# observability pipelines

Published articles for observability pipelines.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines

DevFeed: [Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines](<https://devfeed.tech/articles/transform-and-route-security-logs-to-microsoft-sentinel-tables-using-observability-pipelines-31547.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/observability-pipelines-microsoft-sentinel-packs/>)

Author: Zara Boddula; Danielle Park

Published: 2026-09-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [cisco-meraki](<https://devfeed.tech/tags/cisco-meraki.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fortigate](<https://devfeed.tech/tags/fortigate.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Datadog's Observability Pipelines Packs transform firewall, VPN, and network detection logs into Microsoft Sentinel table schemas before ingestion. The post describes Packs for Palo Alto Networks, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop, including filtering and noise reduction to help control Sentinel ingest volume while retaining visibility.

### Source excerpt

Learn how Observability Pipelines Packs map security logs to Microsoft Sentinel schemas and help control downstream ingest volume.

## Datadog named the Company to Beat for observability platforms in 2026 Gartner® AI Vendor Race report

DevFeed: [Datadog named the Company to Beat for observability platforms in 2026 Gartner® AI Vendor Race report](<https://devfeed.tech/articles/datadog-named-the-company-to-beat-for-observability-platforms-in-2026-gartner-ai-vendor-race-report-17413.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/datadog-observability-platforms-gartner-ai-vendor-race-2026/>)

Author: Yanbing Li

Published: 2026-09-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability](<https://devfeed.tech/topics/observability.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [observability ai agents](<https://devfeed.tech/topics/observability-ai-agents.md>), [incident](<https://devfeed.tech/topics/incident.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agent-observability](<https://devfeed.tech/tags/agent-observability.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [datadog](<https://devfeed.tech/tags/datadog.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>)

### AI overview

Datadog says it was named the Company to Beat for observability platforms in Gartner's August 2026 AI Vendor Race research and a Leader in the 2026 Gartner Magic Quadrant for Observability Platforms. The article presents Datadog's unified observability and security platform, including autonomous incident investigation, AI agent and LLM application observability, an MCP Server for querying telemetry, and Observability Pipelines with OpenTelemetry support.

### Source excerpt

Datadog has been recognized as the Company to Beat for observability platforms in the August 2026 Gartner® AI Vendor Race research.

## Respond to security threats faster with Tines and Observability Pipelines

DevFeed: [Respond to security threats faster with Tines and Observability Pipelines](<https://devfeed.tech/articles/respond-to-security-threats-faster-with-tines-and-observability-pipelines-2314.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/tines-observability-pipelines-security-automation/>)

Author: Zara Boddula

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [accelerate](<https://devfeed.tech/tags/accelerate.md>), [api](<https://devfeed.tech/tags/api.md>), [automation](<https://devfeed.tech/tags/automation.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [reduce](<https://devfeed.tech/tags/reduce.md>), [security](<https://devfeed.tech/tags/security.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Tines and Datadog Observability Pipelines automate security-log processing by standardizing and routing logs, updating pipelines through APIs and reference tables, and applying current context in real time. The integration helps reduce alert noise, identify access-control gaps and suspicious activity, and accelerate threat investigations.

### Source excerpt

Learn how Tines workflows can update Datadog Observability Pipelines to prioritize threats, reduce alert noise, and accelerate investigations.

## Normalize security logs to Google SecOps UDM with Observability Pipelines

DevFeed: [Normalize security logs to Google SecOps UDM with Observability Pipelines](<https://devfeed.tech/articles/normalize-security-logs-to-google-secops-udm-with-observability-pipelines-2301.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/observability-pipelines-google-secops/>)

Author: Danielle Park

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [amazon-vpc](<https://devfeed.tech/tags/amazon-vpc.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [google-secops](<https://devfeed.tech/tags/google-secops.md>), [logs](<https://devfeed.tech/tags/logs.md>), [mapping](<https://devfeed.tech/tags/mapping.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vpc-flow-logs](<https://devfeed.tech/tags/vpc-flow-logs.md>)

### AI overview

The article explains how Observability Pipelines Google SecOps packs normalize security logs into the Unified Data Model before they reach Google SecOps.

### Source excerpt

Learn how Observability Pipelines normalizes your telemetry to Google SecOps UDM, enabling both consistent investigations across sources and precise upstream control over your SIEM ingest.

## Reduce CDN log costs with searchable archives

DevFeed: [Reduce CDN log costs with searchable archives](<https://devfeed.tech/articles/reduce-cdn-log-costs-with-searchable-archives-2304.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/reduce-cdn-log-costs-with-searchable-archives/>)

Author: Rufina Mariam

Published: 2026-06-26T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [archive search](<https://devfeed.tech/topics/archive-search.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [archive-search](<https://devfeed.tech/tags/archive-search.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [cost](<https://devfeed.tech/tags/cost.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [incident](<https://devfeed.tech/tags/incident.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [storage](<https://devfeed.tech/tags/storage.md>)

### AI overview

The article presents a cost-conscious approach to retaining high-volume CDN logs: route raw logs to object storage with Observability Pipelines, retain key signals in Datadog, and use Archive Search for historical investigations.

### Source excerpt

Route high-volume CDN logs to low-cost object storage with Observability Pipelines and search them with Archive Search--without a second tool.

## Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM

DevFeed: [Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM](<https://devfeed.tech/articles/automatically-enrich-security-logs-with-mitre-att-ck-context-before-they-reach-your-siem-2291.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/mitre-attack-enrichment-packs-observability-pipelines/>)

Author: Danielle Park

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how Observability Pipelines uses MITRE ATT&CK Enrichment Packs to automatically map security logs and events to common attacker tactics and techniques before they reach a SIEM, data lake, or archive. It describes the initial packs for Okta, Palo Alto, FortiGate, and AWS WAF, covering identity, firewall, network, and web security activity.

### Source excerpt

Learn how Observability Pipelines enriches security logs with MITRE ATT&CK tactics and techniques before routing them to your SIEM or storage destination.

## Datadog and ClickHouse partner to bring full-fidelity data to modern observability

DevFeed: [Datadog and ClickHouse partner to bring full-fidelity data to modern observability](<https://devfeed.tech/articles/datadog-and-clickhouse-partner-to-bring-full-fidelity-data-to-modern-observability-5222.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/datadog-and-clickhouse-partnership>)

Author: ClickHouse

Published: 2026-06-10T17:21:47Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [observability](<https://devfeed.tech/topics/observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [OpenTelemetry](<https://devfeed.tech/topics/opentelemetry.md>)

Tags: [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [cost](<https://devfeed.tech/tags/cost.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [opentelemetry](<https://devfeed.tech/tags/opentelemetry.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [performance](<https://devfeed.tech/tags/performance.md>), [retention](<https://devfeed.tech/tags/retention.md>), [scale](<https://devfeed.tech/tags/scale.md>), [search](<https://devfeed.tech/tags/search.md>)

### AI overview

ClickHouse and Datadog announce a partnership that lets organizations route logs to ClickHouse through Datadog Observability Pipelines and search them in Datadog Log Explorer. The integration combines ClickHouse's performance and cost efficiency for high-volume, long-term telemetry retention with Datadog's observability workflows and supports OpenTelemetry-compatible schemas.

### Source excerpt

ClickHouse and Datadog are partnering to combine full-fidelity log retention at scale with the powerful search and investigation experience engineers rely on every day.

## Store and search high-volume logs with ClickHouse and Datadog

DevFeed: [Store and search high-volume logs with ClickHouse and Datadog](<https://devfeed.tech/articles/store-and-search-high-volume-logs-with-clickhouse-and-datadog-2257.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/datadog-clickhouse-log-management/>)

Author: Andy Lihani

Published: 2026-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [archive search](<https://devfeed.tech/topics/archive-search.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [database](<https://devfeed.tech/tags/database.md>), [integration](<https://devfeed.tech/tags/integration.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [search](<https://devfeed.tech/tags/search.md>), [storage](<https://devfeed.tech/tags/storage.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Datadog introduces preview capabilities for routing high-volume logs to ClickHouse through Observability Pipelines and searching ClickHouse-stored logs from Datadog Log Explorer without re-ingestion.

### Source excerpt

Route logs to ClickHouse with Observability Pipelines and search them from the Datadog Log Explorer.

## Investigate logs across your entire stack with Federated Logs

DevFeed: [Investigate logs across your entire stack with Federated Logs](<https://devfeed.tech/articles/investigate-logs-across-your-entire-stack-with-federated-logs-2275.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/federated-logs-databricks-clickhouse-snowflake/>)

Author: Rufina Mariam

Published: 2026-06-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [log management](<https://devfeed.tech/topics/log-management.md>), [observability](<https://devfeed.tech/topics/observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [databricks](<https://devfeed.tech/topics/databricks.md>), [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [data](<https://devfeed.tech/topics/data.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [data](<https://devfeed.tech/tags/data.md>), [databricks](<https://devfeed.tech/tags/databricks.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [feature](<https://devfeed.tech/tags/feature.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Learn how Datadog Federated Logs lets teams query logs across Datadog and external data stores such as Databricks and ClickHouse from the Log Explorer. The article demonstrates how a single query interface can help investigate payment failures that trace back to an AI fraud detection model.

### Source excerpt

Learn how to use Federated Logs to investigate logs across Datadog, Databricks, ClickHouse, Amazon S3, and Snowflake.

## Introducing Log Drains

DevFeed: [Introducing Log Drains](<https://devfeed.tech/articles/introducing-log-drains-441.md>)

Original publisher: [Read original article](<https://supabase.com/blog/log-drains>)

Author: Lee TzeYiing

Published: 2024-08-15T07:00:00Z

Content type: release

Language: en

Sources: [Supabase Blog](<https://devfeed.tech/sources/supabase-blog.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [Supabase](<https://devfeed.tech/topics/supabase.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Cross-origin resource sharing (CORS)](<https://devfeed.tech/topics/cors.md>), [backends](<https://devfeed.tech/topics/backends.md>), [JSON](<https://devfeed.tech/topics/json.md>), [BigQuery](<https://devfeed.tech/topics/bigquery.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [bigquery](<https://devfeed.tech/tags/bigquery.md>), [datadog](<https://devfeed.tech/tags/datadog.md>), [http](<https://devfeed.tech/tags/http.md>), [json](<https://devfeed.tech/tags/json.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>)

### AI overview

Supabase introduces Log Drains for Team and Enterprise users, enabling logs from Database, Storage, Realtime, and Auth to be exported to Datadog Logs or custom HTTP endpoints. The feature supports alerting, observability pipelines, SIEM integrations, extended retention, self-hosting, and local development.

### Source excerpt

Log Drains for exporting product logs is now available under Public Alpha