Skip to content
Vinkius

Datadog Security Connector for AI agents.

10 live capabilities

Manage cloud security signals and hunt threats in Datadog.

Live agent request Datadog Security / Connector

Waiting for input…

AI Agent

Why people use Datadog Security

Datadog Cloud SIEM Security Signal Triage

This Connector puts the power of the Datadog Security Module into your AI client. You can ask your agent to find all critical signals from the last 24 hours and then triage them right there in the chat. You get a unified workflow where searching, hunting, and updating alerts happen in one place.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • Visual Studio Code
  • Windsurf

What Vinkius changes

You get a conversational interface for your entire Datadog security stack.

Use it from Claude, ChatGPT, Cursor or another AI client you already have.

One account · 5,900+ Connectors

  1. Real-world use case 01

    Triage a false positive alert

    An analyst identifies a 'Brute Force' alert as a known test and uses `triage_signal` to archive it with the reason 'testing_or_maintenance'.

  2. Real-world use case 02

    Hunt for a malicious IP

    An incident responder asks the agent to search logs for a specific IP and then uses `get_raw_log_context` to see the last 100 events.

  3. Real-world use case 03

    Deploy a new AWS detection rule

    A security engineer describes a new CloudTrail deviation and uses `create_detection_rule` to push the Lucene query and severity levels.

Complete set · 10capabilities

The complete Datadog Security capability set.

These are the exact actions your AI can choose when you ask it to work with Datadog Security.

Capability set01 / 03

01—04

4 capabilities in this set.

Part of 10 available through Datadog Security.

  1. 01 Capability

    Create detection rule

    Create a new Cloud SIEM Log Detection Rule with Lucene queries and severity levels. It auto-activates upon creation.

  2. 02 Capability

    Security system ping

    Check if your API authentication with the Security Module is working correctly. Use this to verify your connection.

  3. 03 Capability

    Delete detection rule

    Permanently delete a custom JSON rule you created in Datadog. This does not work for pre-packaged Datadog rules.

  4. 04 Capability

    Get raw log context

    Extract the last 100 messages from a specific log bound. Use this to get deep context after finding an attacker.

Capability set02 / 03

05—07

3 capabilities in this set.

Part of 10 available through Datadog Security.

  1. 05 Capability

    Get detection rule

    Retrieve the exact logic, severity, and notification hooks for a specific rule. See how your alerts are routed.

  2. 06 Capability

    List security filters

    List the global exclusion policies that block logs from reaching the SIEM. Use this to audit your compute budgets.

  3. 07 Capability

    List detection rules

    List all active rules identifying AWS, GCP, and Kubernetes deviations. Verify your proactive detections instantly.

Capability set03 / 03

08—10

3 capabilities in this set.

Part of 10 available through Datadog Security.

  1. 08 Capability

    Search raw logs

    Query raw Datadog logs over the last 15 minutes. This is essential for rapid threat hunting and finding VPC flow logs.

  2. 09 Capability

    Search signals

    Filter high-severity indicators over the last 24 hours using Lucene queries. Find threats mapping to MITRE ATT&CK.

  3. 10 Capability

    Triage signal

    Change the state of a signal to open or archived. You must provide a reason like false_positive when archiving.

Set up in minutes

One URL. Then ask Datadog Security to work.

Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Datadog Security from the conversation.

Choose your client

Live preview
Advanced clients IDE · CLI

Claude · Web + desktop

Official guide ↗

Connector URL · ready to paste

Streamable HTTP
https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp
  1. Step 01

    Open Connectors

    In Claude Web or Claude Desktop, open Settings and choose Connectors.

  2. Step 02

    Add the URL

    Choose Add custom connector, name it Datadog Security, and paste the URL above.

  3. Step 03

    Turn it on in chat

    Select +, open Connectors, and enable Datadog Security for the conversation.

Where the request belongs

Work Datadog Security can move forward.

Built around the request

This is for security professionals who are tired of manual dashboard navigation. It's built for the SOC analyst who needs to triage alerts quickly and the engineer who needs to deploy rules without wrestling with complex UI menus.

01

Security Analyst

Triages high-volume alerts and archives false positives during a busy shift.

02

Incident Responder

Hunts for malicious IPs in raw logs during an active breach to gather context.

03

Security Engineer

Deploys and updates detection rules for AWS and Kubernetes using natural language.

04

Compliance Officer

Audits security filters and detection rules to ensure environment-wide consistency.

Bring your own AI

Change the model, client or framework. Keep Datadog Security connected.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • VS Code
  • Windsurf
  • ZCode
  • Cline
  • Zed
  • Continue
  • Kiro
  • Roo Code
  • Zencoder
  • Goose
  • Void
  • Augment Code
  • Amp
  • Qodo
  • Tabnine
  • Pieces
  • Sourcegraph Cody
  • JetBrains
  • Warp
  • Amazon Q
  • Antigravity
  • BoltAI
  • Raycast
  • Jan
  • LM Studio
  • AnythingLLM
  • Open WebUI
  • Msty
  • Cherry Studio
  • LibreChat
  • TypingMind
  • Chorus
  • 5ire
  • n8n
  • LangChain
  • LlamaIndex
  • CrewAI
  • Vercel AI SDK

Before you connect

Questions about Datadog Security.

The practical details behind the request, access and result.

Can I use Datadog Cloud SIEM to find malicious IPs?

Yes, you can use this Connector to query raw logs for specific IP addresses to see exactly what they did in your environment during a hunt.

How do I triage alerts with Datadog Cloud SIEM?

You just tell your agent which signal to archive or open, and it updates the status in Datadog for you automatically.

Can this Connector help me manage AWS CloudTrail deviations?

Yes, it lets you list and retrieve the logic for rules that identify those specific deviations across your AWS environment.

Does Datadog Cloud SIEM support creating new rules?

You can create new Cloud SIEM Log Detection rules by describing the fields and queries you need in plain language.

Can I audit my security filters?

Use this Connector to list your global exclusion policies and see which log vectors are being blocked to preserve your compute budgets.

Is this Connector good for incident response?

It's built for it, allowing you to hunt raw logs and triage signals quickly during an active breach without leaving your chat client.

Can my agent help me triage security alerts in Datadog?

Yes. Use the 'triage_signal' capability. You can update active threats from 'open' to 'archived', providing a required justification like 'false_positive'. The agent will push the status update directly to the Datadog SIEM platform.

How do I search for malicious activities matching specific IP addresses?

Use the 'get_raw_log_context' capability. Provide the suspicious IP address, and the agent will perform a threat-hunting search with a 10s lookbehind to capture highly localized context matching that source, helping you verify attacker footprints.

Can I see all active security detection rules through the agent?

Absolutely. The 'list_detection_rules' capability returns all custom and prepackaged Datadog Cloud SIEM rules. Your agent can then inspect specific rule schemas to verify evaluation windows, trigger cases, and notification hooks.

One connection away

Give your agent a direct line to Datadog Security.

Connect Datadog Security once. Keep it beside 5,900+ managed Connectors when the next task needs more.

Explore every Connector No credit card required · Free tier available