Datadog's Observability Pipelines now offers Google SecOps packs — preconfigured mappings that automatically normalize security logs from sources like Palo Alto Firewall, Fortinet Firewall, Windows Event Log, Amazon VPC, and Cisco ASA into Google SecOps Unified Data Model (UDM) format before ingestion. This eliminates the need to manually build and maintain per-source field mappings, enables cross-source detections using consistent UDM fields, and allows teams to filter low-value logs upstream to control SIEM ingest costs. A Live Capture feature lets engineers validate transformation logic against real production logs.
Table of contents
Normalize and optimize your data before it reaches Google SecOpsInvestigate security activity across every sourceControl ingest costs without losing visibilityNormalize your security logs for faster Google SecOps investigations71 Impressions