Dynatrace provides different ways to integrate external security data from multiple third-party products into Grail and operationalize your data on the Dynatrace platform.
For a better understanding of the integration types, see OpenPipeline integration types for security events.
Bring in threat feeds, indicators of compromise (IOCs), and reputation data. Ingested threat reports map to the Threat intelligence semantic dictionary.
Add external threat‑intelligence context to observables using
Security Enrichment. You can connect HTTP‑based threat‑intelligence sources—such as AbuseIPDB, VirusTotal, or any custom API—and enrich observables like IP addresses with reputation, geolocation, or vendor‑specific metadata.
After configuring enrichment connections in
Security Enrichment, you can apply enrichment to:
Investigations
Threats & Exploits
WorkflowsIntegrate SAST tools, SCA scanners, container registries, and artifact repositories. Findings map to the Vulnerabilities semantic dictionary.
Integrate CSPM, vulnerability management, and compliance tools. Findings map to the Vulnerabilities and Compliance semantic dictionaries.
Integrate runtime detection and threat-alerting tools. Events map to the Detections semantic dictionary.
Ingest security events in standard or custom formats when no vendor-specific integration is available. Events map to the Security events semantic dictionary.
Most security tool integrations also ingest audit logs alongside their primary findings data—including Checkmarx, CrowdStrike, GitHub Advanced Security, GitLab, JFrog, Qualys, Snyk, SonarQube, Sonatype, and Tenable. These audit logs capture user activity within each security product, enabling you to correlate activity with security events. Each integration is listed in its primary category above.
The following integrations are designed specifically to bring in security-relevant log data. Logs map to the Log management and analytics semantic dictionary.