Company
Date Published
Author
Tiit Hallas
Word count
515
Language
American English
Hacker News points
None

Summary

Dynatrace's Security Investigator introduces pivoting queries to enhance DQL queries, allowing engineers to switch investigation contexts swiftly by changing query scopes through available pivoting dimensions. This tool is particularly useful for analyzing complex scenarios, such as investigating latency issues in cloud applications by examining Istio proxy logs. Security Investigator, integrated with Dynatrace, leverages logs, metrics, and traces within the Dynatracer GrailĀ® data lakehouse for evidence-driven security investigations. The pivoting queries feature enables users to maintain investigation context, perform complex queries, and save findings for further analysis, while allowing quick shifts in perspective by right-clicking records and selecting pivot dimensions like Kubernetes pod or trace_id. This results in new query nodes for comprehensive context analysis, speeding up investigations by applying different contexts efficiently, and utilizing the power of query trees and other investigative features. The pivoting dimensions can be customized to suit the investigation's needs, enhancing the flexibility and speed of incident response.