Home / Companies / Dynatrace / Blog / Post Details
Content Deep Dive

Generate security events from Dynatrace Security Investigator via OpenPipeline

Blog post from Dynatrace

Post Details
Company
Date Published
Author
Tiit Hallas
Word Count
1,633
Company Posts That Month
17
Language
American English
Hacker News Points
-
Post removed?
No
Summary

In the context of threat-hunting activities using Dynatrace, this blog post details how to automate the detection of suspicious DNS queries, such as those using DNS tunneling, by creating a custom Dynatrace security event. By leveraging Dynatrace's DQL expressions and JSON matchers, users can extract specific fields from DNS query logs and automate these detections through Dynatrace AutomationEngine, using workflows that run at regular intervals. The post further explains how to set up a custom pipeline for ingesting security events using Dynatrace OpenPipeline, which includes creating custom endpoints and adding fields for data analysis. It also covers creating secure tokens for event ingestion, integrating with other systems like Slack or Jira for notifications, and utilizing the semantic dictionary to streamline data analysis. The ultimate goal is to operationalize threat detection and improve security event management within Dynatrace's ecosystem.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 1,277 102 52 +46%
Data Pipeline 1 1,400 332 68 +111%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.