Datadog Security Connector for AI agents.
10 live capabilities
Manage cloud security signals and hunt threats in Datadog.
Waiting for input…
Why people use Datadog Security
Datadog Cloud SIEM Security Signal Triage
This Connector puts the power of the Datadog Security Module into your AI client. You can ask your agent to find all critical signals from the last 24 hours and then triage them right there in the chat. You get a unified workflow where searching, hunting, and updating alerts happen in one place.
What Vinkius changes
You get a conversational interface for your entire Datadog security stack.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Triage a false positive alert
An analyst identifies a 'Brute Force' alert as a known test and uses `triage_signal` to archive it with the reason 'testing_or_maintenance'.
- Real-world use case 02
Hunt for a malicious IP
An incident responder asks the agent to search logs for a specific IP and then uses `get_raw_log_context` to see the last 100 events.
- Real-world use case 03
Deploy a new AWS detection rule
A security engineer describes a new CloudTrail deviation and uses `create_detection_rule` to push the Lucene query and severity levels.
Complete set · 10capabilities
The complete Datadog Security capability set.
These are the exact actions your AI can choose when you ask it to work with Datadog Security.
01—04
4 capabilities in this set.
Part of 10 available through Datadog Security.
- 01 Capability
Create detection rule
Create a new Cloud SIEM Log Detection Rule with Lucene queries and severity levels. It auto-activates upon creation.
- 02 Capability
Security system ping
Check if your API authentication with the Security Module is working correctly. Use this to verify your connection.
- 03 Capability
Delete detection rule
Permanently delete a custom JSON rule you created in Datadog. This does not work for pre-packaged Datadog rules.
- 04 Capability
Get raw log context
Extract the last 100 messages from a specific log bound. Use this to get deep context after finding an attacker.
05—07
3 capabilities in this set.
Part of 10 available through Datadog Security.
- 05 Capability
Get detection rule
Retrieve the exact logic, severity, and notification hooks for a specific rule. See how your alerts are routed.
- 06 Capability
List security filters
List the global exclusion policies that block logs from reaching the SIEM. Use this to audit your compute budgets.
- 07 Capability
List detection rules
List all active rules identifying AWS, GCP, and Kubernetes deviations. Verify your proactive detections instantly.
08—10
3 capabilities in this set.
Part of 10 available through Datadog Security.
- 08 Capability
Search raw logs
Query raw Datadog logs over the last 15 minutes. This is essential for rapid threat hunting and finding VPC flow logs.
- 09 Capability
Search signals
Filter high-severity indicators over the last 24 hours using Lucene queries. Find threats mapping to MITRE ATT&CK.
- 10 Capability
Triage signal
Change the state of a signal to open or archived. You must provide a reason like false_positive when archiving.
Set up in minutes
One URL. Then ask Datadog Security to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Datadog Security from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it Datadog Security, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable Datadog Security for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the Datadog Security URL.
- Step 03
Save and start
Save the connection and enable Datadog Security in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"datadog-cloud-siem": {
"url": "https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using Datadog Security
Open Agent mode in chat and ask: "Using Datadog Security, help me...". 10 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"datadog-cloud-siem": {
"url": "https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using Datadog Security
Ask Copilot: "Using Datadog Security, help me...". 10 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"datadog-cloud-siem": {
"url": "https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using Datadog Security
Open Cascade and ask: "Using Datadog Security, help me...". 10 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"datadog-cloud-siem": {
"url": "https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using Datadog Security
Ask Cline: "Using Datadog Security, help me...". 10 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add datadog-cloud-siem --transport http "https://edge.vinkius.com/vk_preview_ovIPwgyUhVJJzxEVUJaVUxAH4E83Ffjb7HsAdaJt/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using Datadog Security
Ask Claude: "Using Datadog Security, show me...". 10 tools are ready
Where the request belongs
Work Datadog Security can move forward.
This is for security professionals who are tired of manual dashboard navigation. It's built for the SOC analyst who needs to triage alerts quickly and the engineer who needs to deploy rules without wrestling with complex UI menus.
Security Analyst
Triages high-volume alerts and archives false positives during a busy shift.
Incident Responder
Hunts for malicious IPs in raw logs during an active breach to gather context.
Security Engineer
Deploys and updates detection rules for AWS and Kubernetes using natural language.
Compliance Officer
Audits security filters and detection rules to ensure environment-wide consistency.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsElastic Security
Manage SIEM and SOC operations via Elastic Security. monitor detection rules, search security alerts (Signals), handle whitelisting, and audit threat coverage directly from any AI agent.
Tenable
Manage Tenable Vulnerability Management scans, inspect cloud assets, and triage CVEs natively via your AI agent.
Wazuh (SIEM)
Manage your Wazuh SIEM infrastructure—monitor agents, inspect security events, and manage manager configurations directly from your AI agent.
Lacework (Cloud Security & CNAPP)
Secure your cloud via Lacework. search security alerts, monitor vulnerabilities, and audit cloud asset inventory.
Senar.io
Detect and respond to security threats with AI-powered SIEM that correlates events across your infrastructure in real time.
Salt Security
Integrate Salt Security directly with your AI for comprehensive API threat vector discovery, posture management, and active remediation in real-time.
Bring your own AI
Change the model, client or framework. Keep Datadog Security connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about Datadog Security.
The practical details behind the request, access and result.
Can I use Datadog Cloud SIEM to find malicious IPs?
Yes, you can use this Connector to query raw logs for specific IP addresses to see exactly what they did in your environment during a hunt.
How do I triage alerts with Datadog Cloud SIEM?
You just tell your agent which signal to archive or open, and it updates the status in Datadog for you automatically.
Can this Connector help me manage AWS CloudTrail deviations?
Yes, it lets you list and retrieve the logic for rules that identify those specific deviations across your AWS environment.
Does Datadog Cloud SIEM support creating new rules?
You can create new Cloud SIEM Log Detection rules by describing the fields and queries you need in plain language.
Can I audit my security filters?
Use this Connector to list your global exclusion policies and see which log vectors are being blocked to preserve your compute budgets.
Is this Connector good for incident response?
It's built for it, allowing you to hunt raw logs and triage signals quickly during an active breach without leaving your chat client.
Can my agent help me triage security alerts in Datadog?
Yes. Use the 'triage_signal' capability. You can update active threats from 'open' to 'archived', providing a required justification like 'false_positive'. The agent will push the status update directly to the Datadog SIEM platform.
How do I search for malicious activities matching specific IP addresses?
Use the 'get_raw_log_context' capability. Provide the suspicious IP address, and the agent will perform a threat-hunting search with a 10s lookbehind to capture highly localized context matching that source, helping you verify attacker footprints.
Can I see all active security detection rules through the agent?
Absolutely. The 'list_detection_rules' capability returns all custom and prepackaged Datadog Cloud SIEM rules. Your agent can then inspect specific rule schemas to verify evaluation windows, trigger cases, and notification hooks.
One connection away
Give your agent a direct line to Datadog Security.
Connect Datadog Security once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available