Company
Date Published
Author
Vera Chan, Jason Hunsberger
Word count
972
Language
English
Hacker News points
None

Summary

Datadog's integration with Cisco Umbrella provides a platform for monitoring and maintaining DNS-layer security across networks. The integration enables the collection, processing, and visualization of DNS and proxy logs, allowing security teams to detect behavior like DNS hijacking, spoofing, and other attacks. Datadog Cloud SIEM automatically detects threats by continuously scanning DNS logs and generating security signals if it detects potentially malicious activity. Security teams can create custom detection rules or use out-of-the-box rules developed by the dedicated security research team to automate alerts and remediation for suspicious activities. The integration also provides two customizable out-of-the-box dashboards that deliver a high-level view of DNS and proxied network activity, offering essential insights into the health and security of the environment.