Datadog
Read post

Normalize security logs to Google SecOps UDM with Observability Pipelines

Datadog's Observability Pipelines now offers Google SecOps packs — preconfigured mappings that automatically normalize security logs from sources like Palo Alto Firewall, Fortinet Firewall, Windows Event Log, Amazon VPC, and Cisco ASA into Google SecOps Unified Data Model (UDM) format before ingestion. This eliminates the need to manually build and maintain per-source field mappings, enables cross-source detections using consistent UDM fields, and allows teams to filter low-value logs upstream to control SIEM ingest costs. A Live Capture feature lets engineers validate transformation logic against real production logs.

    #devops
Jul 28•6m read time•From datadoghq.com
Post cover image
Table of contents
Normalize and optimize your data before it reaches Google SecOpsInvestigate security activity across every sourceControl ingest costs without losing visibilityNormalize your security logs for faster Google SecOps investigations
71 Impressions
Datadog's image
Datadog

DataDog Blog offers insights, tutorials, and updates on monitoring, analytics, and observability sol...

170 Followers

•

568 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard