1997年出生属什么| 南京大屠杀是什么时候| 一个小时尿一次是什么原因| mar是什么意思| 总是掉头发是什么原因| 指甲油用什么能洗掉| 真金白银是什么意思| 牙龈肿痛吃什么药| 高密度脂蛋白偏低是什么意思| 12.6是什么星座| 女生的名字叫什么好听| 沙土地适合种什么农作物| 流变是什么意思| 晚来天欲雪能饮一杯无什么意思| 性病都有什么| 失眠吃什么药最有效| 手脚发热什么原因| 列文虎克发现了什么| 荞麦长什么样子图片| 小儿风寒感冒吃什么药| 什么水果不上火| as是什么意思| 小脑萎缩吃什么药好| 血小板减少吃什么药| 大安是什么意思| 心脏斑块是什么意思啊| 肺部有结节要注意什么| 咳嗽有黄痰是什么原因| 放屁臭是什么原因| 取保候审是什么意思还会判刑吗| 蚊子的天敌是什么| 男人射精快吃什么药| 狗为什么吐舌头| xanax是什么药| 介质是什么意思| 玄关是什么意思| 房性逸搏心律是什么意思| 周海媚什么病| 浓绿的什么| 为什么喝完酒头疼| 记忆力下降是什么原因引起的| 臭虫怕什么| 喉咙痰多是什么原因造成的| 吃什么食物对胰腺好| 办出国护照需要什么手续| 迦字五行属什么| 3.1是什么星座| 大牙什么时候换| 85年属牛是什么命| 排骨和什么一起炖好吃| 背上长痘是什么原因| 尿检能查出什么| 牛肉配什么菜包饺子好吃| 紫光檀是什么木| 一什么不什么| 丞字五行属什么| 口头禅什么意思| 甲方乙方是什么意思| 遥不可及什么意思| 卤米松软膏主治什么| 左腹下方隐痛什么原因| 心率低于60说明什么| 为什么不建议打水光针| 早搏心律不齐吃什么药| 湿热体质适合喝什么茶| 吃腰果有什么好处| 天蝎座和什么星座最不配| 背后长疙瘩是什么原因| 龙利鱼是什么鱼| 寄大件用什么物流便宜| 吃饺子是什么节日| 早入簧门姓氏标什么意思| 多发息肉是什么意思| 阴囊上长了几根白毛是什么原因| 孕妇喝什么茶对胎儿好| 浮萍是什么意思| 长水痘可以吃什么菜| 耽美剧是什么意思| 交警支队长是什么级别| 孕妇贫血吃什么药| 骨折长骨痂有什么反应| 腿上长水泡是什么原因| 肝不好有什么症状有哪些表现| 06属什么生肖| sei是什么意思| 戒奶涨奶痛有什么缓解方法| 四妙丸有什么功效与作用| 怀孕吃叶酸有什么用| 脾阳虚吃什么食物好| 吃什么补肝血| 为什么会得骨癌| 心跳加速心慌吃什么药| 空调滤芯什么牌子好| 6月24是什么日子| 什么是总胆固醇| 真菌感染是什么意思| 喝完酒吃点什么对胃好| 什么是翘舌音| pop店铺是什么意思| 证监会是干什么的| 油条吃多了有什么危害| 孕妇刚生完孩子吃什么好| 年检是什么意思| venus是什么星球| 宫颈筛查hpv阳性是什么意思| 属鸡的本命佛是什么佛| 什么鸟好养又与人亲近| 植物的茎有什么作用| b是什么| 小巧思什么意思| 下面瘙痒用什么药膏| 甲状腺查什么| cg什么意思| 八大碗都有什么菜| 便秘和腹泻交替出现是什么意思| 小孩子眼睛眨得很频繁是什么原因| 黄芪治什么病| 木驴是什么| 艾滋病简称什么| 全身检查挂什么科| 梦见自己头发白了是什么意思| 连衣裙配什么鞋子好看| 什么水果降火效果最好| 剥离是什么意思| 梦见穿袜子是什么意思| 冬日暖阳是什么意思| 这是什么情况| 肛门瘙痒用什么药膏| 偈语是什么意思| 半什么三什么| 谁也不知道下一秒会发生什么| 天下之奇是什么生肖| 头昏是什么原因| 肝火旺盛吃什么食物好| 大红袍属于什么茶| 李子吃多了有什么坏处| 为什么二楼比三楼好| anca是什么检查| 警察为什么叫蜀黍| 囊肿是什么病严重吗| 什么是舌吻| 婚姻是爱情的坟墓是什么意思| 人的反义词是什么| 麻腮风是什么| 梦见自己儿子死了是什么意思| 山东立冬吃什么| 防代表什么生肖| 五月初六是什么星座| 侧写是什么意思| 全身酸痛失眠什么原因| 怀孕初期要注意什么| 夏至吃什么好| 心率不齐有什么危害| 一什么黑暗| 荨麻疹有什么症状| 处女座的幸运色是什么| 假菌丝是什么意思| 什么时候有雨| kenzo是什么牌子| 孩子脾虚内热大便干吃什么药| 心烦意乱焦躁不安吃什么药| 奶粉可以做什么美食| 阿司匹林什么时候吃| 什么叫重本大学| 一声叹息是什么意思| 一什么瓦| 田螺姑娘是什么意思| 洗涤是什么意思| 颈椎退变是什么意思| co什么意思| 拔牙后能吃什么| 割包皮应该挂什么科| 蜗牛爱吃什么食物| 下眼袋发青是什么原因| hrd是什么意思| ubras是什么牌子| 甘甜是什么意思| 男同是什么| 高血压二级是什么意思| 什么是预科生| 毛囊炎长什么样| 早上起来不晨勃是什么原因| 泌尿外科主要看什么病| 随诊是什么意思| 扁平化管理是什么意思| 勃艮第红是什么颜色| 阿扎西是什么意思| 什么是微量元素| 台卡是什么| 吃鸡蛋胃疼是什么原因| 海马用什么呼吸| 吃什么食物可以减肥| 复刻是什么意思| 新疆是什么气候| 全日制专科是什么意思| 灵芝不能和什么一起吃| 新生儿一直哭闹是什么原因| 尿液检查能查出什么病| 为什么有白带| 不知道为了什么| 安踏属于什么档次| 会厌炎是什么病| 下午4点是什么时辰| 脸上不出汗是什么原因| 接盘侠什么意思| 家政是什么工作| 六月中旬是什么时候| 青睐是什么意思| 84年属鼠是什么命| 桥本是什么意思| 胳膊上的花是打了什么疫苗| 吃什么对胰腺有好处| 艾滋病通过什么传染| 身上长黑痣是什么原因| 身体安康什么意思| 疼痛科主要看什么病| 不言而喻的喻是什么意思| 血小板偏高是什么原因| 牙齿根部发黑是什么原因| 吃什么可以增强抵抗力和免疫力| 拔牙之后吃什么消炎药| 什么是结膜炎| SEX是什么| 舌头中间疼是什么原因| 什么酒适合女生喝| 什么是月食| 月经期间肚子疼是什么原因| 什么树木| 脚心痒是什么原因引起的| 孕妇吃冰的东西对胎儿有什么影响| 梦见小女孩是什么预兆| 什么鞋油好用| 马和驴为什么能杂交| 正厅级是什么级别| 蒙蒙的什么| 异食癖是什么意思| 耳朵发烫是什么原因| 吃钙片有什么好处| 低压高吃什么| 急性尿道炎吃什么药| 三花鱼是什么鱼| 赤诚相见是什么意思| 支气管炎吃什么药| 双规是什么| 脑补是什么意思| 刘备的马叫什么| 两肺纹理增多什么意思| 一周年祭日有什么讲究| 过敏是什么样子的| 补气血吃什么最好| 芙蓉粉是什么颜色| 腰痛吃什么药好| 咳嗽咳出血是什么原因| 君子兰叶子发黄是什么原因| 五味子不适合什么人喝| 盐酸利多卡因注射作用是什么| 阴虚血热什么症状| 咳嗽恶心干呕是什么原因引起的| 小猫来家里有什么预兆| 县检察长是什么级别| 高同型半胱氨酸血症是什么病| 天经地义是什么意思| 晚上9点是什么时辰| 大仙为什么知道你的事| 百度

Overview

百度 本案也是北京市首例比特币被盗案件。

As an administrator or security team member, you can use Datadog Audit Trail to see who is using Datadog within your organization and the context in which they are using Datadog. As an individual, you can see a stream of your own actions, too.

There are two types of events that can occur within an audit trail: request events, which translate all requests made to Datadog’s API into customer records, or product-specific events.

For example, track request events so you can see what API calls led up to the event. Or, if you’re an enterprise or billing admin, use audit trail events to track user events that change the state of your infrastructure.

In this circumstance, audit events are helpful when you want to know product-specific events such as:

  • When someone changed the retention of an index because the log volume changed and, therefore, the monthly bill has changed.

  • Who modified processors or pipelines, and when they were modified, as a dashboard or monitor is now broken and needs to be fixed.

  • Who modified an exclusion filter because the indexing volume has increased or decreased and logs are unable to be found or your bill went up.

For security admins or InfoSec teams, audit trail events help with compliance checks and maintaining audit trails of who did what, and when, for your Datadog resources. For example, maintaining an audit trail:

  • Of anytime someone updates or deletes critical dashboard, monitors, and other Datadog resources.

  • For user logins, account, or role changes in your organization.

You can also analyze Audit Trail events with Cloud SIEM to detect threats and generate security signals. See Getting Started with Cloud SIEM for more information.

Note: See PCI DSS Compliance for information on setting up a PCI-compliant Datadog organization.

Setup

To enable Datadog Audit Trail, navigate to your Organization Settings and select Audit Trail Settings under COMPLIANCE. Click the Enable button.

The Audit Trail Settings page showing it disabled

To see who enabled Audit Trail:

  1. Navigate to Events Explorer.
  2. Enter Datadog Audit Trail was enabled by in the search bar. You may have to select a wider time range to capture the event.
  3. The most recent event with the title “A user enabled Datadog Audit Trail” shows who last enabled Audit Trail.

Configuration

Permissions

Only users with Audit Trail Write permission can enable or disable Audit Trail. Additionally, users need Audit Trail Read permission to view audit events using Audit Explorer.

Archiving

Archiving is an optional feature for Audit Trail. You can use archiving to write to Amazon S3, Google Cloud Storage, or Azure Storage and have your SIEM system read events from it. After creating or updating your archive configurations, it can take several minutes before the next archive upload is attempted. Events are uploaded to the archive every 15 minutes, so check back on your storage bucket in 15 minutes to make sure the archives are successfully being uploaded from your Datadog account.

To enable archiving for Audit Trail, navigate to your Organization Settings and select Audit Trail Settings under Compliance. Scroll down to Archiving and click the Store Events toggle to enable.

Retention

Retaining events is an optional feature for Audit Trail. In the Retention Period section, click the Change retention period to select a retention length appropriate for your use case.

When Audit Trail is enabled, the default retention period for an audit trail event is 90 days. You can set the retention period to: 3, 7, 15, 30, or 90 days.

When Audit Trail is disabled, the retention period is reset back to the default 7 days.

Audit Trail Retention setup in Datadog

Explore audit events

To explore an audit event, navigate to the Audit Trail section, also accessible from your Organization Settings in Datadog.

Audit Trail Settings in the Organization Settings menu

Audit Trail events have the same functionality as logs within the Log Explorer:

  • Filter to inspect audit trail events by Event Names (Dashboards, Monitors, Authentication, and more), Authentication Attributes (Actor, API Key ID, User email, and more), Status (Error, Warn, Info), Method (POST, GET, DELETE), and other facets.

  • Inspect related audit trail events by selecting an event and navigating to the event attributes tab. Select a specific attribute to filter by or exclude from your search, such as http.method, usr.email, client.ip, and more.

Audit Trail in the Organization Settings menu

Saved views

Efficient troubleshooting requires your data to be in the proper scope to permit exploration, have access to visualization options to surface meaningful information, and have relevant facets listed to enable analysis. Troubleshooting is contextual, and Saved Views make it easier for you and your teammates to switch between different troubleshooting contexts. You can access Saved Views in the upper left corner of the Audit Trail explorer.

All saved views, that are not your default view, are shared across your organization:

  • Integration saved views come out-of-the-box with Audit Trail. These views are read-only, and identified by the Datadog logo.
  • Custom saved views are created by users. They are editable by any user in your organization (except read only users), and identified with the avatar of the user who created them Click the Save button to create a new custom saved view from the current content of your explorer.

At any moment, from the saved view entry in the Views panel:

  • Load or reload a saved view.
  • Update a saved view with the configuration of the current view.
  • Rename or delete a saved view.
  • Share a saved view through a short-link.
  • Star (turn into a favorite) a saved view so that it appears on top of your saved view list, and is accessible directly from the navigation menu.

Note: Update, rename, and delete actions are disabled for integration saved views and read only users.

Default view

Default view

The default view feature allows you to set a default set of queries or filters that you always see when you first open the Audit Trail explorer. You can come back to your default view by opening the Views panel and clicking the reload button.

Your existing Audit Trail explorer view is your default saved view. This configuration is only accessible and viewable to you, and updating this configuration does not have any impact on your organization. You can temporarily override your default saved view by completing any action in the UI or by opening links to the Audit Trail explorer that embed a different configuration.

At any moment, from the default view entry in the Views panel:

  • Reload your default view by clicking on the entry.
  • Update your default view with the current parameters.
  • Reset your default view to Datadog’s defaults for a fresh restart.

Notable Events

Notable events are a subset of audit events that show potential critical configuration changes that could impact billing or have security implications as identified by Datadog. This allows org admins to hone in on the most important events out of the many events generated, and without having to learn about all available events and their properties.

The audit event facet panel showing notable events checked

Events that match the following queries are marked as notable.

Description of audit eventQuery in audit explorer
Changes to log-based metrics@evt.name:"Log Management" @asset.type:"custom_metrics"
Changes to Log Management index exclusion filters@evt.name:"Log Management" @asset.type:"exclusion_filter"
Changes to Log Management indexes@evt.name:"Log Management" @asset.type:index
Changes to APM retention filters@evt.name:APM @asset.type:retention_filter
Changes to APM custom metrics@evt.name:APM @asset.type:custom_metrics
Changes to metrics tags@evt.name:Metrics @asset.type:metric @action:(created OR modified)
Creations and deletion of RUM applications@evt.name:"Real User Monitoring" @asset.type:real_user_monitoring_application @action:(created OR deleted)
Changes to Sensitive Data Scanner scanning groups@evt.name:"Sensitive Data Scanner" @asset.type:sensitive_data_scanner_scanning_group
Creation or deletion of Synthetic tests@evt.name:"Synthetics Monitoring" @asset.type:synthetics_test @action:(created OR deleted)

Inspect Changes (Diff)

The Inspect Changes (Diff) tab in the audit event details panel compares the configuration changes that were made to what was previously set. It shows the changes made to dashboard, notebook, and monitor configurations, which are represented as JSON objects.

The audit event side panel showing the changes to a composite monitor configuration, where the text highlighted in green is what was changed and the text highlighted in red is what was removed.

Filter audit events based on Reference Tables

Reference Tables containing over 1,000,000 rows cannot be used to filter events. See Add Custom Metadata with Reference Tables for more information on how to create and manage Reference Tables.

Reference Tables allow you to combine metadata with audit events, providing more information to investigate Datadog user behavior. Add a query filter based on a Reference Table to perform lookup queries. For more information on activating and managing this feature, see the Reference Tables guide.

To apply a query filter with Reference Tables, click on the + Add button next to the query editor and select Join with Reference Table. In the following example, the Reference Table query filter is used to search for dashboards modified by users who are accessing Datadog from non-authorized IP addresses:

The Datadog Audit Trail explorer with reference table search options highlighted

API key auditing

Log management users can audit API key usage with Audit Trail. For API key auditing, logs have a datadog.api_key_uuid tag that contains the UUID of the API key used for collecting those logs. Use this information to determine:

  • How API keys are used across your organization and telemetry sources.
  • API key rotation and management.

Create a monitor

To create a monitor on a type of audit trail event or by specificTrail attributes, see the Audit Trail Monitor documentation. For example, set a monitor that triggers when a specific user logs in, or set a monitor for anytime a dashboard is deleted.

Create a dashboard or a graph

Give more visual context to your audit trail events with dashboards. To create an audit dashboard:

  1. Create a New Dashboard in Datadog.
  2. Select your visualization. You can visualize Audit events as top lists, timeseries, and lists.
  3. Graph your data: Under edit, select Audit Events as the data source, and create a query. Audit events are filtered by count and can be grouped by different facets. Select a facet and limit.
    Set Audit Trail as a data source to graph your data
  4. Set your display preferences and give your graph a title. Click the Save button to create the dashboard.

Create a scheduled report

Datadog Audit Trail allows you to send out audit analytics views as routinely scheduled emails. These reports are useful for regular monitoring of the Datadog platform usage. For example, you can choose to get a weekly report of the number of unique Datadog user logins by country. This query allows you to monitor anomalous login activity or receive automated insight on usage.

To export an audit analytics query as a report, create a timeseries, top list, or a table query and click More… > Export as scheduled report to start exporting your query as a scheduled report.

Note: The List view does not have the option to export to a scheduled report.

Export as scheduled report function in the More... dropdown menu
  1. Enter a name for the dashboard, which is created with the query widget. A new dashboard is created for every scheduled report. This dashboard can be referenced and changed later if you need to change the report content or schedule.
  2. Schedule the email report by customizing the report frequency and time frame.
  3. Add recipients that you want to send the email to.
  4. Add any additional customized messages that needs to be part of the email report.
  5. Click Create Dashboard and Schedule Report.
Exporting a audit analytics view into a scheduled email

Download Audit Events as CSV

Datadog Audit Trail allows you to download up to 100K audit events as a CSV file locally. These events can then be analyzed locally, uploaded to a different tool for further analytics, or shared with appropriate team members as part of a security and compliance exercise.

To export audit events as CSV:

  1. Run the appropriate search query that captures the events you are interested in
  2. Add event fields as columns in the view that you want as part of CSV
  3. Click on Download as CSV
  4. Select the number of events to export and export as CSV

Out-of-the-box dashboard

Datadog Audit Trail comes with an out-of-the-box dashboard that shows various audit events, such as index retention changes, log pipeline changes, dashboard changes, and more. Clone this dashboard to customize queries and visualizations for your auditing needs.

Audit Trail dashboard

Audit terminal commands with CoTerm

CoTerm allows you to record terminal sessions for analysis in Datadog. You can use CoTerm to audit sensitive system changes done through terminals. You can then review these commands and their output as logs and events in Datadog.

Further Reading

长期湿热会引起什么病 感冒什么时候能好 吃什么水果减肥最快减肚子 拔牙后吃什么 dr股票是什么意思
中年危机是什么意思 游离甲状腺素是什么 什么样的人做什么样的事 低热吃什么药 回族为什么姓马的多
mua什么意思 肝疼是什么原因 实性结节什么意思 牛的本命佛是什么佛 嗜睡什么意思
问诊是什么意思 非浅表性胃炎是什么意思 食人鱼的天敌是什么 sp是什么意思 狐臭挂什么科
泥鳅吃什么hcv8jop1ns2r.cn 大同有什么好玩的地方hcv9jop7ns4r.cn 摆地摊卖什么最赚钱而且很受欢迎hcv8jop4ns2r.cn 什么东西能吃不能碰hcv8jop7ns9r.cn 尿频吃什么药hcv9jop3ns7r.cn
老年人吃饭老是噎着是什么原因hcv7jop7ns1r.cn 帆状胎盘是什么意思hcv7jop6ns6r.cn 茉莉花是什么颜色hcv8jop5ns6r.cn 核素是什么hcv9jop6ns1r.cn 羊肉馅饺子配什么菜好hcv8jop7ns7r.cn
吃什么能降铁蛋白hcv8jop5ns1r.cn 眼压是什么hcv7jop5ns1r.cn 单核细胞计数偏高是什么意思hcv8jop1ns3r.cn wing什么意思baiqunet.com 苑什么意思hcv8jop5ns5r.cn
猪肉什么馅的饺子好吃hcv7jop5ns3r.cn 发烧感冒挂什么科室hcv9jop6ns8r.cn 黄毛什么意思hcv8jop9ns7r.cn 李志为什么hcv8jop5ns4r.cn 说话口臭是什么原因引起的hcv8jop0ns0r.cn
百度