概要
Cloud SIEM コンテンツパック は、主要なセキュリティのインテグレーションのために、すぐに使えるコンテンツを提供します。インテグレーションに応じて、コンテンツパックには以下が含まれます。
- 環境の包括的なカバレッジを提供する 検出ルール
- コンテンツパックのログとセキュリティシグナルの状態に関する詳細なインサイトを提供するインタラクティブなダッシュボード
- ユーザーやリソースによる不審なアクティビティを調査するためのインタラクティブなグラフィカルインターフェースである Investigator
- アクションを自動化し、問題をより素早く調査し修復する Workflow Automation
- 設定ガイド
- インテグレーションのログを Open Cybersecurity Schema Framework の共通データモデルに正規化するための OCSF パイプライン
- Cloud SIEM セキュリティシグナルにマッピングされる、インテグレーションから送られるサードパーティアラート
コンテンツパックは、以下のタイプ別にフィルタリングできます。
- コンテンツパック: 検出ルール、SOAR (Security Orchestration, Automation, and Response) ワークフロー、カスタムツールなど、セキュリティ関連のコンテンツがバンドルされたインテグレーション
- エンリッチメントパック: 脆弱性やサードパーティのインサイトなど、調査を改善するために SIEM 分析に有益なコンテキストを追加するコンテンツ
- インテグレーションパック: Cloud SIEM での使用に関連する、Datadog カタログから選別されたコンテンツ
このページに記載されているコンテンツパックに加え、Cloud SIEM には Always-On コンテンツパックが含まれています。これらは、Datadog がログやセキュリティシグナルに自動的に適用する脅威インテリジェンスのエンリッチメントであり、インストールや設定を必要としません。
Content Packs are grouped into the following categories:
Authentication: 1Password, Datadog Audit Trail, Auth0, BeyondTrust Identity Security Insights, BeyondTrust Password Safe, BeyondTrust Privileged Remote Access, Bitwarden, Cisco Duo, Delinea Privilege Manager, Delinea Secret Server, Have I Been Pwned, Ivanti nZTA, JumpCloud, Keeper Security, Keycloak, LastPass, Okta, PingFederate, PingOne Advanced Identity Cloud, PingOne, Push Security, Symantec VIP, Zscaler
Cloud Audit: Claude Compliance, AWS CloudTrail, Azure Security, GCP Audit Logs, Greenhouse, Kubernetes Audit Logs, Linux Audit Logs, Oracle Cloud Infrastructure
Cloud Developer Tools: Atlassian Jira & Confluence Audit Records, Atlassian Organization Event Logs, Confluent Cloud Audit Logs, GitHub, GitLab Audit Events, GuardDog, HCP Terraform, IDE-SHEPHERD, Snowflake, Twilio
Cloud Security: Falco, Google Security Command Center, Microsoft Graph, Obsidian Security, Orca Security, Palo Alto Networks Cortex XSOAR, Recorded Future, Wiz, Wiz Vulnerabilities
Collaboration: Asana, Box, Google Workspace, Microsoft 365, Salesforce, Slack, Zendesk, Zoom Activity Logs
Email Security: Abnormal Security, Check Point Harmony Email & Collaboration, Cisco Secure Email Threat Defense, Cofense Triage, Mimecast, Proofpoint On-Demand Email Security, Proofpoint TAP, Trend Micro Email Security
Endpoint: Arctic Wolf Aurora Endpoint Security, Avast, Bitdefender, Check Point Harmony Endpoint, Cisco Secure Endpoint, CrowdStrike, ESET Protect, Jamf Pro, Jamf Protect, Iru (Kandji), Mac Audit Logs, Microsoft Sysmon, OSSEC, SentinelOne, Sophos Central Cloud, Supply-Chain Firewall, Symantec Endpoint Protection, Tanium, Trellix Endpoint Security (ENS), Trend Micro Vision One Endpoint Security, Trend Micro Vision One XDR, Wazuh, Windows Event Logs
Network: Barracuda SecureEdge, Bind9, Check Point Quantum Firewall, Cisco ASA, Cisco Secure Client, Cisco Secure Firewall, Cisco Umbrella DNS, Cloudflare, Barracuda CloudGen Firewall, DNSFilter, ExtraHop, Forescout, Fortinet FortiManager, Imperva, Ivanti Connect Secure, Juniper SRX Firewall, Cisco Meraki, Microsoft DNS, OpenVPN, Palo Alto Cortex XDR, Palo Alto Networks Firewall, Palo Alto Panorama, Sonicwall Firewall, Suricata, Vectra, WatchGuard Firebox, Zeek, Zero Networks, Zscaler Private Access
Threat Intel: CrowdStrike Threat Intelligence, MISP Threat Intelligence, OpenCTI Threat Intelligence, Recorded Future Threat Intelligence
Web Security: Akamai Application Security, Apache, App & API Protection, Cisco Secure Web Appliance, F5 Distributed Cloud Services, Fastly, Forcepoint Secure Web Gateway, Forcepoint Security Service Edge, iboss, Netskope, NGINX, Squid, ZeroFox Cloud Platform
1Password
Monitor account activity with 1Password Events Reporting.
1Password Content Pack includes:
Datadog Audit Trail
Gain visibility into user and configuration changes across Datadog to monitor activity, detect unauthorized modifications, and support compliance and governance requirements.
Datadog Audit Trail Content Pack includes:
Auth0
Monitor and generate signals around Auth0 user activity.
Auth0 Content Pack includes:
BeyondTrust Identity Security Insights
Monitor identity risks with BeyondTrust Identity Security Insights.
BeyondTrust Identity Security Insights Content Pack includes:
BeyondTrust Password Safe
Monitor privileged access activity with BeyondTrust Password Safe.
BeyondTrust Password Safe Content Pack includes:
BeyondTrust Privileged Remote Access
Monitor privileged remote access logins, sessions, and admin changes in BeyondTrust PRA.
BeyondTrust Privileged Remote Access Content Pack includes:
Bitwarden
Ingest and analyze Bitwarden event logs, including item events, user events, group events, and organization activity.
Bitwarden Content Pack includes:
Cisco Duo
Monitor and analyze MFA and secure access logs from Cisco Duo.
Cisco Duo Content Pack includes:
Delinea Privilege Manager
Gain insights into Delinea Privilege Manager events.
Delinea Privilege Manager Content Pack includes:
Delinea Secret Server
Track privileged credential usage and user activity from Delinea Secret Server to monitor authentication events and secure access to sensitive systems.
Delinea Secret Server Content Pack includes:
Have I Been Pwned
Collect breach activity logs from Have I Been Pwned.
Have I Been Pwned Content Pack includes:
Ivanti nZTA
Investigate Ivanti nZTA logins, admin activity, alerts, and zero-trust application access
Ivanti nZTA Content Pack includes:
JumpCloud
Track user activity by monitoring JumpCloud audit logs.
JumpCloud Content Pack includes:
Keeper Security
Monitor credential use, privileged access, and security events from Keeper Security.
Keeper Security Content Pack includes:
Keycloak
Gain insights into user and administrative activity from Keycloak.
Keycloak Content Pack includes:
LastPass
Monitor LastPass activity and analyze with detection rules
LastPass Content Pack includes:
Okta
Track user activity by monitoring Okta audit logs.
Okta Content Pack includes:
PingFederate
Collect and analyze PingFederate admin and audit logs
PingFederate Content Pack includes:
PingOne Advanced Identity Cloud
Detect suspicious authentication and identity changes in PingOne Advanced Identity Cloud
PingOne Advanced Identity Cloud Content Pack includes:
PingOne
Analyze PingOne audit events
PingOne Content Pack includes:
Push Security
Gain visibility into user activity with Push Security.
Push Security Content Pack includes:
Symantec VIP
Ingest Symantec VIP logs to track user creation, password changes, group management events, and more.
Symantec VIP Content Pack includes:
Zscaler
Gain visibility into internet and security activity with Zscaler Internet Access.
Zscaler Content Pack includes:
Claude Compliance
Monitor audit activity logs from Anthropic's Compliance API.
Claude Compliance Content Pack includes:
AWS CloudTrail
Monitor security and compliance levels of your AWS operations.
AWS CloudTrail Content Pack includes:
Azure Security
Protect your Azure environment by tracking attacker activity.
Azure Security Content Pack includes:
GCP Audit Logs
Protect your GCP environment by monitoring audit logs.
GCP Audit Logs Content Pack includes:
Greenhouse
Gain insights into your organization's hiring activities by monitoring Greenhouse audit logs
Greenhouse Content Pack includes:
Kubernetes Audit Logs
Monitor open source Kubernetes and Amazon Elastic Kubernetes Service (EKS) audit logs for threats.
Kubernetes Audit Logs Content Pack includes:
Linux Audit Logs
Monitor user activity, authentication events, and policy changes with enriched Linux audit logs across Red Hat, Ubuntu, and CentOS.
Linux Audit Logs Content Pack includes:
Oracle Cloud Infrastructure
Monitor Oracle Cloud Infrastructure audit logs to detect suspicious activity, failed access, and resource changes.
Oracle Cloud Infrastructure Content Pack includes:
Atlassian Jira & Confluence Audit Records
Monitor, secure, and optimize your Atlassian's Jira & Confluence environments.
Atlassian Jira & Confluence Audit Records Content Pack includes:
Atlassian Organization Event Logs
Monitor admin activity from your organization's Atlassian Org including your Atlassian Guard subscription, Jira, and Confluence
Atlassian Organization Event Logs Content Pack includes:
Confluent Cloud Audit Logs
Monitor Confluent Cloud audit logs
Confluent Cloud Audit Logs Content Pack includes:
GitHub
Track user activity and code change history by monitoring GitHub audit logs.
GitHub Content Pack includes:
GitLab Audit Events
Collect GitLab Audit Events to assess risk, security, and compliance
GitLab Audit Events Content Pack includes:
GuardDog
View, analyze, and monitor open source dependency usage with GuardDog.
GuardDog Content Pack includes:
HCP Terraform
Collect activity and audit logs from Terraform
HCP Terraform Content Pack includes:
IDE-SHEPHERD
Monitor and protect IDE extensions and workspace tasks in VS Code and Cursor from malicious activities in real-time.
IDE-SHEPHERD Content Pack includes:
Snowflake
Collect snowflake logs to monitor for threats, conduct hunts, and perform investigations.
Snowflake Content Pack includes:
Twilio
Collect and analyze Twilio message, call summary, and event logs
Twilio Content Pack includes:
Falco
Detect runtime threats across containers, Kubernetes, and cloud workloads using enriched alert logs from Falco.
Falco Content Pack includes:
Google Security Command Center
Track and analyze Google Security Command Center findings.
Google Security Command Center Content Pack includes:
Microsoft Graph
Collect security logs and alerts from Defender, Purview, Entra ID, and Sentinel
Microsoft Graph Content Pack includes:
Obsidian Security
Gain insights into Obsidian Security Platform alerts, events and audit logs.
Obsidian Security Content Pack includes:
Orca Security
Ingest cloud security alerts from Orca to monitor risk, compliance, and workload protection across your cloud environment.
Orca Security Content Pack includes:
Palo Alto Networks Cortex XSOAR
Monitor Palo Alto Networks Cortex XSOAR audit activity and security incidents in Cloud SIEM.
Palo Alto Networks Cortex XSOAR Content Pack includes:
Recorded Future
Investigate Recorded Future Classic and Playbook alerts alongside your Cloud SIEM logs
Recorded Future Content Pack includes:
Wiz
View and monitor Wiz audit logs and issues, including toxic combinations.
Wiz Content Pack includes:
Wiz Vulnerabilities
Enrich signals and detections with vulnerability data from Wiz.
Wiz Vulnerabilities Content Pack includes:
Asana
Explore and analyze Asana audit logs
Asana Content Pack includes:
Box
Monitor activity across your Box environment with enterprise event logs.
Box Content Pack includes:
Google Workspace
Optimize your security monitoring within Google Workspace.
Google Workspace Content Pack includes:
Microsoft 365
Monitor key security events from Microsoft 365 logs.
Microsoft 365 Content Pack includes:
Salesforce
Collect Salesforce real-time platform events as Datadog logs.
Salesforce Content Pack includes:
Slack
View, analyze, and monitor Slack audit logs.
Slack Content Pack includes:
Zendesk
Ingest Zendesk audit and access logs to monitor user and admin activity.
Zendesk Content Pack includes:
Zoom Activity Logs
Collect and monitor Zoom activity
Zoom Activity Logs Content Pack includes:
Abnormal Security
Monitor threat events, cases, and audit logs for Abnormal Security
Abnormal Security Content Pack includes:
Check Point Harmony Email & Collaboration
Collect security events from Check Point Harmony Email & Collaboration.
Check Point Harmony Email & Collaboration Content Pack includes:
Cisco Secure Email Threat Defense
Gain insights into Cisco Secure Email Threat Defense message logs.
Cisco Secure Email Threat Defense Content Pack includes:
Cofense Triage
Detect phishing campaigns in Cofense Triage email reports and threat indicators.
Cofense Triage Content Pack includes:
Mimecast
Analyze logs and generate signals from Mimecast email security solutions
Mimecast Content Pack includes:
Proofpoint On-Demand Email Security
Detect email-borne threats and abuse in Proofpoint On-Demand message logs
Proofpoint On-Demand Email Security Content Pack includes:
Proofpoint TAP
Monitor Proofpoint TAP email threats: phishing, malware, and malicious URL clicks
Proofpoint TAP Content Pack includes:
Trend Micro Email Security
Analyze email policy events and track mail flows for Trend Micro Email Security
Trend Micro Email Security Content Pack includes:
Arctic Wolf Aurora Endpoint Security
Collect endpoint security events from Arctic Wolf Aurora Endpoint Security.
Arctic Wolf Aurora Endpoint Security Content Pack includes:
Avast
Monitor Avast endpoint threat detections, patch status, and admin audit activity.
Avast Content Pack includes:
Bitdefender
Ingest endpoint threat detections and incident activity from Bitdefender EDR, including malware, phishing, exploits, and ransomware events.
Bitdefender Content Pack includes:
Check Point Harmony Endpoint
Collect endpoint security logs from Check Point Harmony Endpoint.
Check Point Harmony Endpoint Content Pack includes:
Cisco Secure Endpoint
Collect Cisco Secure Endpoint alerts and audit logs
Cisco Secure Endpoint Content Pack includes:
CrowdStrike
Improve the security posture of your endpoints with CrowdStrike.
CrowdStrike Content Pack includes:
ESET Protect
Monitor endpoint threats, firewall activity, and web filtering logs from ESET Protect.
ESET Protect Content Pack includes:
Jamf Pro
Monitor Apple device activity and management events using Jamf Pro logs.
Jamf Pro Content Pack includes:
Jamf Protect
Endpoint security and mobile threat defense (MTD) for Mac and mobile devices.
Jamf Protect Content Pack includes:
Iru (Kandji)
Collect audit, threat, and detection logs from Iru (Kandji).
Iru (Kandji) Content Pack includes:
Mac Audit Logs
Monitor macOS system events, user actions, and security activity using Mac Audit Logs.
Mac Audit Logs Content Pack includes:
Microsoft Sysmon
Gain insights into Windows system activity events.
Microsoft Sysmon Content Pack includes:
OSSEC
Ingest OSSEC alerts from monitored hosts
OSSEC Content Pack includes:
SentinelOne
Integrate SentinelOne Singularlity Endpoint alerts and threats into Cloud SIEM.
SentinelOne Content Pack includes:
Sophos Central Cloud
Monitor and analyze Sophos Central Cloud events and alerts
Sophos Central Cloud Content Pack includes:
Supply-Chain Firewall
View, analyze, and monitor package manager usage with Supply-Chain Firewall.
Supply-Chain Firewall Content Pack includes:
Symantec Endpoint Protection
Detect endpoint threats with Symantec Endpoint Protection risk, scan, and security logs
Symantec Endpoint Protection Content Pack includes:
Tanium
Monitor Tanium endpoint threat response alerts and platform audit activity
Tanium Content Pack includes:
Trellix Endpoint Security (ENS)
Investigate endpoint threats, malware, web and firewall activity from Trellix ENS logs.
Trellix Endpoint Security (ENS) Content Pack includes:
Trend Micro Vision One Endpoint Security
Collect and analyze extensive logs from Trend Micro Vision One Endpoint Security
Trend Micro Vision One Endpoint Security Content Pack includes:
Trend Micro Vision One XDR
Gain insights into Trend Micro Vision One XDR logs.
Trend Micro Vision One XDR Content Pack includes:
Wazuh
Detect threats across endpoints with Wazuh alerts: FIM, malware, and vulnerability events.
Wazuh Content Pack includes:
Windows Event Logs
Monitor and analyze your Windows system for potential threats with Windows Event Logs.
Windows Event Logs Content Pack includes:
Barracuda SecureEdge
Collect network and security logs from Barracuda SecureEdge.
Barracuda SecureEdge Content Pack includes:
Bind9
Collect Bind9 DNS server logs
Bind9 Content Pack includes:
Check Point Quantum Firewall
Monitor and alert on your network's Check Point Quantum firewalls.
Check Point Quantum Firewall Content Pack includes:
Cisco ASA
Collect firewall, authentication, and network activity logs from Cisco ASA.
Cisco ASA Content Pack includes:
Cisco Secure Client
Collect VPN and access logs from Cisco Secure Client.
Cisco Secure Client Content Pack includes:
Cisco Secure Firewall
Gain insights into Cisco Secure Firewall logs.
Cisco Secure Firewall Content Pack includes:
Cisco Umbrella DNS
Collect and monitor logs from Cisco Umbrella to gain insights into DNS and Proxy logs.
Cisco Umbrella DNS Content Pack includes:
Cloudflare
Enhance security for your web applications.
Cloudflare Content Pack includes:
Barracuda CloudGen Firewall
Collect network and firewall logs from Barracuda CloudGen Firewall.
Barracuda CloudGen Firewall Content Pack includes:
DNSFilter
Monitor and analyze DNSFilter logs to detect blocked threats and DNS activity.
DNSFilter Content Pack includes:
ExtraHop
Gain insights into ExtraHop detection and investigation logs.
ExtraHop Content Pack includes:
Forescout
Monitor network devices and security activity with Forescout.
Forescout Content Pack includes:
Fortinet FortiManager
Monitor device health, security telemetry, and more across your networks managed by Fortinet, including FortiGate Next Generation Firewalls (NGFW).
Fortinet FortiManager Content Pack includes:
Imperva
Collect and analyze Imperva web application firewall logs, audit logs, and attack analytics
Imperva Content Pack includes:
Ivanti Connect Secure
Monitor Ivanti Connect Secure logs to gain visibility into authentication activity, system changes, and security events.
Ivanti Connect Secure Content Pack includes:
Juniper SRX Firewall
Monitor session activity, security threats, and authentication events from Juniper SRX Firewall logs.
Juniper SRX Firewall Content Pack includes:
Cisco Meraki
Monitor Cisco Meraki logs and identify attacker activity.
Cisco Meraki Content Pack includes:
Microsoft DNS
Gain insights into Microsoft DNS Server audit events.
Microsoft DNS Content Pack includes:
OpenVPN
Monitor VPN session activity and authentication events with real-time insights from OpenVPN logs.
OpenVPN Content Pack includes:
Palo Alto Cortex XDR
Collect and analyze Palo Alto Cortex XDR logs
Palo Alto Cortex XDR Content Pack includes:
Palo Alto Networks Firewall
Analyze traffic and detect threats with Palo Alto Networks Firewall.
Palo Alto Networks Firewall Content Pack includes:
Palo Alto Panorama
Monitor and detect your Palo Alto Panorama firewalls.
Palo Alto Panorama Content Pack includes:
Sonicwall Firewall
Investigate SonicWall Firewall traffic, threat, and authentication logs in Cloud SIEM.
Sonicwall Firewall Content Pack includes:
Suricata
Gain insights into Suricata logs.
Suricata Content Pack includes:
Vectra
Investigate Vectra AI network threat detections, entity scoring and audit events
Vectra Content Pack includes:
WatchGuard Firebox
Analyze firewall, VPN, proxy, and system events from WatchGuard Firebox logs.
WatchGuard Firebox Content Pack includes:
Zeek
Analyze and store Corelight / Zeek logs to gain insights into network threats.
Zeek Content Pack includes:
Zero Networks
Gain insights into Zero Networks audit and network activities logs.
Zero Networks Content Pack includes:
Zscaler Private Access
Monitor private application access and activity with Zscaler Private Access.
Zscaler Private Access Content Pack includes:
CrowdStrike Threat Intelligence
Enrich logs and detections with threat intelligence data from CrowdStrike.
CrowdStrike Threat Intelligence Content Pack includes:
MISP Threat Intelligence
Enrich logs and detections with threat intelligence data from MISP.
MISP Threat Intelligence Content Pack includes:
OpenCTI Threat Intelligence
Enrich logs and detections with threat intelligence data from OpenCTI.
OpenCTI Threat Intelligence Content Pack includes:
Recorded Future Threat Intelligence
Enrich logs and detections with threat intelligence data from Recorded Future.
Recorded Future Threat Intelligence Content Pack includes:
Akamai Application Security
Akamai edge WAF security events for detecting web attacks, DDoS, and bot activity.
Akamai Application Security Content Pack includes:
Apache
Collect and analyze Apache logs and metrics
Apache Content Pack includes:
App & API Protection
Monitor and protect your applications with App & API Protection for Java, Python, Ruby, .NET, Go, Node.js, and PHP.
App & API Protection Content Pack includes:
Cisco Secure Web Appliance
Gain visibility into access and traffic logs from Cisco Secure Web Appliance to detect web threats and enforce security policies.
Cisco Secure Web Appliance Content Pack includes:
F5 Distributed Cloud Services
Monitor F5 Distributed Cloud WAF, bot defense, and access logs for web attacks and abuse.
F5 Distributed Cloud Services Content Pack includes:
Fastly
Monitor HTTP server performance, traffic, and uptime metrics.
Fastly Content Pack includes:
Forcepoint Secure Web Gateway
Monitor user web activity and data loss prevention events with real-time logs from Forcepoint Secure Web Gateway.
Forcepoint Secure Web Gateway Content Pack includes:
Forcepoint Security Service Edge
Collect and analyze cloud activity, access, admin, and health logs from Forcepoint Security Service Edge
Forcepoint Security Service Edge Content Pack includes:
iboss
Ingest iboss web, DLP, and audit logs to monitor traffic activity, data loss risks, and user actions.
iboss Content Pack includes:
Netskope
Gain visibility into user web traffic and security events with Netskope transaction logs.
Netskope Content Pack includes:
NGINX
Monitor and respond to web-based risks with Nginx.
NGINX Content Pack includes:
Squid
Investigate Squid proxy logs: web destinations, denied requests, and client browsing activity
Squid Content Pack includes:
ZeroFox Cloud Platform
Monitor ZeroFox digital risk alerts across dark web, social, and domain threats.
ZeroFox Cloud Platform Content Pack includes:
参考文献