Datadog Security
SIEM
Pushes events to Datadog Logs with the `service:isochronic` tag. Datadog Cloud SIEM rules can match on `evt.name:policy_outcome` and outcome fields.
Forwarding rules
- All policy_outcome events
- All denied outcomes
Surfaces this would light up
- Datadog Cloud SIEM rules
- Log Explorer