SpyCloud’s integration with Datadog brings identity exposure alerts directly into your Datadog environment. When SpyCloud detects compromised employee identities – whether through phishing, malware infections, or third-party breaches – those alerts are sent as structured log events into Datadog. This enables your team to correlate SpyCloud alerts with other observability data and take faster, more informed action using the tools you already rely on.
BENEFITS
Consolidated visibility View SpyCloud identity exposure alerts alongside your infrastructure, application, and security telemetry.
Streamlined response Use Datadog monitors to trigger automated notifications via Slack, PagerDuty, email, and other channels.
Operational efficiency Leverage existing workflows without introducing new tools or relying on a SIEM.
HOW IT WORKS
SpyCloud continuously monitors for exposed employee identities. When exposures are detected, alert data is sent to Datadog as structured log events, including identity details and risk severity. Datadog monitors can then be configured to trigger alerts or workflows based on your team’s response criteria.
Integration setup includes:
Generating SpyCloud and Datadog API keys with appropriate permissions.
Configuring a Datadog HTTP log intake to receive SpyCloud alerts.
Creating or importing monitors and dashboards to track and act on SpyCloud events.
NEW RESEARCH: Over 2/3 of orgs had an identity event last year – NHIs were the top cause. Read on→