DatadogCloudSIEMV2
Datadog Cloud SIEM integration for XSOAR provides security signal management capabilities. This integration allows you to retrieve, filter, and manage security signals from Datadog's Cloud SIEM platform, enabling security teams to investigate threats, manage signal triage states, and assign signals to team members. Supports incoming mirroring of signals to XSOAR incidents.
- Category
- Analytics & SIEM
- Pack
- DatadogCloudSIEM
Configuration parameters
- site — Server URL (required)
- api_key — API Key (required)
- app_key — Application Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- first_fetch — First fetch time
- max_fetch — Max fetch
- fetch_severity — Fetch severity
- fetch_state — Fetch state
- fetch_query — Fetch query
- mirror_direction — Incident Mirroring Direction
- close_incident — Close Mirrored XSOAR Incident
Commands (18)
- datadog-add-signal-comment — Add a comment to a security signal in Datadog Cloud SIEM .
- datadog-bitsai-get-investigation — Get the BitsAI investigation for a security signal from Datadog Cloud SIEM . BitsAI provides AI-powered analysis and investigation steps for security signals.
- datadog-get-rule — Get a specific security monitoring rule by ID from Datadog Cloud SIEM .
- datadog-get-signal — Get a specific security signal by ID from Datadog Cloud SIEM .
- datadog-list-risk-scores — List risk scores from Datadog Cloud SIEM . Risk scores provide a quantitative assessment of security risks associated with entities in your environment.
- datadog-list-security-filters — List all security filters from Datadog Cloud SIEM . Security filters control which logs are indexed and analyzed by the Cloud SIEM platform.
- datadog-list-signal-comments — List all comments for a security signal in Datadog Cloud SIEM .
- datadog-list-signal-notification-rules — List all signal notification rules from Datadog Cloud SIEM . Signal notification rules define how and when security signals should trigger notifications to specified channels (e.g., email, Slack, PagerDuty).
- datadog-list-signals — Get a list of security signals from Datadog Cloud SIEM with optional filtering and pagination.
- datadog-list-suppressions — List all suppressions affecting a specific security monitoring rule in Datadog Cloud SIEM .
- datadog-list-vulnerability-notification-rules — List all vulnerability notification rules from Datadog Cloud SIEM. Vulnerability notification rules define how and when vulnerability findings should trigger notifications to specified channels (e.g., email, Slack, PagerDuty).
- datadog-query-logs — Query logs in Datadog Cloud SIEM with optional filtering for security investigations.
- datadog-update-signal-assignee — Update a security signal's assignee in Datadog Cloud SIEM.
- datadog-update-signal-state — Update a security signal's state in Datadog Cloud SIEM.
- datadog-update-suppression — Update an existing suppression rule by ID. Allows updating enabled state, name, description, and data exclusion query. At least one attribute must be provided to update.
- get-mapping-fields — Get the mapping fields for Datadog Cloud SIEM security signals. This command is used for debugging the mirroring integration and returns the schema of available fields.
- get-modified-remote-data — Get the list of signal IDs that were modified since lastUpdate. This command is used for debugging the mirroring integration.
- get-remote-data — Get remote data from Datadog Cloud SIEM for mirroring. This command is used for debugging the mirroring integration.