/plushcap/analysis/datadog/datadog-add-context-with-reference-tables-in-cloud-siem

Add more context to Cloud SIEM detections and investigations with Datadog Reference Tables

What's this blog post about?

Datadog Cloud SIEM enables security teams to efficiently identify threats by adding context to their detection rules and log searches with Datadog Reference Tables, allowing them to filter out non-relevant data, detect threats quickly, and conduct efficient security investigations on historical logs. By using custom metadata from tables built around primary keys, security teams can bring rich and up-to-date security context to their detection rules, including data outside of standard logs, third-party security feeds, and large datasets. With the ability to easily update and enrich the data used by detection rules, security teams can continuously evaluate logs against the most up-to-date datasets and threat intelligence lists, optimizing their detection rules for fast and accurate signal generation and conducting in-depth security investigations on historical logs.

Company
Datadog

Date published
Dec. 19, 2024

Author(s)
Nimisha Saxena, Paul Howard-Flanders

Word count
784

Language
English

Hacker News points
None found.


By Matt Makai. 2021-2024.