Configure Datadog for Arctic Wolf monitoring
You can configure to send the necessary logs to Arctic Wolf® for security monitoring.
Complete these steps to configure a custom destination to send logs to Arctic Wolf using the Arctic Wolf webhook API.
These resources are required:
To complete this configuration, your Datadog user account must have the Admin role or a custom role with the permissions listed below.
|
Data type |
Permission |
Subscription |
|---|---|---|
| Audit Trail (Required) | audit_logs_write |
Audit Trail is a paid feature that may require specific subscription entitlements. |
| Application Security (Optional) | apm_pipelines_write |
Requires an active subscription to App and API Protection (AAP). |
| Security Signals (Optional) | security_monitoring_signals_write |
Requires an active subscription to Cloud SIEM or other security products, such as App and API Protection or Workload Protection, that generate detection rules. |
| Workload Protection Agent (Optional) | security_monitoring_cws_agent_rules_write |
Requires an active subscription to Workload Protection. |
Get the webhook token and URL
Configure a custom destination in Datadog
Repeat these steps for each data type that you want to forward. Event Forwarding supports one data type per destination configuration.
- Sign in to https://app.datadoghq.com/.
- Go to .
- Click New Destination.
- On the Configuration tab, under Define data to forward, select the data type that you want to forward:
- Audit Trail
- Application Security
- Security Signals
- Workload Protection Agent
- In the Filter field, enter * to forward all events for the selected data type, or replace it with a filter query that matches the specific events that you want to send.
- Under Choose a destination type, select HTTP.
- Under Name the destination, enter a descriptive name for the destination.
- Under Configure the destination, enter the webhook URL that you saved in Get the webhook token and URL, and select the Enable Gzip compression for payloads checkbox.
- Under Configure authentication settings, select Request Header as the authentication type.
- Enter Authorization as the header name.
- Enter Bearer token as the header value, replacing token with the token that you saved in Get the webhook token and URL.
- Under Select tags to forward, select All Tags.
- Click Save.