Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines
Blog post from Datadog
Datadog Observability Pipelines introduces Microsoft Sentinel Packs, preconfigured integrations that normalize vendor-specific firewall, VPN, and network detection logs into Microsoft Sentinel table schemas before ingestion. Available initially for Palo Alto Networks, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop, the Packs map supported events into schemas such as CommonSecurityLog and Syslog, deriving fields including severity and device actions to support Sentinel analytics rules, workbooks, and investigations without requiring teams to maintain custom parsers. By applying consistent mappings across sources, security teams can investigate activity such as suspicious outbound traffic using shared fields like SourceIP, DestinationIP, and DeviceAction rather than stitching together disparate raw formats. The pipeline-based approach also enables organizations to limit Sentinel’s per-GB ingest to high-value events, retain complete raw logs in lower-cost storage, and filter repetitive or low-risk data, including ExtraHop detections below a configured risk threshold.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Observability | 9 | 472 | 102 | 54 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.