Configure Datadog for Arctic Wolf monitoring

You can configure to send the necessary logs to Arctic Wolf® for security monitoring.

Complete these steps to configure a custom destination to send logs to Arctic Wolf using the Arctic Wolf webhook API.

These resources are required:

To complete this configuration, your Datadog user account must have the Admin role or a custom role with the permissions listed below.

Data type

Permission

Subscription

Audit Trail (Required) audit_logs_write Audit Trail is a paid feature that may require specific subscription entitlements.
Application Security (Optional) apm_pipelines_write Requires an active subscription to App and API Protection (AAP).
Security Signals (Optional) security_monitoring_signals_write Requires an active subscription to Cloud SIEM or other security products, such as App and API Protection or Workload Protection, that generate detection rules.
Workload Protection Agent (Optional) security_monitoring_cws_agent_rules_write Requires an active subscription to Workload Protection.

Get the webhook token and URL

  1. Sign in to the Portail unifié Arctic Wolf.
  2. Dans le menu de navigation, cliquez sur Collecte de données > Capteurs cloud.
  3. Click Add Account +.
  4. On the Add Account page, click Datadog.
  5. In the Name field, enter a unique and descriptive name for the account.
  6. Click Get Credentials.
  7. Copy the token and webhook URL, and then save them in a safe, encrypted location.

    You will use these values to configure the custom destination in .

Configure a custom destination in Datadog

Repeat these steps for each data type that you want to forward. Event Forwarding supports one data type per destination configuration.

  1. Sign in to https://app.datadoghq.com/.
  2. Go to Security Settings > Event Forwarding.
  3. Click New Destination.
  4. On the Configuration tab, under Define data to forward, select the data type that you want to forward:
    • Audit Trail
    • Application Security
    • Security Signals
    • Workload Protection Agent
  5. In the Filter field, enter * to forward all events for the selected data type, or replace it with a filter query that matches the specific events that you want to send.
  6. Under Choose a destination type, select HTTP.
  7. Under Name the destination, enter a descriptive name for the destination.
  8. Under Configure the destination, enter the webhook URL that you saved in Get the webhook token and URL, and select the Enable Gzip compression for payloads checkbox.
  9. Under Configure authentication settings, select Request Header as the authentication type.
  10. Enter Authorization as the header name.
  11. Enter Bearer token as the header value, replacing token with the token that you saved in Get the webhook token and URL.
  12. Under Select tags to forward, select All Tags.
  13. Click Save.

Verify the Datadog configuration

  1. In , go to Security Settings > Event Forwarding.
  2. Confirm that the Status column for each custom destination that you created shows Active.

    The Status column can show one of these values:

    • Active — the destination is receiving and forwarding logs
    • Error — the destination is unable to forward logs; review the destination configuration
    • No Data — the destination has not received any logs yet
  3. Confirm that the Estimated Log Volume column shows a non-zero value once logs begin to flow.