December 2021 Summaries
13 posts from Datadog
Filter
Month:
Year:
Post Summaries
Back to Blog
Fairwinds Insights is a Kubernetes governance and security software that helps DevOps teams monitor and prevent configuration problems in their infrastructure and applications. The integration of Fairwinds Insights with Datadog Marketplace provides end-to-end visibility into clusters and the applications they're running, enabling continuous monitoring of Kubernetes security and cost optimization without compromising reliability. Key features include action items related to new deployments, estimated workload costs, remediation guidance, links to reference resources, and customizable dashboards.
Dec 21, 2021
853 words in the original blog post.
GitHub Apps is a service that automates key processes in workflows and enables direct interaction with the GitHub API. Integrating Datadog with GitHub allows users to add valuable context to notebooks, access links to Git repositories, and view inline code snippets for stack traces. This integration helps reduce mean time to resolution (MTTR) by enabling faster troubleshooting and pinpointing the root cause of issues without leaving Datadog. Additionally, Datadog's GitHub integration works seamlessly with Notebooks, allowing users to create richer postmortems, investigations, and reports by adding link previews of issues and pull requests. The combination of GitHub and source code integrations in Datadog provides a powerful tool for faster troubleshooting and efficient access to relevant information.
Dec 21, 2021
647 words in the original blog post.
Fairwinds Insights is a Kubernetes governance and security software that simplifies complexity and reduces risk by surfacing security and reliability issues in Kubernetes clusters. The Fairwinds Insights integration with Datadog provides end-to-end visibility into clusters and applications, offering essential insights such as action items related to new deployments, estimated cost of workloads, remediation guidance, and more. This integration enables continuous monitoring of Kubernetes cluster security and optimization of costs without sacrificing reliability, providing actionable recommendations for root cause analysis, cost optimization, and remediation guidance. With Fairwinds Insights, teams can quickly triage urgent problems, mark action items as resolved, or assign issues to team members, ensuring feedback is sent to responsible infrastructure teams. The integration also helps ensure that resources are provisioned in a way that enforces policies, promoting branded monitoring tools in the Datadog Marketplace and enabling the development of custom integrations.
Dec 21, 2021
864 words in the original blog post.
Datadog Cloud SIEM provides an extensive set of out-of-the-box detection rules to help detect security threats in large-scale environments. These rules can be combined with log-based detection rules that are tailored to a specific business case, allowing users to automatically identify malicious activity and mitigate threats before they become more serious. To create powerful detection rules, it's essential to build efficient queries that extract the most critical security-related events from application logs, use templates and template variables to create informative signals, and create suppression lists to reduce false positives. Datadog's flexible search syntax enables users to customize queries to fit their needs, and security signals provide important details about activity flagged by a detection rule, including customizable messages that can be used to share security policies and remediation steps. By fine-tuning security signals and suppressing noise, users can accelerate investigation efforts and identify real threats to their applications.
Dec 15, 2021
1,381 words in the original blog post.
The text provides a detailed analysis of the Log4Shell vulnerability in the Log4j Java logging library, identified as CVE-2021-44228, which allows remote code execution and full system control by attackers. Disclosed in December 2021, the vulnerability was introduced in 2013 and exploited as a zero-day in the wild before public awareness. The document outlines the timeline of discovery, methods for identifying and securing vulnerable systems, and remediation strategies, including upgrading to Log4j version 2.16+. It elaborates on the exploit chain, highlighting how attackers use the Java Naming and Directory Interface (JNDI) to compromise applications. Datadog's Security Platform is discussed as a tool for detecting and preventing such exploits, with capabilities to identify attack payloads and monitor for suspicious activities. Real-world exploitation attempts observed by Datadog, such as those involving the Kinsing malware, are described to illustrate the threat's prevalence and the importance of a defense-in-depth security strategy.
Dec 14, 2021
1,757 words in the original blog post.
The integration of Amazon S3 Storage Lens with Datadog enhances the ability to monitor and optimize S3 storage across multiple AWS accounts and regions. By leveraging S3 Storage Lens metrics through Datadog's dashboard, users can gain detailed insights into storage trends, cost efficiency, and data protection practices. The dashboard facilitates granular analysis by allowing filtration of metrics by various parameters such as AWS organization, account, and region, thereby helping organizations understand changes and trends in S3 usage. Cost optimization is achieved by identifying non-current object versions and incomplete uploads that can be deleted, and by utilizing efficient data retrieval methods like Amazon S3 Select. Furthermore, the integration supports data protection by providing a summary of encrypted, replicated, and protected storage, allowing users to configure alerts for any deviations. It also aids in maintaining continuous visibility and security of S3 data, suggesting steps that align with AWS best practices for data protection. Users can begin utilizing this integration with a straightforward setup process, enhancing their S3 management capabilities.
Dec 09, 2021
817 words in the original blog post.
HashiCorp Vault provides centralized storage and management of passwords, API keys, tokens, and other secrets that distributed applications can use to operate securely. Audit logs are critical for investigating potential security issues in Vault. In this post, we explained some common threats to HashiCorp Vault security, such as using root or recovery tokens to access your secrets, disabling audit logging, and elevating permissions assigned to Vault clients. Datadog can help detect these and other threats with automated threat detection and alerting.
Dec 08, 2021
2,278 words in the original blog post.
HashiCorp Vault provides centralized storage and management of sensitive data, such as passwords and API keys. However, this centralized system can be vulnerable to security threats, including the use of root or recovery tokens by attackers to access secrets, disabling audit logging to cover their tracks, elevating permissions assigned to Vault clients, manipulating Vault policies to introduce security risks, and leveraging elevated privileges to disable audit devices or manipulate policies. To detect potential malicious activity in Vault installations, Datadog Cloud SIEM automatically analyzes Vault audit logs as they're ingested, providing automated threat detection and alerting capabilities to ensure the security of secrets stored in Vault.
Dec 08, 2021
2,175 words in the original blog post.
Azure Cosmos DB is a fully managed NoSQL database that automatically scales with load and supports multiple APIs, making it easy to incorporate with applications while removing the need for maintaining own servers. The integrated cache can help reduce costs and improve performance by reducing request units (RUs). Datadog's Azure Cosmos DB integration now includes metrics to track the health and performance of the integrated cache and dedicated gateway. Users can optimize their cache hit rate, rightsize their dedicated gateway cluster, and evaluate the benefits of using the Azure Cosmos DB integrated cache. The integration also helps monitor the entire cloud environment by integrating with all Azure services.
Dec 07, 2021
1,000 words in the original blog post.
The text discusses the benefits and features of using Azure Cosmos DB's integrated cache, a read-through, write-through cache that can be placed between an application and Azure Cosmos DB without changing business logic. This cache can help reduce costs and improve performance by reducing request units (RUs) consumed by reads. Datadog's integration with Azure Cosmos DB provides metrics to track the health and performance of the integrated cache, allowing users to optimize their cache hit rate and right-size their dedicated gateway cluster to achieve significant cost savings. The text also highlights scenarios where the integrated cache is most beneficial, such as read-heavy workloads, and provides guidance on evaluating its benefits and monitoring Azure Cosmos DB account performance using Datadog's integration.
Dec 07, 2021
1,010 words in the original blog post.
HashiCorp Cloud Platform (HCP) offers fully managed versions of popular HashiCorp tools like Vault for secure secret management across distributed systems. Datadog's new HCP Vault integration provides an out-of-the-box dashboard to monitor cluster activity and detect potential security vulnerabilities. The integration helps identify unusual token activity, track client usage across namespaces, and analyze tokens by authentication method and associated policies. This enables organizations to optimize their use of Vault, plan cloud resources effectively, and respond quickly to potential threats.
Dec 01, 2021
765 words in the original blog post.
HashiCorp Cloud Platform (HCP) provides a fully managed version of Vault, which allows users to securely store and manage access to secrets across distributed systems. Datadog's new integration with HCP Vault enables an out-of-the-box dashboard for monitoring activity, analyzing security vulnerabilities, and detecting potential threats such as token TTLs. The integration also helps track client usage across namespaces, providing insights into how teams are using Vault and enabling organizations to optimize their cloud resources and detect anomalies in token usage patterns. With the Datadog-HCP Vault integration, users can start monitoring HCP Vault metrics and audit logs with ease, streamlining their security and compliance efforts.
Dec 01, 2021
771 words in the original blog post.
Watchdog is Datadog's AI-driven engine that automatically detects performance issues in infrastructure and applications using algorithms like anomaly detection. A new feature, Impact Analysis, assesses the impact of these issues on end users by analyzing metrics from RUM SDKs. It helps prioritize troubleshooting by highlighting which performance anomalies affect the most users, thereby reducing business impact and aiding in the prevention of future issues. Impact Analysis provides detailed information on user impact, including which users were affected, and facilitates the creation of postmortems by exporting data to Datadog Notebooks. This feature is automatically available to all Datadog APM and RUM users, enhancing visibility into service performance and streamlining incident response.
Dec 01, 2021
731 words in the original blog post.