Datadog Detection Posture Report
Delivers a weekly report on Datadog Cloud SIEM log ingestion gaps, detection rules that are disabled, erroring, or blind, and anything in the organization that needs an admin, from Security Filter exclusions to silent Agents.
What this agent does
This read-only agent checks the health of Datadog Cloud SIEM every week. It finds log sources and services that stopped sending, and Datadog Agents that stopped reporting. It finds Security Filter exclusions that keep logs a rule needs out of Cloud SIEM analysis. It finds sources whose logs stopped carrying an attribute a rule queries. It finds detection rules that are disabled, failing, or querying sources with no data. It summarizes the security signals raised and closed since last week. It flags anything that needs an admin.
The challenge
A detection rule fires only when Cloud SIEM analyzes the logs it queries. A Security Filter exclusion added to cut Cloud SIEM cost drops the events a rule needs. A service renames its source tag and every rule that filtered on the old one returns nothing. A log format change drops an attribute and a rule's query stops matching. Fewer signals each week look like a quieter environment.
The solution
The agent checks ingestion, Security Filters, rule health, and signal activity in one pass each week and compares them with the previous week. It names the logs that stopped, the rules that cannot fire, and the fix for each. Provides a weekly briefing a detection engineer can read in a few minutes.
Workflow
- 01
Check ingestion
Compare log volume per source and service with the previous week, check Agent check-ins, and read each Security Filter and its exclusions.
- 02
Check rule health
Read each detection rule's enabled state, recent errors, and the sources, services, and attributes its query depends on.
- 03
Check activity
Summarize security signals raised, closed, and archived since last week, by rule.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Datadog Detection Posture Report
## Measurable outcomes
Every week, the detection engineer knows which logs stopped arriving, which detection rules cannot fire, and what needs action before a detection is missed. Track the silent sources, the unhealthy rules, and the open action items on every run.
## Procedure
Once a week, read the log volume per source and per service for the last 7 days and compare with the previous 7 days. Flag each source or service that fell to zero or dropped by more than half, unless I mark it as expected. Flag Datadog Agents that have not reported in the window. Read each Security Filter and its exclusions, and flag any that removes a source or service a detection rule queries. Count logs tagged datadog.cloud_siem:false from sources a rule queries. Flag sources where the share of logs missing an attribute a rule queries rose against the previous week. For each detection rule in Cloud SIEM, read its enabled state, its query, and the sources, services, and attributes the query depends on. Flag a rule as blind when a source or service it depends on is silent or excluded by a Security Filter. Flag rules with execution errors in the window. List rules that were disabled or changed since last week, with who changed them, and default rules Datadog updated. Summarize the security signals raised, closed, and archived since the last report, by rule. Flag rules that raised nothing in the last 30 days and at least one in the 90 days before. Skip New Value and Anomaly rules still in their learning period. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Datadog API access to logs usage, the logs in scope, Security Filters, Agents, security monitoring rules, and signals, and nothing more. It never changes rules, Security Filters, pipelines, or signals. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools