Add more context to Cloud SIEM detections and investigations with Datadog Reference Tables
Datadog Cloud SIEM enables security teams to efficiently identify threats by adding context to their detection rules and log searches with Datadog Reference Tables, allowing them to filter out non-relevant data, detect threats quickly, and conduct efficient security investigations on historical logs. By using custom metadata from tables built around primary keys, security teams can bring rich and up-to-date security context to their detection rules, including data outside of standard logs, third-party security feeds, and large datasets. With the ability to easily update and enrich the data used by detection rules, security teams can continuously evaluate logs against the most up-to-date datasets and threat intelligence lists, optimizing their detection rules for fast and accurate signal generation and conducting in-depth security investigations on historical logs.
Company
Datadog
Date published
Dec. 19, 2024
Author(s)
Nimisha Saxena, Paul Howard-Flanders
Word count
784
Language
English
Hacker News points
None found.