Workload Protection security signals are created when Datadog detects a threat based on a security rule. View, search, filter, and investigate security signals in the Signals Explorer, or configure Notification Rules to send signals to third-party tools.

Signals Explorer

The Signals Explorer lists Workload Protection security signals generated by detection rules. Use the search bar or facet panel to filter signals by severity, triage state, detection rule, host, container, and other attributes. For example, to filter by triage state, use @workflow.triage.state:<status>, where <status> is the state you want (open, under_review, or archived). You can also use the Signal State facet on the facet panel.

Select a signal to open the side panel. From there, you can investigate the threat using the investigation graph, timeline, context, and Signal JSON, or take action to triage, escalate, automate, or respond to the signal.

Next steps