DatadogZara Boddula, Danielle Park5 min readintermediate
Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines
Summary
Datadog Observability Pipelines now ships pre‑built Microsoft Sentinel Packs that map logs from Palo Alto, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop into Sentinel’s CommonSecurityLog or Syslog tables. Packs handle field extraction, severity derivation, and device‑action mapping, letting you filter or drop low‑value events before ingest, validate mappings with Live Capture, and reduce per‑GB…
- Packs provide out‑of‑the‑box mappings for 5 major firewall/VPN vendors, converting vendor‑specific fields to Sentinel’s schema (e.g., DeviceAction, LogSeverity, SourceIP).
- Mapping occurs in the pipeline, so you can filter on normalized fields (e.g., only denied connections) before data hits Sentinel, cutting ingest costs.
- Live Capture lets you compare raw and transformed events in real time to verify mappings.
- ExtraHop pack can drop low‑risk detections, further reducing noise.
Security teams often spend weeks writing parsers for each firewall/VPN vendor to fit Sentinel’s tables. Pre‑built packs eliminate that effort, ensure consistent field names across sources, and let you control ingest volume at the source, which directly impacts Sentinel’s per‑GB pricing model.
5/10



