- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Cloud SIEM Content Packs provide out-of-the box content for key security integrations. Depending on the integration, a Content Pack can include the following:
Content Packs are grouped into the following categories:
Monitor account activity with 1Password Events Reporting.
1Password Content Pack includes:
Monitor LastPass activity and analyze with detection rules
LastPass Content Pack includes:
Track user activity by monitoring Okta audit logs.
Okta Content Pack includes:
Monitor and analyze MFA and secure access logs from Cisco DUO.
Cisco DUO Content Pack includes:
Track user activity by monitoring Jumpcloud audit Logs.
Jumpcloud Content Pack includes:
Analyze PingOne audit events
PingOne Content Pack includes:
Monitor and generate signals around Auth0 user activity.
Auth0 Content Pack includes:
Collect and analyze Ping Federate admin and audit logs
Ping Federate Content Pack includes:
Protect your GCP environment by monitoring audit logs.
GCP Audit Logs Content Pack includes:
Monitor open source Kubernetes and Amazon Elastic Kubernetes Service (EKS) audit logs for threats.
Kubernetes Audit Logs Content Pack includes:
Monitor security and compliance levels of your AWS operations.
AWS CloudTrail Content Pack includes:
Protect your Azure environment by tracking attacker activity.
Azure Security Content Pack includes:
Collect and analyze Twilio message, call summary, and event logs
Twilio Content Pack includes:
Monitor admin activity from your organization's Atlassian Org including your Atlassian Guard subscription, Jira, and Confluence
Atlassian Organization Event Logs Content Pack includes:
Collect snowflake logs to monitor for threats, conduct hunts, and perform investigations.
Snowflake Content Pack includes:
Monitor Confluent Cloud audit logs
Confluent Cloud Audit Logs Content Pack includes:
Collect GitLab Audit Events to assess risk, security, and compliance
Gitlab Audit Events Content Pack includes:
Collect activity and audit logs from Terraform
HCP Terraform Content Pack includes:
Monitor, secure, and optimize your Atlassian's Jira & Confluence environments.
Atlassian Jira & Confluence Audit Records Content Pack includes:
Track user activity and code change history by monitoring Github audit logs.
GitHub Content Pack includes:
View and monitor Wiz audit logs and issues, including toxic combinations.
Wiz Content Pack includes:
Track and analyze Google Security Command Center findings.
Google Security Command Center Content Pack includes:
Collect security logs and alerts from Defender, Purview, Entra ID, and Sentinel
Microsoft Graph Content Pack includes:
Optimize your security monitoring within Google Workspace.
Google Workspace Content Pack includes:
Collect and monitor Zoom activity
Zoom Activity Logs Content Pack includes:
Monitor key security events from Microsoft 365 logs.
Microsoft 365 Content Pack includes:
View, analyze, and monitor Slack audit logs.
Slack Content Pack includes:
Monitor threat events, cases, and audit logs for Abnormal Security
Abnormal Security Content Pack includes:
Analyze logs and generate signals from Mimecast email security solutions
Mimecast Content Pack includes:
Analyze email policy events and track mail flows for Trend Micro Email Security
Trend Micro Email Security Content Pack includes:
Integrate SentinelOne Singularlity Endpoint alerts and threats into Cloud SIEM.
SentinelOne Content Pack includes:
Improve the security posture of your endpoints with Crowdstrike.
Crowdstrike Content Pack includes:
Monitor and analyze Sophos Central Cloud events and alerts
Sophos Central Cloud Content Pack includes:
Collect Cisco Secure Endpoint alerts and audit logs
Cisco Secure Endpoint Content Pack includes:
Monitor and analyze your Windows system for potential threats with Windows Event Logs.
Windows Event Logs Content Pack includes:
Endpoint security and mobile threat defense (MTD) for Mac and mobile devices.
Jamf Protect Content Pack includes:
Collect and analyze Imperva web application firewall logs, audit logs, and attack analytics
Imperva Content Pack includes:
Analyze traffic and detect threats with Palo Alto Networks Firewall.
Palo Alto Networks Firewall Content Pack includes:
Monitor and alert on your network's Check Point Quantum firewalls.
Checkpoint Quantum Firewall Content Pack includes:
Collect Bind9 DNS server logs
Bind9 Content Pack includes:
Monitor Cisco Meraki logs and identify attacker activity.
Cisco Meraki Content Pack includes:
Gain insights into Cisco Secure Firewall logs.
Cisco Secure Firewall Content Pack includes:
Analyze and store Corelight / Zeek logs to gain insights into network threats.
Zeek Content Pack includes:
Collect and monitor logs from Cisco Umbrella to gain insights into DNS and Proxy logs.
Cisco Umbrella DNS Content Pack includes:
Enhance security for your web applications.
Cloudflare Content Pack includes:
Monitor and detect your Palo Alto Panorama firewalls.
Palo Alto Panorama Content Pack includes:
Monitor and respond to web-based risks with Nginx.
NGINX Content Pack includes:
추가 유용한 문서, 링크 및 기사: