Repository navigation
[DOCS-15474] Add default Standalone product info to Cloud SIEM docs #39641
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
b792057
bdc1bfe
6001558
8eb6f69
228e56b
50ff996
eeedaf5
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,18 +1,28 @@ | ||
| --- | ||
| title: Determine the Cloud SIEM product your organization is using | ||
| description: Cloud SIEM is available in Standalone, Add-on with Flex Logs, and Legacy products. Follow this guide to determine which product your organization is using. | ||
| description: Cloud SIEM is available in Standalone, Add-on with Flex Logs, and Legacy products. Follow this guide to determine which product your organization is using and compare the features available in each. | ||
| --- | ||
|
|
||
| ## Overview | ||
| Cloud SIEM is available as the following products: | ||
| - Standalone | ||
| - 12 months (365 days, usage measured in GB) | ||
| - 15 months (450 days, usage measured in millions of events) | ||
| <div class="alert alert-info">Organizations that adopted Standalone before 12-month retention was introduced have a 15-month retention period. The documentation refers to both as Standalone, because they provide the same features.</div> | ||
| - Add-on with Flex Logs | ||
| - Legacy | ||
|
|
||
| Standalone 12 months is the default product for new Cloud SIEM organizations. In Standalone: | ||
| - Usage is measured in gigabytes of analyzed logs, rather than in millions of analyzed events. | ||
| - Ingestion of logs indexed in the Cloud SIEM index is included in the analyzed log cost, rather than billed separately. | ||
| - Data is retained for 365 days (12 months), rather than for 15 months. | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Does "data" here refer to logs AND signals? If so, we should clarify they have different retention periods here as well.
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. @shrey4b let me know how to make this clearer! |
||
|
|
||
| There are two ways to see which Cloud SIEM product your organization is using: | ||
| - [Check the Plan & Usage page](#plan-usage) | ||
| - [Check the Cloud SIEM settings page](#settings) | ||
|
|
||
| To compare what each product includes, see [Features by Cloud SIEM product](#features). | ||
|
|
||
| ## Check the Plan & Usage page{#plan-usage} | ||
|
|
||
| <div class="alert alert-info">You may not be able to use this option if: | ||
|
|
@@ -74,7 +84,7 @@ In Datadog, go to the [Cloud SIEM settings][2] page. The page shows either a {{< | |
| </tr> | ||
| <tr> | ||
| <td><strong>Core Configuration</strong> section with <strong>Security Filters Configuration</strong><br /> | ||
| {{< img src="security/cloud_siem/guide/config_core_security_filters.png" alt="Configuration settings including a Core Configuration heading, which contains an Index Configuration section" width="80%">}} | ||
| {{< img src="security/cloud_siem/guide/config_core_security_filters.png" alt="Configuration settings including a Core Configuration heading, which contains an Security Filters Configuration section." width="80%">}} | ||
| </td> | ||
| <td>Add-on with Flex Logs</td> | ||
| </tr> | ||
|
|
@@ -87,8 +97,40 @@ In Datadog, go to the [Cloud SIEM settings][2] page. The page shows either a {{< | |
| </tbody> | ||
| </table> | ||
|
|
||
| Need additional assistance? Contact [Datadog support][3]. | ||
| ## Features by Cloud SIEM product{#features} | ||
|
|
||
| The following table lists the Cloud SIEM features available in each product. | ||
|
|
||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I would say let's leave Add-on out of this table as it maps to exactly what Standalone offers
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Is this true? Security and log index filters don't match in the below table
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Oops yes you're right
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We just don't publicly advertise Add on today - I'm wondering if it makes sense to keep it as a discoverability item - like to understand if you are on Add on, but not to have customers inquire about Add on, if that makes sense
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Yeah, I think docs tend to describe what's possible rather than trying to encourage people to go one way or the other |
||
| | Feature | Standalone | Add-on with Flex Logs | Legacy | | ||
| |---------|:----------:|:---------------------:|:------:| | ||
| | [Content Packs][4] | {{< X >}} | {{< X >}} | {{< X >}} | | ||
| | [Editing default detection rules][5] | {{< X >}} | {{< X >}} | {{< X >}} | | ||
| | [MITRE ATT&CK Map][6] | {{< X >}} | {{< X >}} | {{< X >}} | | ||
| | [Security Filters][7] | | {{< X >}} | {{< X >}} | | ||
| | [Log index filters][8] | {{< X >}} | | | | ||
| | [MITRE ATT&CK Map compact view][6] | {{< X >}} | {{< X >}} | | | ||
| | [Scheduled rules][9] | {{< X >}} | {{< X >}} | | | ||
| | [Sequence detections][10] | {{< X >}} | {{< X >}} | | | ||
| | [Historical jobs][11] | {{< X >}} | {{< X >}} | | | ||
| | [Risk Insights][12] | {{< X >}} | {{< X >}} | | | ||
| | [Dynamic Severity][13] | {{< X >}} | {{< X >}} | | | ||
| | [Open Cybersecurity Schema Framework (OCSF)][14] | {{< X >}} | {{< X >}} | | | ||
| | [Threat intelligence][15] | {{< X >}} | {{< X >}} | | | ||
|
|
||
| For help identifying your product, or to use a feature your product does not include, contact your Datadog account team or [Datadog support][3]. | ||
|
|
||
| [1]: https://app.datadoghq.com/billing/usage | ||
| [2]: https://app.datadoghq.com/security/configuration/siem/setup | ||
| [3]: /help/ | ||
| [4]: /security/cloud_siem/ingest_and_enrich/content_packs/ | ||
| [5]: /security/detection_rules/ | ||
| [6]: /security/cloud_siem/detect_and_monitor/mitre_attack_map/ | ||
| [7]: /security/cloud_siem/guide/customize-which-logs-cloud-siem-analyzes/#how-security-filters-work | ||
| [8]: /security/cloud_siem/guide/customize-which-logs-cloud-siem-analyzes/#cloud-siem-standalone-filter-the-cloud-siem-index | ||
| [9]: /security/cloud_siem/detect_and_monitor/custom_detection_rules/ | ||
| [10]: /security/cloud_siem/detect_and_monitor/custom_detection_rules/sequence/ | ||
| [11]: /security/cloud_siem/detect_and_monitor/historical_jobs/ | ||
| [12]: /security/cloud_siem/triage_and_investigate/entities_and_risk_scoring/ | ||
| [13]: /security/cloud_siem/detect_and_monitor/dynamic_severity/ | ||
| [14]: /security/cloud_siem/ingest_and_enrich/open_cybersecurity_schema_framework/ | ||
| [15]: /security/cloud_siem/ingest_and_enrich/threat_intelligence/ | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@maxvp This is ready for re-review when you have a second! Thanks for the suggestion to move this - how does this look to you?