How we brought agentic workflows to Cloud SIEM with the Datadog MCP Server
Blog post from Datadog
Security engineers using Cloud SIEM navigate complex workflows by investigating signals, tuning detection rules, and managing suppressions, with agents becoming crucial tools in this process. To address these needs, a set of security tools were developed for the Datadog MCP Server, designed to support various interconnected workflows while managing a shared context window to prevent task confusion. The development of these tools was driven by real user behaviors, analyzed through API call patterns, Real User Monitoring data, and chat logs, highlighting common tasks such as detection rule authoring and bulk signal triage, which often hit the system's limits. Progressive disclosure and a custom evaluation framework were employed to manage the context window and test tools' reliability, ensuring that only necessary information is provided for each task and that tools function as intended despite non-deterministic behavior. A lightweight governance model was implemented to maintain tool quality across a growing multi-team toolset, focusing on real user interactions to guide development and refinement, while setting standards to prevent new tools from degrading existing ones.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 10 | 3,533 | 369 | 145 | -53% |
| Harness engineering | 4 | 137 | 67 | 36 | -46% |
| Observability | 1 | 1,844 | 344 | 128 | -56% |
| Platform Engineering | 1 | 544 | 153 | 49 | -67% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.