Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add AppOmni integration (ECOINT-58) #2587

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions appomni_appomni/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# CHANGELOG - appomni

## 1.0.0 / 2025-01-23

_**Added**_:

* Initial Release
51 changes: 51 additions & 0 deletions appomni_appomni/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# AppOmni

## Overview

AppOmni Threat Detection Datadog Integration provides a single source to ingests and normalizes all your SaaS logs, and visualize events and alerts.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
AppOmni Threat Detection Datadog Integration provides a single source to ingests and normalizes all your SaaS logs, and visualize events and alerts.
AppOmni Threat Detection Integration with Datadog provides a single source to ingest and normalize all your SaaS logs. You can visualize any events and alerts.

Add more context about the events and alerts


## Setup

**Log in to Datadog**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
**Log in to Datadog**
### Create a Datadog API key

First Obtain a Datadog [API Key][1]. See the steps below:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
First Obtain a Datadog [API Key][1]. See the steps below:
Create a Datadog [API Key][1]. See the steps below:


Within Datadog navigate to **Organization settings** then click **API Keys**.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Within Datadog navigate to **Organization settings** then click **API Keys**.
Within Datadog, navigate to **Organization settings**, then click **API Keys**.

1. Click New Key
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
1. Click New Key
1. Click **New Key**.

2. Provide a name for the API key
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
2. Provide a name for the API key
2. Provide a name for the API key.

3. Click copy API key, and save this key for later.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
3. Click copy API key, and save this key for later.
3. Click **Copy API key**, and save this key for later.


**Create a Datadog AppOmni Destination**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
**Create a Datadog AppOmni Destination**
### Create a Datadog AppOmni Destination

**Log in to AppOmni**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
**Log in to AppOmni**
**Log in to AppOmni**

I recommend just making this the first step in the list below.

1. Navigate to **Threat Detection** and select **Destinations**.
2. Click **Add New Destination**.
3. Click the **Datadog Logs** card.
4. Enter a **Name** and **Description** (optional).
5. Ensure the following settings are checked:

- **SSL Verification**
- Select **Hash Original Field** to replace the original event field from the monitored service with a SHA256 hash of that event, thereby reducing event size.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Select **Hash Original Field** to replace the original event field from the monitored service with a SHA256 hash of that event, thereby reducing event size.
- Select **Hash Original Field** to replace the original event field from the monitored service with a SHA256 hash of that event, which reduces event size.

- Check **Gzip Compress Payloads** to reduce data size.

6. Enter your **Datadog API Key**.
7. Select your **Datadog site**. Identify which site you are on using [this table][2].
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
7. Select your **Datadog site**. Identify which site you are on using [this table][2].
7. Select your **Datadog site**. Identify which site you are on using [the sites table][2].

8. Click **Save**.

## Uninstallation

**Log in to Datadog**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This line can be deleted.

Within Datadog navigate to **Organization settings** then click **API Keys**.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Within Datadog navigate to **Organization settings** then click **API Keys**.
Within Datadog, navigate to **Organization settings**, then click **API Keys**.

It seems as though this should be a numbered step?

1. Click Revoke Key for the API key you want to remove.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
1. Click Revoke Key for the API key you want to remove.
1. Click **Revoke Key** for the API key you want to remove.


**Log in to AppOmni**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
**Log in to AppOmni**
**Log in to AppOmni**

This line can be deleted, and the first step can just start with "In AppOmni,". I recommend labeling the set of steps with a subheader that describes the high-level action being taken.

1. Navigate to **Threat Detection** and select **Destinations**.
2. Locate the **Datadog** destination and click on it.
3. Click the **Configuration**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
3. Click the **Configuration**
3. Click **Configuration**.

4. Click **Delete**
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
4. Click **Delete**
4. Click **Delete**.


## Support

Support can be reached by e-mail: [email protected]
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Support can be reached by e-mail: [email protected]
Contact [[email protected]](mailto:[email protected]) for support requests.



[1]: https://docs.datadoghq.com/account_management/api-app-keys/
[2]: https://docs.datadoghq.com/getting_started/site/
Loading
Loading