Uptycs events per host trend graph
Uptycs detection as a Datadog event
Uptycs alert as a Datadog event
Overview
Uptycs mitigates risk by prioritizing your responses to threats, vulnerabilities, misconfigurations, sensitive data exposure, and compliance requirements across your modern attack surface, making this information accessible through a single user interface and data model. This includes the capability to correlate threat activity as it traverses on-premises and cloud boundaries, providing a more comprehensive enterprise-wide security posture.
Looking for acronym coverage? We’ve got you covered with CNAPP, CWPP, CSPM, KSPM, CIEM, CDR, and XDR. Start with your Detection Cloud, utilize Google-like search, and the attack surface coverage you need today.
For more information, see the Uptycs website.
The Uptycs integration enables you to ingest your Uptycs alerts and detections into Datadog events.
Alert Details
Each alert contains the following main components:
- Title
- Description
- Id: Uptycs alert ID.
- Uptycs alert code.
- Alert severity.
- Alert key and value.
- Asset details: Asset ID and host name.
- Uptycs URL to navigate to the Uptycs platform.
Detection Details
Each detection contains the following main components:
- Title or Name
- Id: Uptycs detection ID.
- Score: Uptycs calculated score.
- Alerts: List of Alerts associated with the detection.
- Events: List of Events associated with the detection.
- Attack Matrix: Techniques associated with the alerts and events.
- Asset details: Asset ID and host name.
- Uptycs URL to navigate to the Uptycs platform.
Setup
To set up this integration, you must have an Uptycs account. If you are not an Uptycs customer, contact us for an Uptycs account.
You’ll also need Datadog API keys.
Configuration
- Create a Datadog API key.
- Create a Datadog Integration Destination on the Uptycs platform using your Datadog API key:
Go to Configuration > Destinations.
Click on New destination.
Select Datadog destination type.
Provide a name for the destination, your Datadog domain, and your API key. You can also add custom templates for alerts or detections in the template field.
Click Save.
- Once the destination is set up, create a forwarding rule for it.
Go to Configuration > Detection Forwarding Rules > New rule
Provide a name and description, then choose the relevant criteria for the rule.
In the ‘Destinations’ options, select the newly created destination.
Select Enable Rule and click Save.
- The created destination can be used for alert forwarding.
Go to Configuration > Alert Rules.
Select an Alert Rule or bulk select several rules.
In the ‘Destinations’ options, select the newly created destination.
Select the options for ‘Notify on Every Alert’ and ‘Close After Delivery’.
Click Save.
- Once Uptycs generates an alert or detection, it will be delivered as a Datadog Event.
Troubleshooting
Need help? Contact Support.