-
Notifications
You must be signed in to change notification settings - Fork 1.5k
[SAASINT-4032] DDS: DNSFilter: Crawler Integration v1.0.0 #20384
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
[SAASINT-4032] DDS: DNSFilter: Crawler Integration v1.0.0 #20384
Conversation
Created DOCS-11046 for Docs Team review. |
I'm the assigned reviewer from Documentation. |
|
||
## Overview | ||
|
||
This check monitors [DNSFilter][1]. | ||
[DNSFilter][1] is a cloud-based content filtering and threat protection by blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[DNSFilter][1] is a cloud-based content filtering and threat protection by blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience. | |
[DNSFilter][1] is a cloud-based content filtering tool that blocks internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience. |
The first sentence is not grammatically correct. I made one possible edit, but feel free to revise to your preferences.
|
||
### Installation | ||
This integration seamlessly collects DNS Traffic Logs, channeling them into Datadog for analysis. Leveraging the built-in logs pipeline, these logs are parsed and enriched, enabling effortless search and analysis. The integration provides insight into dns traffic logs through out-of-the-box dashboards and includes ready-to-use Cloud SIEM detection rules for improved monitoring and security. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This integration seamlessly collects DNS Traffic Logs, channeling them into Datadog for analysis. Leveraging the built-in logs pipeline, these logs are parsed and enriched, enabling effortless search and analysis. The integration provides insight into dns traffic logs through out-of-the-box dashboards and includes ready-to-use Cloud SIEM detection rules for improved monitoring and security. | |
This integration collects DNS Traffic Logs, channeling them into Datadog for analysis. Leveraging the built-in logs pipeline, these logs are parsed and enriched, enabling search and analysis. The integration provides insight into DNS traffic logs through out-of-the-box dashboards and includes ready-to-use Cloud SIEM detection rules for improved monitoring and security. |
|
||
The DNSFilter check is included in the [Datadog Agent][2] package. | ||
No additional installation is needed on your server. | ||
### Generate API Credentials in DNSFilter |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
### Generate API Credentials in DNSFilter | |
### Generate API credentials in DNSFilter |
3. Navigate to **Security** tab. | ||
4. Navigate to **API Keys** section, then click **CREATE KEY**. | ||
5. Enter a key **Name** and select an **Expiration**. | ||
6. Click **GENERATE KEY**. | ||
7. Fetch API Key from **Your API Key** Section. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
3. Navigate to **Security** tab. | |
4. Navigate to **API Keys** section, then click **CREATE KEY**. | |
5. Enter a key **Name** and select an **Expiration**. | |
6. Click **GENERATE KEY**. | |
7. Fetch API Key from **Your API Key** Section. | |
3. Navigate to the **Security** tab. | |
4. Navigate to the **API Keys** section, then click **CREATE KEY**. | |
5. Enter a key **Name** and select an **Expiration**. | |
6. Click **GENERATE KEY**. | |
7. Fetch the API Key from the **Your API Key** Section. |
|
||
!!! Add list of steps to set up this integration !!! | ||
### Connect your DNSFilter Account to Datadog |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
### Connect your DNSFilter Account to Datadog | |
### Connect your DNSFilter account to Datadog |
!!! Add steps to validate integration is functioning as expected !!! | ||
| Parameters | Description | | ||
| ------------------------------------- | ------------------------------------------------------------ | | ||
| API Key | The API Key of your DNSFilter Platform | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| API Key | The API Key of your DNSFilter Platform | | |
| API Key | The API Key of your DNSFilter platform | |
|
||
DNSFilter does not include any metrics. | ||
The DNSFilter integration collects and forwards dns traffic logs to Datadog. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The DNSFilter integration collects and forwards dns traffic logs to Datadog. | |
The DNSFilter integration collects and forwards DNS traffic logs to Datadog. |
"id": 8262886595283344, | ||
"definition": { | ||
"type": "note", | ||
"content": "DNSFilter is a cloud-based content filtering and threat protection by blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience.\n\nThis dashboard provides a comprehensive summary of DNSFilter Traffic logs.\n\nFor more information, see the [DNSFilter Integration Documentation](https://docs.datadoghq.com/integrations/dnsfilter/).\n\n**Tips**\n- Use the timeframe selector in the top right of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify and add widgets and visualizations. ", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"content": "DNSFilter is a cloud-based content filtering and threat protection by blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience.\n\nThis dashboard provides a comprehensive summary of DNSFilter Traffic logs.\n\nFor more information, see the [DNSFilter Integration Documentation](https://docs.datadoghq.com/integrations/dnsfilter/).\n\n**Tips**\n- Use the timeframe selector in the top right of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify and add widgets and visualizations. ", | |
"content": "DNSFilter is a cloud-based content filtering tool that blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience.\n\nThis dashboard provides a comprehensive summary of DNSFilter Traffic logs.\n\nFor more information, see the [DNSFilter Integration Documentation](https://docs.datadoghq.com/integrations/dnsfilter/).\n\n**Tips**\n- Use the timeframe selector in the top right of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify and add widgets and visualizations. ", |
"id": 3572596914767264, | ||
"definition": { | ||
"type": "note", | ||
"content": "DNSFilter is a cloud-based content filtering and threat protection by blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience.\n\nThis dashboard displays information about allowed and blocked DNS requests, threats, domains accessed, policies, networks, and other DNS-related traffic data.\n\nFor more information, see the [DNSFilter Integration Documentation](https://docs.datadoghq.com/integrations/dnsfilter/).\n\n**Tips**\n- Use the timeframe selector in the top right of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify and add widgets and visualizations. ", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"content": "DNSFilter is a cloud-based content filtering and threat protection by blocking internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience.\n\nThis dashboard displays information about allowed and blocked DNS requests, threats, domains accessed, policies, networks, and other DNS-related traffic data.\n\nFor more information, see the [DNSFilter Integration Documentation](https://docs.datadoghq.com/integrations/dnsfilter/).\n\n**Tips**\n- Use the timeframe selector in the top right of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify and add widgets and visualizations. ", | |
"content": "DNSFilter is a cloud-based content filtering and threat protection tool that blocks internet threats at the DNS layer. It protects organizations by preventing access to malicious domains, phishing sites, and other cyber threats, ensuring a safer internet experience.\n\nThis dashboard displays information about allowed and blocked DNS requests, threats, domains accessed, policies, networks, and other DNS-related traffic data.\n\nFor more information, see the [DNSFilter Integration Documentation](https://docs.datadoghq.com/integrations/dnsfilter/).\n\n**Tips**\n- Use the timeframe selector in the top right of the dashboard to change the default timeframe.\n- Clone this dashboard to rearrange, modify and add widgets and visualizations. ", |
What does this PR do?
This is a initial release PR of DNSFilter integration including all the required assets.
Motivation
Review checklist (to be filled by reviewers)
qa/skip-qa
label if the PR doesn't need to be tested during QA.backport/<branch-name>
label to the PR and it will automatically open a backport PR once this one is merged