Home / Companies / Datadog / Blog / Post Details
Content Deep Dive

Backtest detection rules with Datadog Cloud SIEM Historical Jobs

Blog post from Datadog

Post Details
Company
Date Published
Author
Nimisha Saxena, Vera Chan
Word Count
666
Language
English
Hacker News Points
-
Summary

Datadog Cloud SIEM` offers a solution to the common problem of deploying new threat detections effectively by using `Detection-as-Code`, which enables security teams to test their detection rules in various ways, including `backtesting`, `unit testing`, and `simulation`. The `Historical Jobs` feature allows users to run their detections against historical logs stored in `Datadog`, providing essential insights into potential threats or anomalies identified within the associated logs. By using `Historical Jobs`, security teams can conduct thorough investigations of past events, uncover activity patterns, and understand the context of previous security incidents. This approach helps build confidence that new rules will generate valuable signals at the right time and in the right manner.