# SIEM, Security

Security information and event management (SIEM) is a security application that gathers security data from information-system components and presents actionable information through a single interface.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Architecting a secure landing zone in the AWS European Sovereign Cloud

DevFeed: [Architecting a secure landing zone in the AWS European Sovereign Cloud](<https://devfeed.tech/articles/architecting-a-secure-landing-zone-in-the-aws-european-sovereign-cloud-31478.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/architecting-a-secure-landing-zone-in-the-aws-european-sovereign-cloud/>)

Author: Pablo Pagani

Published: 2026-09-16T21:20:48Z

Content type: article

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-identity-and-access-management-iam](<https://devfeed.tech/tags/aws-identity-and-access-management-iam.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [infrastructure-as-code-iac](<https://devfeed.tech/tags/infrastructure-as-code-iac.md>), [partition](<https://devfeed.tech/tags/partition.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [technical-how-to](<https://devfeed.tech/tags/technical-how-to.md>)

### AI overview

This article explains how to architect a secure, scalable landing zone in the AWS European Sovereign Cloud. It describes the aws-eusc partition boundary and covers governance, identity, logging, data protection, network design, CI/CD, artifact distribution, and incident response.

### Source excerpt

The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and [...]

## Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines

DevFeed: [Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines](<https://devfeed.tech/articles/transform-and-route-security-logs-to-microsoft-sentinel-tables-using-observability-pipelines-31547.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/observability-pipelines-microsoft-sentinel-packs/>)

Author: Zara Boddula; Danielle Park

Published: 2026-09-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [cisco-meraki](<https://devfeed.tech/tags/cisco-meraki.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fortigate](<https://devfeed.tech/tags/fortigate.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Datadog's Observability Pipelines Packs transform firewall, VPN, and network detection logs into Microsoft Sentinel table schemas before ingestion. The post describes Packs for Palo Alto Networks, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop, including filtering and noise reduction to help control Sentinel ingest volume while retaining visibility.

### Source excerpt

Learn how Observability Pipelines Packs map security logs to Microsoft Sentinel schemas and help control downstream ingest volume.

## ClickHouse welcomes RunReveal

DevFeed: [ClickHouse welcomes RunReveal](<https://devfeed.tech/articles/clickhouse-welcomes-runreveal-5165.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/clickhouse-welcomes-runreveal>)

Author: ClickHouse

Published: 2026-09-01T22:01:39Z

Content type: news

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Database](<https://devfeed.tech/topics/database.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>)

Tags: [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [database](<https://devfeed.tech/tags/database.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

ClickHouse announces its acquisition of RunReveal, a security data platform built on ClickHouse. The article discusses security-data workloads, continued RunReveal support, and plans to apply the team's expertise to security and agentic investigations.

### Source excerpt

Security is the largest and fastest growing data workload in the enterprise, and today, ClickHouse has acquired RunReveal.

## VAST Data CrowdStrike Integration Goes Live: Native Falcon Sensor Now, Next-Gen SIEM and AIDR in Preview

DevFeed: [VAST Data CrowdStrike Integration Goes Live: Native Falcon Sensor Now, Next-Gen SIEM and AIDR in Preview](<https://devfeed.tech/articles/vast-data-crowdstrike-integration-goes-live-native-falcon-sensor-now-next-gen-siem-and-aidr-in-preview-12379.md>)

Original publisher: [Read original article](<https://www.storagereview.com/news/vast-data-crowdstrike-integration-goes-live-native-falcon-sensor-now-next-gen-siem-and-aidr-in-preview>)

Author: Harold Fritts

Published: 2026-09-01T15:37:31Z

Content type: news

Language: en

Sources: [StorageReview.com](<https://devfeed.tech/sources/storagereview-com.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Jailbreak](<https://devfeed.tech/topics/jailbreak.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Nvidia](<https://devfeed.tech/topics/nvidia.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [pii](<https://devfeed.tech/tags/pii.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

VAST Data and CrowdStrike have launched an integration that embeds Falcon security capabilities into VAST AI storage infrastructure, data pipelines, and production AI workloads. The integration supports native Falcon sensors, sends VAST audit telemetry to CrowdStrike Next-Gen SIEM, inspects data in flight with Falcon AIDR, helps identify PII before downstream use, and detects prompt injection and jailbreak attempts during model interactions.

### Source excerpt

VAST Data and CrowdStrike are turning the AI security partnership they announced at VAST Forward in February into a shipping product, detailing a multi-layered integration that embeds enterprise-grade cybersecurity directly into AI storage infrastructure, data pipelines, and production AI workloads. By combining the VAST AI Operating System with the CrowdStrike Falcon platform, the collaboration addresses The post VAST Data CrowdStrike Integration Goes Live: Native Falcon Sensor Now, Next-Gen SIEM and AIDR in Preview appeared first on StorageReview.com.

## Centralize human and agentic work with Datadog Work Management

DevFeed: [Centralize human and agentic work with Datadog Work Management](<https://devfeed.tech/articles/centralize-human-and-agentic-work-with-datadog-work-management-2319.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/work-management/>)

Author: Roxanne Moslehi

Published: 2026-08-18T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [incident](<https://devfeed.tech/topics/incident.md>), [site-reliability-engineering](<https://devfeed.tech/topics/site-reliability-engineering.md>), [Slack](<https://devfeed.tech/topics/slack.md>), [SRE](<https://devfeed.tech/topics/sre.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [error tracking](<https://devfeed.tech/topics/error-tracking.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Traces](<https://devfeed.tech/topics/traces.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [error-tracking](<https://devfeed.tech/tags/error-tracking.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [management](<https://devfeed.tech/tags/management.md>), [slack](<https://devfeed.tech/tags/slack.md>), [sre](<https://devfeed.tech/tags/sre.md>), [traces](<https://devfeed.tech/tags/traces.md>), [work-management](<https://devfeed.tech/tags/work-management.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

Datadog Work Management centralizes work created by people, automations, and Datadog AI agents. It preserves context from logs, traces, monitors, alerts, ownership, assignments, approvals, artifacts, and activity while integrating with Datadog and external collaboration systems.

### Source excerpt

Learn how Datadog Work Management helps you coordinate human and AI agent-driven work while preserving context, ownership, and activity across tools.

## Audit Log Drains now support Datadog, Splunk, and Panther

DevFeed: [Audit Log Drains now support Datadog, Splunk, and Panther](<https://devfeed.tech/articles/audit-log-drains-now-support-datadog-splunk-and-panther-813.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/audit-log-drains-now-support-datadog-splunk-and-panther>)

Author: Nate McGrady

Published: 2026-08-07T04:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Streaming](<https://devfeed.tech/topics/streaming.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>)

Tags: [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [datadog](<https://devfeed.tech/tags/datadog.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [integration](<https://devfeed.tech/tags/integration.md>), [logs](<https://devfeed.tech/tags/logs.md>), [migration](<https://devfeed.tech/tags/migration.md>), [migration-guide](<https://devfeed.tech/tags/migration-guide.md>), [s3](<https://devfeed.tech/tags/s3.md>), [streaming](<https://devfeed.tech/tags/streaming.md>)

### AI overview

Vercel Audit Log Drains can stream team audit events and metadata to Datadog, Splunk, or Panther, in addition to custom HTTPS endpoints and Amazon S3. The feature is available on Enterprise plans and replaces Custom SIEM Log Streaming.

### Source excerpt

Audit Log Drains now stream your team's audit events into Datadog, Splunk, and Panther, joining the existing custom HTTPS endpoint and Amazon S3 destinations. An Audit Log Drain forwards every event from your team's Activity Log, plus additional audit metadata, to the destination you choose. They're available on Enterprise plans. To create one, go to Drains in your team settings. Click Add Drain, choose Audit Log as the data type, and pick a destination. Audit Log Drains replace Custom SIEM Log Streaming. If you already stream audit logs to a SIEM, follow the migration guide to move your integration over. Learn more about Drains in the documentation. Read more

## How we secure Figma's internal systems with agents

DevFeed: [How we secure Figma's internal systems with agents](<https://devfeed.tech/articles/how-we-secure-figma-s-internal-systems-with-agents-9817.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/how-we-secure-figmas-internal-systems-with-agents/>)

Author: Matthew Sullivan; Brad Girardeau

Published: 2026-07-29T20:44:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Amazon Bedrock](<https://devfeed.tech/topics/amazon-bedrock.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Code](<https://devfeed.tech/topics/code.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [bedrock](<https://devfeed.tech/tags/bedrock.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [code](<https://devfeed.tech/tags/code.md>), [llm](<https://devfeed.tech/tags/llm.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Figma's security team built an AI agent that triages alerts, investigates incidents, queries security data, writes fixes, opens pull requests, and retains knowledge from prior investigations. The system reduced alert time to resolution by 71% and changed how on-call engineers handle security work.

### Source excerpt

Our security team built an AI agent that triages alerts, conducts forensic investigations, queries our security data lake, writes code to fix issues--and remembers what it learns. Here's how we cut alert time-to-resolution by 71% and fundamentally changed how our on-call engineers work.

## How we brought agentic workflows to Cloud SIEM with the Datadog MCP Server

DevFeed: [How we brought agentic workflows to Cloud SIEM with the Datadog MCP Server](<https://devfeed.tech/articles/how-we-brought-agentic-workflows-to-cloud-siem-with-the-datadog-mcp-server-2245.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/creating-mcp-tools-for-cloud-siem/>)

Author: Chelsea Xu; Eddie Cai; Romain Kirszbaum; Mohamed Hachem Ouertani

Published: 2026-07-17T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [real user monitoring](<https://devfeed.tech/topics/real-user-monitoring.md>)

Tags: [agent-observability](<https://devfeed.tech/tags/agent-observability.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-impact](<https://devfeed.tech/tags/ai-impact.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [context-window](<https://devfeed.tech/tags/context-window.md>), [eval](<https://devfeed.tech/tags/eval.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [real-user-monitoring](<https://devfeed.tech/tags/real-user-monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [tool](<https://devfeed.tech/tags/tool.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article explains how Datadog built MCP tools for Cloud SIEM to support agentic security workflows. It covers tool scoping based on user behavior, progressive disclosure for managing a shared context window, custom evaluation of non-deterministic agent behavior, and governance of a growing multi-team toolset.

### Source excerpt

See how we built MCP tools for Cloud SIEM, using usage data, progressive disclosure, and a custom eval framework to keep a multi-team agentic toolset reliable.

## Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM

DevFeed: [Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM](<https://devfeed.tech/articles/automatically-enrich-security-logs-with-mitre-att-ck-context-before-they-reach-your-siem-2291.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/mitre-attack-enrichment-packs-observability-pipelines/>)

Author: Danielle Park

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how Observability Pipelines uses MITRE ATT&CK Enrichment Packs to automatically map security logs and events to common attacker tactics and techniques before they reach a SIEM, data lake, or archive. It describes the initial packs for Okta, Palo Alto, FortiGate, and AWS WAF, covering identity, firewall, network, and web security activity.

### Source excerpt

Learn how Observability Pipelines enriches security logs with MITRE ATT&CK tactics and techniques before routing them to your SIEM or storage destination.

## Detecting the Klue supply chain attack in Salesforce instances

DevFeed: [Detecting the Klue supply chain attack in Salesforce instances](<https://devfeed.tech/articles/detecting-the-klue-supply-chain-attack-in-salesforce-instances-8286.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/>)

Author: Julie Agnes Sparks

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [API](<https://devfeed.tech/topics/api.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Python](<https://devfeed.tech/topics/python.md>), [data](<https://devfeed.tech/topics/data.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [data](<https://devfeed.tech/tags/data.md>), [external](<https://devfeed.tech/tags/external.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integration](<https://devfeed.tech/tags/integration.md>), [logs](<https://devfeed.tech/tags/logs.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [python](<https://devfeed.tech/tags/python.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [salesforce](<https://devfeed.tech/tags/salesforce.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

This article summarizes the Klue supply chain attack, in which a threat actor abused a dormant integration credential to obtain OAuth tokens and query connected Salesforce environments through automated Python REST API calls. It reconstructs the attack timeline and provides detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

### Source excerpt

We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

## Audit trails are a feature, not a compliance tax

DevFeed: [Audit trails are a feature, not a compliance tax](<https://devfeed.tech/articles/audit-trails-are-a-feature-not-a-compliance-tax-9179.md>)

Original publisher: [Read original article](<https://webflowmarketingmain.com/blog/audit-trails-not-a-compliance-tax>)

Author: Mohit Bansal

Published: 2026-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Webflow Blog](<https://devfeed.tech/sources/webflow-blog.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

The article argues that audit logging has evolved from an overlooked compliance requirement into a product capability. Queryable, timestamped logs can support sales, vendor evaluations, accountability for AI agents, and more complete breach reconstruction.

### Source excerpt

Logging used to satisfy auditors. Now it closes deals, holds AI agents accountable, and decides whether you can reconstruct a breach.

## How to Design SIEM Alerts for Real-Time Application Security Monitoring

DevFeed: [How to Design SIEM Alerts for Real-Time Application Security Monitoring](<https://devfeed.tech/articles/siem-alerts-everything-you-need-to-know-20056.md>)

Original publisher: [Read original article](<https://www.honeybadger.io/blog/siem-alerts/>)

Author: Muhammed Ali

Published: 2026-05-21T07:00:00Z

Content type: tutorial

Language: en

Sources: [Honeybadger](<https://devfeed.tech/sources/honeybadger.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [real-time](<https://devfeed.tech/topics/real-time.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devops-articles](<https://devfeed.tech/tags/devops-articles.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [security-events](<https://devfeed.tech/tags/security-events.md>), [siem](<https://devfeed.tech/tags/siem.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This tutorial explains SIEM alerts, their role in application security, and how SIEM platforms aggregate and correlate logs and security events to identify suspicious behavior. It also provides practical alert examples and describes configuring simple alerts with Honeybadger Insights.

### Source excerpt

SIEM alerts help you detect suspicious behavior before it becomes a breach. But security monitoring can quickly turn into noisy dashboards and missed threats without the right approach. Read this article to learn how to design effective SIEM alerts and implement real-time security monitoring.

## PCI DSS Compliance: What Digital Businesses Need to Know

DevFeed: [PCI DSS Compliance: What Digital Businesses Need to Know](<https://devfeed.tech/articles/pci-dss-compliance-what-digital-businesses-need-to-know-10274.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/pci-dss-compliance-digital-business/>)

Author: Ayush Agarwal

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [digital-products](<https://devfeed.tech/tags/digital-products.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [saas](<https://devfeed.tech/tags/saas.md>), [scope](<https://devfeed.tech/tags/scope.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tokenization](<https://devfeed.tech/tags/tokenization.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This guide explains how PCI DSS applies to digital businesses that accept card payments, including SaaS companies and sellers of digital products. It outlines the standard's 12 requirements and discusses controls for networks, account data, vulnerabilities, access, monitoring, and information security. It also covers card-not-present transactions, recurring billing, and tokenization.

### Source excerpt

PCI DSS compliance explained for digital businesses. Understand the 12 requirements, compliance levels, and how to reduce your scope when selling digital products online.

## Logging for Detection and Response: How We Build Security Signals at Cockroach Labs

DevFeed: [Logging for Detection and Response: How We Build Security Signals at Cockroach Labs](<https://devfeed.tech/articles/logging-for-detection-and-response-how-we-build-security-signals-at-cockroach-labs-23792.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/logging-for-detection-and-response>)

Author: Munir Jaber

Published: 2026-01-15T00:00:00Z

Content type: article

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [Security](<https://devfeed.tech/topics/security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logging](<https://devfeed.tech/tags/logging.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Cockroach Labs describes a security logging architecture for Detection and Response around CockroachDB and its supporting cloud services. The approach prioritizes logs that capture meaningful behaviors, support event reconstruction, and provide useful signals for detection and incident response, with detection rules reviewed and tested like software.

### Source excerpt

Modern applications rely on CockroachDB for workloads where resilience, correctness and availability are absolutely critical. Whether it's being deployed for payment systems, identity provider systems, or transactional systems, one thing is certain: If the underlying database platform of these applications isn't secure, nothing built on top of it can be truly secure, either.

## Know your tools: The full range of Elastic Security's detection engineering capabilities

DevFeed: [Know your tools: The full range of Elastic Security's detection engineering capabilities](<https://devfeed.tech/articles/know-your-tools-the-full-range-of-elastic-security-s-detection-engineering-capabilities-21083.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/elastic-security-detection-engineering>)

Author: Kseniia Ignatovych

Published: 2024-11-12T05:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [alert triage](<https://devfeed.tech/topics/alert-triage.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [alert-fatigue](<https://devfeed.tech/tags/alert-fatigue.md>), [alert-triage](<https://devfeed.tech/tags/alert-triage.md>), [automated](<https://devfeed.tech/tags/automated.md>), [automated-threat-protection-cybersecurity-defense-security-compliance](<https://devfeed.tech/tags/automated-threat-protection-cybersecurity-defense-security-compliance.md>), [blog](<https://devfeed.tech/tags/blog.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [features](<https://devfeed.tech/tags/features.md>), [latest-features](<https://devfeed.tech/tags/latest-features.md>), [quality](<https://devfeed.tech/tags/quality.md>), [security](<https://devfeed.tech/tags/security.md>), [security-siem](<https://devfeed.tech/tags/security-siem.md>), [siem](<https://devfeed.tech/tags/siem.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [tools](<https://devfeed.tech/tags/tools.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This Elastic Security blog provides an overview of detection engineering capabilities, including customizable prebuilt rules, alert suppression, manual rule runs, automated case creation, and machine learning jobs.

### Source excerpt

This blog provides a comprehensive overview of the detection capabilities available in Elastic Security. Learn about the latest features and get useful tips and tricks for your detection practice!

## Introducing Log Drains

DevFeed: [Introducing Log Drains](<https://devfeed.tech/articles/introducing-log-drains-441.md>)

Original publisher: [Read original article](<https://supabase.com/blog/log-drains>)

Author: Lee TzeYiing

Published: 2024-08-15T07:00:00Z

Content type: release

Language: en

Sources: [Supabase Blog](<https://devfeed.tech/sources/supabase-blog.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [Supabase](<https://devfeed.tech/topics/supabase.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Cross-origin resource sharing (CORS)](<https://devfeed.tech/topics/cors.md>), [backends](<https://devfeed.tech/topics/backends.md>), [JSON](<https://devfeed.tech/topics/json.md>), [BigQuery](<https://devfeed.tech/topics/bigquery.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [bigquery](<https://devfeed.tech/tags/bigquery.md>), [datadog](<https://devfeed.tech/tags/datadog.md>), [http](<https://devfeed.tech/tags/http.md>), [json](<https://devfeed.tech/tags/json.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>)

### AI overview

Supabase introduces Log Drains for Team and Enterprise users, enabling logs from Database, Storage, Realtime, and Auth to be exported to Datadog Logs or custom HTTP endpoints. The feature supports alerting, observability pipelines, SIEM integrations, extended retention, self-hosting, and local development.

### Source excerpt

Log Drains for exporting product logs is now available under Public Alpha

## Application vulnerability management best practices

DevFeed: [Application vulnerability management best practices](<https://devfeed.tech/articles/application-vulnerability-management-best-practices-8229.md>)

Original publisher: [Read original article](<https://snyk.io/blog/vulnerability-management-best-practices/>)

Author: Mariah Gresham

Published: 2024-08-06T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [iac](<https://devfeed.tech/tags/iac.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains application vulnerability management as a lifecycle approach for identifying, classifying, remediating, mitigating, reporting, and continuously monitoring application vulnerabilities. It describes how DevSecOps practices such as containerization, infrastructure as code, AI coding assistants, and third-party code require security teams to adapt existing techniques. It also covers enterprise practices including automation, management tools, SIEM systems, and regulatory mapping.

### Source excerpt

Learn about application vulnerability management, including its basic definition, what it can and cannot do, and how to supplement it with best practices.

## Reducing false positives with automated SIEM investigations from Elastic and Tines

DevFeed: [Reducing false positives with automated SIEM investigations from Elastic and Tines](<https://devfeed.tech/articles/reducing-false-positives-with-automated-siem-investigations-from-elastic-and-tines-4823.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/false-positives-automated-siem-investigations-elastic-tines>)

Author: Aaron Jewitt

Published: 2024-05-31T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [analysts](<https://devfeed.tech/tags/analysts.md>), [api](<https://devfeed.tech/tags/api.md>), [automated-threat-protection-anomaly-detection-cybersecurity-network-visibility-security-analytic](<https://devfeed.tech/tags/automated-threat-protection-anomaly-detection-cybersecurity-network-visibility-security-analytic.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [endpoint-security-security](<https://devfeed.tech/tags/endpoint-security-security.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [soc](<https://devfeed.tech/tags/soc.md>), [token](<https://devfeed.tech/tags/token.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Elastic's InfoSec team uses Tines to automate initial SIEM alert investigations, helping reduce false positives and analyst fatigue. The workflow queries Elasticsearch using alert data such as source.ip, closes alerts associated with trusted devices or known benign activity, and escalates cases that cannot be resolved automatically.

### Source excerpt

Discover how Elastic's InfoSec team saves thousands of hours per month by using Tines to automate SIEM alert investigations while reducing false positives and detect compromised accounts.

## Rolling your own Detections as Code with Elastic Security

DevFeed: [Rolling your own Detections as Code with Elastic Security](<https://devfeed.tech/articles/rolling-your-own-detections-as-code-with-elastic-security-4797.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/detections-as-code-elastic-security>)

Author: Mika Ayenson,Kseniia Ignatovych,Justin Ibarra

Published: 2024-05-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [automated-threat-protection-cybersecurity-devops-open-security](<https://devfeed.tech/tags/automated-threat-protection-cybersecurity-devops-open-security.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [devops](<https://devfeed.tech/tags/devops.md>), [research](<https://devfeed.tech/tags/research.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [siem-security](<https://devfeed.tech/tags/siem-security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

Elastic describes how its detection-rules repository supports Detections as Code, including rule-management tooling, tests, CLI commands, and automation. The article explains how teams can adapt these capabilities for custom detection-rule management using peer review, testing, and CI/CD practices.

### Source excerpt

Detections as Code (DaC) is transforming security rule management. Learn about Elastic's latest enhancements in the detection-rules repo, how to leverage it for custom rule management, and our comprehensive guide for adopting DaC.