For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/logs/log_configuration/processors/threat_intel_processor.md. A documentation index is available at /llms.txt.

Threat Intel Processor

Overview

Add the Threat Intel Processor to evaluate logs against the table using a specific Indicator of Compromise (IoC) key, such as an IP address. If a match is found, the log is enriched with relevant Threat Intelligence (TI) attributes from the table, which enhances detection, investigation, and response.

For more information, see Threat Intelligence.

Further reading