Use Datadog Security with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Manage cloud security via Datadog. search security signals, triage alerts, and audit detection rules directly from any AI agent.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 10 capabilities
The complete Datadog Security capability set.
These are the exact actions your AI can choose when you ask it to work with Datadog Security.
01-04
4 capabilities in this set.
Part of 10 available through Datadog Security.
- 01
Get detection rule
G. > 5 occurrences in 5 mins), severity bindings, tagging matrices, and Notification routing hooks tying into PagerDuty or Slack. Retrieve the exact logic/queries for a specific Detection Rule
- 02
List detection rules
Verifies the existence of proactive detections identifying AWS CloudTrail deviations, GCP anomalous IAM usage, and Kubernetes root escalations. List configured Datadog Security Detection Rules
- 03
List security filters
These filters inherently block high-volume, low-value logging vectors from ever reaching the SIEM evaluation engine in order to preserve compute budgets. List Security Filter configurations
- 04
Security system ping
Test API authentication validity against the Security Module
05-07
3 capabilities in this set.
Part of 10 available through Datadog Security.
- 05
Create detection rule
Accepts raw name/message fields, specific Lucene query bindings filtering for malicious activity, and severity levels (info, low, medium, high, critical). Auto-activates upon creation. Construct a new Cloud SIEM Log Detection Rule
- 06
Delete detection rule
Irreversible action. Pre-packaged rules provided by Datadog typically cannot be outright deleted (only disabled), making this primarily for user-created custom JSON rules. Permanently delete a Datadog Security Detection Rule
- 07
Get raw log context
Use this immediately after verifying an attacker footprint. Additional threat hunt capability extracting exact log bounds (100 msgs)
08-10
3 capabilities in this set.
Part of 10 available through Datadog Security.
- 08
Triage signal
Transition signals directly from "open" to "archived", or from "archived" back to "open". If archiving, an official reason (e.g. "false_positive" or "testing_or_maintenance") must be assigned. Modify the state of a Datadog SIEM Security Signal
- 09
Search raw logs
Essential for rapid Threat Hunting before detection rules alert. Useful for extracting contextual VPC Flow Logs or application stack traces related to an active breach. Directly query raw Datadog Logs over the past 15/m for Threat Hunting
- 10
Search signals
Use lucene-based queries like "status:critical OR @usr.id:admin" to filter high severity indicators mapping to MITRE ATT&CK vectors. Search Cloud SIEM Security Signals (Alerts) over the last 24h
Observed, not estimated
877ms average. Fast in production.
Datadog Security is checked daily against the live service.
- Fastest day
- 697ms
- Slowest day
- 1121ms
- 14-day trend
- Slowing+24%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 10 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Datadog Security, so you can see the experience inside your AI.
It does not authenticate your account with Datadog Security. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
Datadog Security Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — Datadog Security capabilities are ready to use.
{
"mcpServers": {
"datadog-cloud-siem-mcp": {
"url": "https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions Datadog Security owners ask.
- 01
Can my agent help me triage security alerts in Datadog?
Yes. Use the 'triage_signal' capability. You can update active threats from 'open' to 'archived', providing a required justification like 'false_positive'. The agent will push the status update directly to the Datadog SIEM platform.
- 02
How do I search for malicious activities matching specific IP addresses?
Use the 'get_raw_log_context' capability. Provide the suspicious IP address, and the agent will perform a threat-hunting search with a 10s lookbehind to capture highly localized context matching that source, helping you verify attacker footprints.
- 03
Can I see all active security detection rules through the agent?
Absolutely. The 'list_detection_rules' capability returns all custom and prepackaged Datadog Cloud SIEM rules. Your agent can then inspect specific rule schemas to verify evaluation windows, trigger cases, and notification hooks.
Explore
More in Fort Knox
Lacework (Cloud Security & CNAPP) AI Connector
Secure your cloud via Lacework — search security alerts, monitor vulnerabilities, and audit cloud asset invent
ViewSalt Security AI Connector
Integrate Salt Security directly with your AI for comprehensive API threat vector discovery, posture managemen
ViewWazuh (SIEM) AI Connector
Manage your Wazuh SIEM infrastructure—monitor agents, inspect security events, and manage manager configuratio
ViewAikido Security AI Connector
Query security vulnerabilities via Aikido — list open issues, check repositories, monitor cloud assets, and tr
View
Suggestions
Prisma Cloud AI Connector
Connect Prisma Cloud to any AI agent via MCP.
ViewLevo.ai (API Security & Observability) AI Connector
Secure your APIs via Levo.ai — audit endpoints, monitor sensitive data (PII/PHI), and manage OWASP vulnerabili
ViewDrata AI Connector
Automate compliance and security via Drata — monitor controls, track personnel onboarding, audit policies, and
ViewVanta AI Connector
Manage your automated compliance and security posture. Audit users, devices, vendors, and vulnerabilities dire
View
