This product is not supported for your selected Datadog site. ().

Overview

The packs section of Observability Pipelines

When setting up a pipeline to send logs from a specific source to Observability Pipelines, you often need to decide how to process and manage those logs.

Questions such as the following might come up:

  • Which logs from this source are important?
  • Which logs can safely be dropped?
  • Should repetitive logs be sampled?
  • Which fields should be parsed or formatted for the destination?

Making these decisions typically requires coordination across multiple teams and detailed knowledge of each log source.

Observability Pipelines Packs provide predefined configurations to help you make these decisions quickly and consistently. Packs apply Datadog-recommended best practices for specific log sources such as Akamai, AWS CloudTrail, Cloudflare, Fastly, Palo Alto Firewall, and Zscaler.

What Packs do

Each Pack includes source-specific configurations that define:

  • Fields that can safely be removed to reduce payload size
  • Logs that can be dropped, such as duplicate events or health checks
  • Logs that should be retained or parsed, such as errors or security detections
  • Formatting and normalization rules to align logs across different destinations and environments

By using Packs, you can apply consistent parsing, filtering, and routing logic for each log source without creating configurations manually.

Why use Packs

Packs help teams:

  • Reduce ingestion volume and costs by filtering or sampling repetitive, low-value events
  • Maintain consistency in parsing and field mapping across environments and destinations
  • Accelerate setup by applying ready-to-use configurations for common sources

Setup

To set up packs:

  1. Navigate to the Pipelines page.
  2. Click Packs.
  3. Click the pack you want to set up.
  4. You can either create a new pipeline from the pack or add the pack to an existing pipeline.
    • If you clicked Add to New Pipeline, in the new pipeline that was created:
      • Click the processor group that was added to see the individual processors that the pack added and edit them as needed. See Processors for more information.
      • See Set Up Pipelines for information on setting up the rest of the pipeline.
    • If you clicked Add to Existing Pipeline:
      1. Select the pipeline you want to add the pack to.
      2. Click Add to Existing Pipeline.
        1. The pack is added to the last processor group in your pipeline.
        2. Click on the group to review the individual processors and edit them as needed. See Processors for more information.

Available packs

Search or filter the table by source or destination. Select a pack name for details.

PackSourceDestinationDescription
Abnormal.ai - Abuse CampaignsAbnormal.aiAny destinationThis pack flags malicious abuse-mailbox campaigns and failed remediation attempts across reported messages.
Abnormal.ai - Abuse Mailbox Messages Not AnalyzedAbnormal.aiAny destinationThis pack tracks the backlog of user-reported abuse mailbox messages Abnormal.ai did not analyze.
Abnormal.ai - Audit LogsAbnormal.aiAny destinationThis pack flags failed admin actions and mass remediation events from the Abnormal.ai portal audit trail.
Abnormal.ai - ThreatsAbnormal.aiAny destinationThis pack flags unremediated high-risk email threats like business email compromise (BEC), extortion, and credential phishing targeting VIPs.
Active DirectoryActive DirectoryAny destinationThis pack processes Active Directory Domain Services events, including Kerberos authentication, directory-service changes, and DCSync replication abuse.
Akamai CDNAkamaiAny destinationAkamai logs show client requests and responses at the edge.
AlphaSOC FindingsAlphaSOCAny destinationAlphaSOC findings flag DNS and IP threats detected across your network.
Amazon CloudFrontAWSAny destinationAWS CloudFront logs show requests, cache use, and edge activity.
Amazon ConnectAWSAny destinationThis pack extracts contact and agent signals from Amazon Connect logs, flagging abandoned calls and fraud risk.
Amazon VPC Flow LogsAWSAny destinationAmazon VPC Flow Logs capture network traffic between VPC resources.
Argo CDArgo CDAny destinationThis pack processes Argo CD sync, health, and RBAC events from the application controller and API server.
Auth0Auth0Any destinationAuth0 logs cover login, signup, MFA, and API activity.
Aviatrix Controller API AuditAviatrixAny destinationAviatrix Controller audit logs capture API commands, user attribution, and results.
Aviatrix FQDN FirewallAviatrixAny destinationAviatrix FQDN firewall logs capture egress domain requests and policy enforcement.
Aviatrix Gateway Network StatsAviatrixAny destinationAviatrix gateway net stats logs expose per-interface rx/tx bytes, packet counts, and network drop events.
Aviatrix Gateway System StatsAviatrixAny destinationAviatrix gateway system stats expose per-gateway CPU, memory, and disk utilization across cloud gateways.
Aviatrix L4 MicrosegmentationAviatrixAny destinationAviatrix DCF microsegmentation logs capture east-west policy enforcement across cloud gateways.
Aviatrix L7/TLS InspectionAviatrixAny destinationAviatrix L7/TLS inspection logs capture TLS session context and policy enforcement.
Aviatrix Suricata IDS/IPSAviatrixAny destinationAviatrix Suricata IDS/IPS alerts capture signature hits on gateway network traffic.
Aviatrix Tunnel StatusAviatrixAny destinationAviatrix tunnel status logs capture Site2Cloud and transit link state changes, events, and failure causes.
Aviatrix VPN SessionAviatrixAny destinationAviatrix VPN gateway logs capture per-user session lifecycles, auth events, and gateway traffic volumes.
AWS Application Load Balancer LogsAWSAny destinationAWS ALBs capture HTTP request activity routed through them.
AWS CloudTrailAWSAny destinationAWS CloudTrail records API calls and account activity across AWS services.
AWS CloudWatch LogsAWSAny destinationAWS CloudWatch Logs captures log streams from Lambda, ECS, and more.
AWS ConfigAWSAny destinationAWS Config monitors and records resource configuration changes.
AWS Elastic Load Balancer LogsAWSAny destinationAWS ELBs captures HTTP and HTTPS requests from Classic Load Balancers.
AWS GuardDutyAWSAny destinationAWS GuardDuty detects threats in your AWS account.
AWS LambdaAWSAny destinationAWS Lambda logs capture invocations, errors, and cold starts.
AWS Network Load Balancer LogsAWSAny destinationAWS NLBs captures connection activity and performance data.
AWS Route 53AWSAny destinationAWS Route 53 captures DNS queries across your AWS infrastructure.
AWS Security HubAWSAny destinationAWS Security Hub aggregates security findings across AWS.
AWS WAFAWSAny destinationAWS WAF captures AWS WAF logs from CloudWatch, S3, or Firehose.
Azure NSGAzureAny destinationAzure Network Security Group v2 flow logs record per-connection decisions and byte counts.
BlueCat DNSBlueCatAny destinationBlueCat BDDS syslog captures DNS queries and DHCP leases.
Check PointCheck PointAny destinationThis pack processes Check Point logs in CEF format, with or without syslog prefix.
Cisco ACICiscoAny destinationCisco ACI syslog events capture fabric health, endpoint moves, and admin activity.
Cisco ASACiscoAny destinationCisco ASA firewall logs capture syslog events for traffic, VPNs, and security alerts.
Cisco ASA - Google SecOpsCiscoGoogle SecOpsThis pack maps Cisco ASA syslog events to the UDM schema in Google Security Operations.
Cisco ASA - Microsoft SentinelCiscoMicrosoft SentinelThis pack maps parsed Cisco ASA syslog events to the CommonSecurityLog schema in Microsoft Sentinel.
Cisco FTDCiscoAny destinationCisco FTD syslog events cover access control, intrusion prevention, file detection, and VPN.
Cisco IOSCiscoAny destinationCisco IOS syslog captures security, auth, and routing events.
Cisco IOS TracebackCiscoAny destinationCisco IOS traceback events signal software faults, memory failures, and CPU issues.
Cisco MerakiCiscoAny destinationCisco Meraki captures appliance events, flows, VPN firewall, NAT flows, and URL activity.
Cisco Meraki - Microsoft SentinelCiscoMicrosoft SentinelThis pack maps parsed Cisco Meraki syslog events to the Syslog table schema in Microsoft Sentinel.
CloudflareCloudflareAny destinationCloudflare logs show edge traffic, performance, and security.
CrowdStrike FDRCrowdStrikeAny destinationFalcon Data Replicator (FDR) provides endpoint detection and response.
DNS StreamDNS StreamAny destinationThis vendor-neutral DNS query/response stream includes tunneling and DGA beaconing indicators.
Exabeam - Cisco ASACiscoExabeamThis pack processes Cisco ASA firewall logs sent to Exabeam and filters by ASA code to drop non-actionable syslog noise.
Exabeam - CrowdStrike FDRCrowdStrikeExabeamThis pack processes CrowdStrike Falcon Data Replicator events sent to Exabeam and drops sensor and telemetry noise.
Exabeam - Fortinet FortiGateFortinetExabeamThis pack processes FortiGate firewall logs sent to Exabeam and filters out routine traffic and health-check noise.
Exabeam - Palo AltoPalo AltoExabeamThis pack processes PAN-OS syslog sent to Exabeam and filters empty and duplicate-start traffic logs, leaving raw CSV untouched.
Exabeam - SentinelOne Cloud FunnelSentinelOneExabeamThis pack processes SentinelOne EDR events sent to Exabeam and samples high-volume event types to reduce ingest costs.
Exabeam - WindowsWindowsExabeamThis pack processes Windows Event Logs sent to Exabeam and filters to codes Exabeam parsers use, keeping raw XML intact for parsing.
Exabeam - ZscalerZscalerExabeamThis pack processes Zscaler ZIA web, ZIA DNS, and ZPA logs sent to Exabeam and filters and samples routine traffic.
ExtraHopExtraHopAny destinationExtraHop Reveal(x) detections surface network threats and behavioral anomalies.
ExtraHop - Microsoft SentinelExtraHopMicrosoft SentinelThis pack tags ExtraHop Reveal(x) network detections with severity and IPs for Microsoft Sentinel ingestion.
F5F5Any destinationF5 logs capture traffic, security policy, and intrusion events.
FastlyFastlyAny destinationFastly CDN logs record client requests, cache states, and delivery performance.
Fortinet - Microsoft SentinelFortinetMicrosoft SentinelThis pack maps FortiGate logs to the CommonSecurityLog schema in Microsoft Sentinel.
Fortinet FirewallFortinetAny destinationFortinet firewall logs record allowed, denied, and other network traffic.
GCP FirewallGoogle CloudAny destinationGCP VPC Firewall logs record allowed and denied traffic.
Google Cloud AuditGoogle CloudAny destinationGoogle Cloud Audit logs capture admin activity and policy violations.
Google SecOps - AWS VPCAWSGoogle SecOpsThis pack maps AWS VPC flow records to the UDM schema in Google Security Operations.
Google SecOps - Fortinet FirewallFortinetGoogle SecOpsThis pack maps Fortinet firewall logs to the UDM schema in Google Security Operations.
Google SecOps - Palo Alto FirewallPalo AltoGoogle SecOpsThis pack remaps PAN-OS logs to the UDM schema in Google Security Operations.
Google SecOps - Windows Event LogWindowsGoogle SecOpsThis pack maps Windows security events to the UDM schema in Google Security Operations.
HAProxy IngressHAProxyAny destinationHAProxy Ingress logs record how Kubernetes ingress traffic is routed and served.
InfobloxInfobloxAny destinationInfoblox NIOS syslog captures DNS, DHCP, audit, and CEF activity from appliances.
Istio ProxyIstioAny destinationIstio Proxy logs capture inbound and outbound traffic handled by Envoy.
Juniper SRX Firewall Traffic LogsJuniperAny destinationJuniper SRX Firewall records network session data.
Kube ProxyKubernetesAny destinationThis pack keeps kube-proxy errors and warnings only, dropping routine iptables sync noise fired every cycle.
Microsoft DNSMicrosoftAny destinationThis pack parses the classic Windows DNS Server debug text log (dns.log) and decodes query names and response codes.
MITRE ATT&CK AWS WAF EnrichmentAWSAny destinationThis pack tags AWS WAF logs with MITRE ATT&CK tactics and techniques.
MITRE ATT&CK CloudTrail EnrichmentAWSAny destinationThis pack tags CloudTrail logs with MITRE ATT&CK tactics and techniques.
MITRE ATT&CK FortiGate EnrichmentFortinetAny destinationThis pack tags FortiGate logs with MITRE ATT&CK tactics and techniques.
MITRE ATT&CK Okta EnrichmentOktaAny destinationThis pack tags Okta logs with MITRE ATT&CK tactics and techniques.
MITRE ATT&CK Palo Alto EnrichmentPalo AltoAny destinationThis pack tags Palo Alto logs with MITRE ATT&CK tactics and techniques.
MITRE ATT&CK Windows EnrichmentWindowsAny destinationThis pack tags Windows event logs with MITRE ATT&CK tactics and techniques.
NetskopeNetskopeAny destinationNetskope logs capture cloud app use, policies, and security events.
NGINXNGINXAny destinationNGINX logs record client requests, responses, and errors from the web server.
OktaOktaAny destinationOkta logs show authentication, user activity, and policy events.
OpenAI - Audit LogsOpenAIAny destinationThis pack flags failed logins, new API keys, and privilege changes from OpenAI organization audit logs.
OpenTelemetry LogsOpenTelemetryAny destinationOTLP/JSON logs nest events under resourceLogs, scopeLogs, and logRecords arrays, three levels deep per payload.
Orca SecurityOrca SecurityAny destinationThis pack normalizes Orca Security cloud findings for SIEM and data lake routing.
Palo Alto CortexPalo AltoAny destinationCortex XDR alerts include severity, MITRE ATT&CK mapping, and source/destination context.
Palo Alto FirewallPalo AltoAny destinationPalo Alto firewall logs capture traffic, threat, and system events.
Palo Alto Networks - Microsoft SentinelPalo AltoMicrosoft SentinelThis pack maps PAN-OS logs to the CommonSecurityLog schema in Microsoft Sentinel.
Palo Alto Networks - XSIAMPalo AltoCortex XSIAMThis pack remaps PAN-OS logs to the Cortex XSIAM flat JSON schema.
Proofpoint Email SecurityProofpointAny destinationProofpoint Email Security logs capture email threats, phishing, and malware detections.
Qualys DetectionsQualysAny destinationThis pack surfaces new, confirmed, and reopened Qualys vulnerability detections, dropping low-severity noise.
SentinelOne Cloud Funnel EDRSentinelOneAny destinationSentinelOne Cloud Funnel streams EDR and Deep Visibility events as JSON to cloud storage.
SyslogSyslogAny destinationThis pack parses generic RFC 3164/5424 syslog with severity mapping and a log-volume metric.
Windows DNS LogWindowsAny destinationThe Windows DNS Server analytic log covers queries, zone transfers, and dynamic updates.
Windows Office 365MicrosoftAny destinationThis pack flags high-risk Microsoft 365 (M365) Unified Audit Log events: mail-forwarding rules, delegation, and role changes.
Windows XMLWindowsAny destinationWindows Event logs capture system, application, and security activity from Windows hosts.
WinEventLogWindowsAny destinationWindows Event Log captures authentication, process creation, and account management events.
ZScaler ZIA DNSZscalerAny destinationZScaler Internet Access (ZIA) DNS logs capture org-wide DNS activity and policy actions.
Zscaler ZIA FirewallZscalerAny destinationZscaler Internet Access (ZIA) Firewall logs show network traffic and security events.
Zscaler ZIA TunnelZscalerAny destinationZscaler Internet Access (ZIA) Tunnel logs show tunnel health, traffic, and key events.
Zscaler ZIA Web LogsZscalerAny destinationZscaler Internet Access (ZIA) Web Logs capture user web activity and security actions.
Zscaler ZPAZscalerAny destinationZscaler Private Access captures private app access, sessions, and connections.

Further reading