for quick and easy analysis.

Logs from Security Lake will also be collected and visualized in Datadog’s OOTB IP Investigation dashboard. This dashboard can help you execute IP-based security investigations by providing you with a centralized view of key IP security data such as security signals, unusual HTTP requests, and traffic from malicious IPs.

Datadog’s OOTB IP Investigation dashboard can help you execute IP-based security investigations by providing you with a centralized view of key IP security data.

Since Security Lake aggregates a large volume of security telemetry, it’s particularly important for you to have an efficient way to explore the resultant data. With Datadog Log Management and our Log Explorer, you can search for and view security-related logs collected from Security Lake. You can then use custom and OOTB saved views—which enable you to isolate specific subsets of logs—to focus the Log Explorer on a specific contextual scope. For example, you can create a saved view that narrows your view down to VPC flow logs and CloudTrail logs that indicate security-related issues such as rejected VPC traffic and AccessDenied errors. Narrowing your view down to a specific subset of logs enables you to quickly identify security-related issues for faster troubleshooting.

VPC flow logs and CloudTrail logs that contain security-related enable you to quickly identify security-related issues for faster troubleshooting.

Let Datadog fetch your Security Lake logs today

Amazon Security Lake helps customers improve their security posture by aggregating security telemetry into a centralized pool that can then be sent to Datadog. To learn more about how you can ingest Security Lake telemetry to detect threats and explore issues with Datadog Cloud SIEM and Log Management, please check out our documentation here.

If you aren’t already using Datadog, sign up today for a 14-day free trial.