惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
罗磊的独立博客
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
博客园_首页
量子位
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
S
SegmentFault 最新的问题
雷峰网
雷峰网
小众软件
小众软件
博客园 - 聂微东
美团技术团队
Apple Machine Learning Research
Apple Machine Learning Research
WordPress大学
WordPress大学
Jina AI
Jina AI
Hugging Face - Blog
Hugging Face - Blog

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Measure and optimize security team efficiency with Cloud ...
Vera Chan, Nimisha Saxena, Anes Bendimerad, Jesse Mack · 2024-11-11 · via Datadog | The Monitor blog
Vera Chan

Vera Chan

Nimisha Saxena

Nimisha Saxena

Anes Bendimerad

Anes Bendimerad

Jesse Mack

Jesse Mack

Many organizations lack clear visibility into the efficiency of their security processes, making it difficult to accurately assess their security teams’ performance. Without insight into key factors like alert response speed, investigation thoroughness, and the accuracy of detection rules, teams risk operating without a clear view. This can lead to missed threats, inefficient use of resources, and an inability to improve security outcomes.

To give security teams enhanced insights into how they are performing, Datadog Cloud SIEM delivers comprehensive security operational metrics—mean time to detect (MTTD), mean time to acknowledge (MTTA), and mean time to resolve (MTTR)—that offer clear visibility into your teams’ effectiveness. With these insights, security teams can streamline their processes, address threats promptly, and continuously optimize operations to enhance security performance.

In this post, we’ll cover:

  • How Datadog calculates security operational metrics

  • How to visualize the metrics in dashboards

  • How to explore, tag, and track progress on your security operational metrics

How Datadog calculates security operational metrics

Security operational metrics are distribution metrics—these are calculated across the entirety of your distributed infrastructure at specific intervals, providing accurate percentile aggregations, as well as the ability to customize tags.

The three security operational metrics available in Datadog Cloud SIEM are:

  • Datadog.security.siem_signal.time_to_detect: Time to detect (TTD) measures the time from when a log triggers a security signal (T0) to when the signal is generated (T1), representing the speed of threat detection.

  • Datadog.security.siem_signal.time_to_acknowledge: Time to acknowledge (TTA) tracks the time from signal generation (T1) to when the signal is marked as under review (T2), showing how quickly teams initiate investigations.

  • Datadog.security.siem_signal.time_to_resolve: Time to resolve (TTR) measures the total time from signal generation (T1) to when the signal is archived (T3), reflecting the duration required to fully resolve the incident.

These metrics enable security teams to monitor and enhance their detection and response times, ensuring quick action against security threats.

Use dashboards to visualize security operational metrics

The Cloud SIEM Overview dashboard now includes security operational metrics out of the box, so that teams can quickly and easily start tracking MTTD, MTTA, and MTTR to evaluate and improve the effectiveness of their incident response.

Security Operational Metrics section in Cloud SIEM Overview dashboard

With these metrics, you can spot trends, measure improvements, and ensure your team is consistently optimizing its response workflows to minimize potential security risks. The ability to customize time ranges provides additional flexibility in how you query these metrics. You can also add security operational metrics to your own custom dashboards, giving teams the flexibility to monitor threats and response times in the dashboards they already use.

Explore, tag, and monitor security operational metrics

To explore security operational metrics in greater depth, you can also use the Metrics Summary, which provides a centralized view of all your metrics, including important metadata and context. Here, you can see exactly which dashboards, notebooks, monitors, and SLOs are using your security operational metrics, giving you visibility into how this data is being leveraged across your security operations. This summary helps you ensure that teams are tracing and using all relevant metrics to understand their performance and inform security strategy.

Security operational metrics in Metrics Summary

You can also use tags to further enhance the usability of these metrics and filter them based on specific teams, data sources, or environments. This granularity lets you focus on the most relevant data for different segments of your security infrastructure. Once filtered, you can create custom dashboards to visualize key metrics or set up monitors that trigger alerts when certain thresholds are met.

Filter security operational metrics by source and other facets

To help you stay on top of your operational metrics, Datadog Cloud SIEM generates weekly digest reports that provide a consolidated overview of key metrics and operational insights. These reports summarize critical information such as alert volumes, response times, and investigation outcomes, allowing teams to assess their performance and identify trends over time so they can proactively address vulnerabilities and optimize their security operations.

Subscribe to Cloud SIEM reports
Schedule reports and add recipients

Get valuable insights with security operational metrics

Datadog Cloud SIEM security operational metrics offer valuable insights into your teams’ effectiveness and facilitate seamless monitoring, enabling you to respond effectively to evolving threats, maintain a stronger security posture, and ensure that your cloud environments remain secure and resilient. Check out our in-depth guide for more information about monitoring these and other key security metrics.

If you’re already a Datadog customer, see our documentation so you can start exploring security operational metrics in the Cloud SIEM Overview dashboard and start receiving weekly digest reports now. If you’re not a customer, you can get started today with a 14-day free trial.