Home / Companies / Datadog / Blog / Post Details
Content Deep Dive

Normalize security logs to Google SecOps UDM with Observability Pipelines

Blog post from Datadog

Post Details
Company
Date Published
Author
Danielle Park
Word Count
1,040
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Google Security Operations (SecOps) is a platform designed to handle security threats by processing large volumes of security telemetry using a Unified Data Model (UDM), which standardizes logs from various sources like firewalls and endpoints. This standardization allows security teams to easily analyze and respond to threats as data is normalized before it reaches Google SecOps, enabling efficient investigations and reducing the need for separate detection logic for each source. The platform includes Google SecOps packs that come with preconfigured mappings for different log sources, such as Palo Alto Firewall and Windows Event Log, ensuring that they conform to UDM standards and are ready for analysis. These packs streamline the process by allowing teams to write detection rules once and apply them across all sources, reducing manual maintenance and controlling ingest costs by focusing on high-value logs. Observability Pipelines further supports this by providing tools to map logs to both UDM and Open Cybersecurity Schema Framework (OCSF), enhancing the data's utility and enriching it with additional context for better security insights.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.