Home / Companies / Datadog / Blog / Post Details
Content Deep Dive

Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines

Blog post from Datadog

Post Details
Company
Date Published
Author
Zara Boddula, Danielle Park
Word Count
1,000
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

Datadog Observability Pipelines introduces Microsoft Sentinel Packs, preconfigured integrations that normalize vendor-specific firewall, VPN, and network detection logs into Microsoft Sentinel table schemas before ingestion. Available initially for Palo Alto Networks, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop, the Packs map supported events into schemas such as CommonSecurityLog and Syslog, deriving fields including severity and device actions to support Sentinel analytics rules, workbooks, and investigations without requiring teams to maintain custom parsers. By applying consistent mappings across sources, security teams can investigate activity such as suspicious outbound traffic using shared fields like SourceIP, DestinationIP, and DeviceAction rather than stitching together disparate raw formats. The pipeline-based approach also enables organizations to limit Sentinel’s per-GB ingest to high-value events, retain complete raw logs in lower-cost storage, and filter repetitive or low-risk data, including ExtraHop detections below a configured risk threshold.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 9 472 102 54 -85%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.