Datadog
Create an API Key and Application Key










Enable Datadog
Dropzone Field
Source









Last updated
Was this helpful?
Datadog is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
The Dropzone platform integrates with the Datadog security SIEM. Many customers ingest other alert sources into DataDog (e.g. IDPs) and integrate Dropzone into DataDog rather than the source systems.
Datadog requires both an API Key and an Application Key to enable.
To obtain an API Key, do the following:
In the bottom left hand corner of your Datadog Dashboard, click on your organization icon
Navigate to Organization Settings > API Keys

Click "New Key"

Name your token something memorable, such as "dropzone.ai," then click "Create Key"

Copy the key generated for use later in the Dropzone UI where it is called "API Key," then click "Finish"

To obtain an Application Key, do the following:
In the bottom left hand corner of your Datadog Dashboard, click on your organization icon
Navigate to Organization Settings > Application Keys

Click "New Key"

Name the key something memorable, such as "dropzone.ai," then click "Create Key"

In the "Scope" section, select "Edit"

Assign the key the following scopes, then click "Save":
logs_read_data
security_monitoring_signals_read

Copy the key generated for use later in the Dropzone UI where it is called "Application Key," then click "Finish"

To enable the Data Source integration, you will need the following information:
API Key
The API key value you generated earlier
Application Key
The Application key value you generated earlier
Datadog site
The same as your url in Datadog, eg datadoghq.com, us3.datadoghq.com, etc
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Available"

In the Search bar, search Datadog, then click "Configure"

Under the Alert Source heading, input the API Key, Application Key, and your Datadog site

In the "Enabled Severities" section, choose the severity levels of alerts you want Dropzone to investigate
Under "Enabled Sources," check the box for each known Datadog Security Monitoring Signal source you want to retrieve signals for

In the "Signal Rule Filters" section, you may choose Datadog security signal names to include/exclude from searches. To do so, click "Add Item," then input the signals you wish to filter. Under "Rule Filter Mode," select whether to include or exclude those signals from investigation

In the "Excluded Tags," you may exclude tags from analysis. To do so, click "Add Item," then input the tag Field Name (or "Key") and Value. Continue adding tags until done

Input your desired log ingestion delay, poll interval and lookback

If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
Contact your Dropzone AI support representative for more information about this feature

Click "Test & Save" to finish
If you have any errors engage your Dropzone AI support representative.
Last updated
Was this helpful?
Was this helpful?