Transform observability into action: How Datadog and Tines help you scale your security and compliance in real time

Written by Emily KerrSenior Partner Marketing Manager, Tines
Cover image for Transform observability into action: How Datadog and Tines help you scale your security and compliance in real time

Security and IT teams are managing growing volumes of logs, alerts, and telemetry data across disconnected tools and data stores. When teams are tasked with responding to audit or compliance requests, they need to pull the right information quickly and accurately and that is rarely a straightforward process. Investigations span multiple tools, logs sit in storage, routing and retrieving archived logs are manual processes that overburden teams when they can least afford it. 

To keep pace, more organizations are turning to AI and automation as a path forward for overwhelmed security and IT teams. As automation grows, so does the critical need of how to govern it and ensure that the data powering your workflows is accurate, compliant and audit ready - all without sacrificing your team’s already constrained bandwidth. 

Together, Tines and Datadog help teams meet compliance requirements without sacrificing security visibility or adding manual work. Datadog Observability Pipelines gives teams control over their telemetry before it ever reaches downstream destinations. It filters, governs, enriches and routes logs and metrics within your own environment. Teams are able to optimize log and SIEM costs, reduce compliance risk, and maintain a vendor agnostic ecosystem. With built-in support for GDPR, HIPAA, CCPA, and PCI compliance, and the ability to detect and redact PII, PHI and other regulated data before ingestion, Observability Pipelines ensure that what reaches your SIEM is clean, compliant and cost effective. 

Tines gives teams a secure environment to build, run, and maintain the agents, apps, and automation that act on Datadog observability data. Teams can control how that work accesses sensitive data and credentials, maintain an auditable record of activity, and identify and fix issues when something breaks or changes. For compliance processes, that means teams can automate work that would otherwise require manual effort, while maintaining the visibility and control needed to govern it over time.

Use Case: The offboarding gap that nobody watches

oktadatadogslack
Automate offboarding

Automate offboarding with Okta, Slack, and Datadog observability pipelines

Suspend Okta accounts, revoke sessions, and unenroll devices on employee termination, then tag their logs in Datadog Observability Pipelines for 30 days to flag post-termination activity.

Community author

Zara Boddula (Datadog)

Loading story...

When an employee is terminated, the traditional process depends on someone finding the time. The HR record has to be spotted, matched to an Okta account, the account suspended, active sessions and OAuth tokens revoked, every MFA factor unenrolled one at a time, the manager told about mailbox delegation and asset return, and then someone has to remember to check whether that identity shows up in logs afterwards. Most of it returns nothing interesting, so it drifts into a checklist that gets worked through on Monday, and the hours that matter most are the ones between the last day and the first login attempt nobody was watching for.

With Datadog and Tines working together, teams can automate that entire process.

  • Tines receives the termination event from the HRIS and normalizes it into a single employee record.

  • The matching Okta account is retrieved. If no account exists, the workflow notifies IT and stops rather than reporting a success it didn't achieve.

  • For involuntary terminations, the workflow pauses for approval in Slack before taking irreversible action.

  • Tines suspends the Okta account, revokes all sessions and OAuth tokens, and unenrolls every MFA factor.

  • The departed identity is added to a lookup table that Datadog Observability Pipelines enriches against, tagging any log event carrying that user for the next 30 days.

  • A Datadog monitor is created for the same identity, so post-termination activity alerts through the existing on-call path.

  • Slack gets a summary in the IT channel, and the manager gets a DM covering mailbox delegation and asset return.

  • Thirty days later, a companion workflow removes the lookup entry and deletes the monitor, so the watchlist stays short enough to be worth reading.

The result: access gone in minutes instead of days, no factor left enrolled on a phone the company doesn't own, and if that identity ever appears in a log line again, the team hears about it the same day.

When an analyst has a hunch, act on it

datadogtines🔎
Tag and investigate users with Datadog

Tag and investigate users with Datadog observability pipelines

Tag a user's logs in Datadog Observability Pipelines when an analyst submits an investigation, then automatically remove the tag when the case is closed.

Tools

DataDog

Community author

Zara Boddula (Datadog)

Loading story...

An analyst notices a user downloading an unusual volume of files. Not enough to trigger a detection, but enough to feel wrong. 

That instinct is often the only thing that catches a slow compromise or a supply chain attack moving through a trusted account. Neither looks like a spike. Both look like a slightly odd version of normal, which is why they depend on judgment rather than a rule. The problem is that judgment usually has nowhere to go except a manual hunt across several tools, while the activity in question keeps flowing through untagged.

With Datadog and Tines working together, teams can automate that entire process:

  • An analyst submits a user and a reason through a Tines form, so a hunch becomes a record with an owner and a timestamp.

  • Tines adds the user to a lookup table that Datadog Observability Pipelines enriches against, tagging every matching log event in flight with the investigation ID.

  • Tagged events are routed to an investigation destination alongside the normal path, leaving production log flow untouched.

  • Datadog returns the tagged activity as a single scoped view, so anyone joining the case queries one tag instead of rebuilding the original search.

  • New activity keeps getting tagged for as long as the investigation stays open, without anyone re-running anything.

  • When the case is closed, Tines removes the tag from the pipeline and records who closed it and when.

The result: acting on a hunch costs one form submission, evidence collects itself while the case is open, and the tag disappears when the case does instead of following the user around indefinitely.

The alert your CMDB could have dismissed

datadogslackservicenow
Suppress alert storms

Suppress alert storms with ServiceNow CMDB and Datadog Observability Pipelines

Investigate Datadog brute-force alerts against the ServiceNow CMDB to automatically suppress known scanners or escalate unrecognized IPs to Slack for analyst review.

Community author

Zara Boddula (Datadog)

Loading story...

A brute-force alert fires at 3am. It's the quarterly vulnerability scan, the same one that fired last quarter, hitting the same hosts from the same internal IP. The analyst who gets paged has no way to know that without opening the CMDB and looking the address up by hand, so they open the CMDB and look it up by hand, then close the alert and go back to bed.

The information needed to dismiss that alert already exists. It's sitting in ServiceNow, one lookup away, and the only reason a person is doing the lookup is that nothing connects the two systems at the moment the alert arrives. Do that a few dozen times and the team stops reading brute-force alerts carefully, which is exactly when a real one lands.  

With Datadog, ServiceNow, and Tines working together, teams can automate that entire process.

  • Datadog sends the brute-force alert to Tines as soon as it triggers, with the source IP and affected hosts.

  • Tines queries the ServiceNow CMDB for that IP to find out what it is and who owns it.

  • If the CMDB identifies it as a known scanner or other sanctioned system, Tines suppresses the alert in Datadog and logs the decision with the CMDB record that justified it.

  • If the IP is unrecognized, or the CMDB record doesn't account for the behavior, Tines escalates to Slack with the alert details and the lookup result already attached.

  • The analyst gets a decision to make rather than a lookup to perform, and a record of which alerts were suppressed and why.

The result: known scanners stop paging people, unrecognized IPs reach an analyst with context already gathered, and brute-force alerts become worth reading again.

Why this matters for IT & Security Teams

Together, Datadog and Tines help security and IT teams get more value from their telemetry without adding cost, complexity, or manual work. Datadog gives teams greater control over the data flowing through their environment, while Tines 3B provides a secure, auditable environment to put that data to work through AI and automation

For IT & security practitioners, the day-to-day impact is equally substantial. Less time manually routing and retrieving data, and more time investigating real threats and improving security.

Get started with Tines and Datadog

To learn more about shaping, enriching, and routing telemetry data before it reaches your destinations, read the Datadog Observability Pipelines documentation. Discover pre-built examples of Tines in action or get inspiration for your next build with the Tines library.

Sign up today to get started or schedule time with our team to learn more.