Try it free

Security integrations

  • Latest Dynatrace
  • Overview

Dynatrace provides different ways to integrate external security data from multiple third-party products into Grail and operationalize your data on the Dynatrace platform.

For a better understanding of the integration types, see OpenPipeline integration types for security events.

Threat intelligence

Bring in threat feeds, indicators of compromise (IOCs), and reputation data. Ingested threat reports map to the Threat intelligence semantic dictionary.

Ingest

  • Ingest LevelBlue (AlienVault) OTX threat reports

  • Ingest CrowdStrike detection findings, threat reports, and audit logs

  • Ingest Recorded Future threat reports

  • Ingest STIX/TAXII threat reports

Enrich

Add external threat‑intelligence context to observables using Security Enrichment Security Enrichment. You can connect HTTP‑based threat‑intelligence sources—such as AbuseIPDB, VirusTotal, or any custom API—and enrich observables like IP addresses with reputation, geolocation, or vendor‑specific metadata.

  • Enrich threat observables with Security Enrichment

  • Create custom enrichment connections

  • Enrich threat observables with AbuseIPDB

  • Enrich threat observables with VirusTotal

After configuring enrichment connections in Security Enrichment Security Enrichment, you can apply enrichment to:

  • Validate observables in Investigations Investigations
  • Enhance detection findings in Threats & Exploits Threats & Exploits
  • Use enrichment actions in Workflows Workflows

Code & build artifact scanners

Integrate SAST tools, SCA scanners, container registries, and artifact repositories. Findings map to the Vulnerabilities semantic dictionary.

  • Ingest Amazon ECR container vulnerability findings and scan events

  • Ingest Black Duck security findings and scan events

  • Ingest Checkmarx security findings, scan events, and audit logs

  • Ingest Docker Scout vulnerability findings and scan events

  • Ingest GitHub Advanced Security security events and audit logs

  • Ingest GitLab security findings and audit logs

  • Ingest Google Artifact Registry vulnerability findings

  • Ingest Harbor vulnerability findings, scans, and audit logs

  • Ingest JFrog security findings and audit logs

  • Ingest Mend Renovate vulnerability findings and scans

  • Ingest Snyk vulnerability findings, scans, and audit logs

  • Ingest SonarQube security and quality events, metrics, and audit logs

  • Ingest Sonatype Lifecycle security events and audit logs

Security posture

Integrate CSPM, vulnerability management, and compliance tools. Findings map to the Vulnerabilities and Compliance semantic dictionaries.

  • Ingest AWS Security Hub security findings

  • Ingest Kyverno compliance findings

  • Ingest Microsoft Defender for Cloud security events

  • Ingest Qualys vulnerability findings, scan events, and audit logs

  • Ingest Runecast Analyzer compliance findings

  • Ingest Tenable vulnerability findings, scan events, and audit logs

  • Ingest Wiz cloud configuration findings and audit logs

Alerts & detections

Integrate runtime detection and threat-alerting tools. Events map to the Detections semantic dictionary.

  • Ingest Amazon GuardDuty security findings

  • Ingest CrowdStrike detection findings, threat reports, and audit logs

  • Ingest Microsoft Sentinel security events

Generic

Ingest security events in standard or custom formats when no vendor-specific integration is available. Events map to the Security events semantic dictionary.

  • Ingest custom security events via API

  • Ingest vulnerability findings in OCSF format

Security logs

Security product audit logs

Most security tool integrations also ingest audit logs alongside their primary findings data—including Checkmarx, CrowdStrike, GitHub Advanced Security, GitLab, JFrog, Qualys, Snyk, SonarQube, Sonatype, and Tenable. These audit logs capture user activity within each security product, enabling you to correlate activity with security events. Each integration is listed in its primary category above.

Dedicated log integrations

The following integrations are designed specifically to bring in security-relevant log data. Logs map to the Log management and analytics semantic dictionary.

  • Ingest Akamai security logs and events

  • Amazon API Gateway monitoring

  • Amazon VPC NAT Gateways monitoring

  • AWS WAF monitoring

  • Azure Logs

  • CyberArk extension

  • Ingest Microsoft Entra ID sign-in logs

  • Okta extension

Related tags
Threat Observability