This article explains how to connect your Datadog device to Workbench.

In this article

Step 1: Create a service account and API credentials

You must have the System Administrator role on Datadog to add a service account.

Having read-only access to the interface of your technology allows Expel to dig deeper during incident investigations. Our device health team uses this access to investigate potential health issues with your tech.

Note

Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.

Caution

Think carefully about the data you enter. After you create a service account, you can't make changes. You have to delete it and start over.

  • Log in to the Datadog console.

  • Navigate to Organization Settings > API Keys.

  • Select + New Key.

  • Name the key, then click Create Key.

  • Copy and paste or write down the API key for later use.

  • Navigate to Organization Settings > Service Accounts.

  • Click + New Service Account.

  • Type the following details for the service account:

  • Click Create Service Account.

  • Select the created service account. A popup appears.

  • On the service account popup, click + New Key.

  • Copy+paste or write down the Application key for later use.

Step 2: Configure the technology in Workbench

Now that we have the correct access configured and noted the credentials, we can integrate your tech with Workbench.

  1. Log in to Workbench.
  2. In the side menu, navigate to Organization Settings > Security Devices.
  3. Select the Add Security Device button.
  4. In the search box, type “data” and then select the Datadog integration.
  5. Complete these fields using the credentials and information you collected in Step 1:
    • Name: the host name of the device.
    • Location: the geographic location of the appliance.
    • Datadog site: select your site.
    • API key: the API key generated in Step 1.
    • Application key: the Application key generated in Step 1.
  6. Click Save.
  7. You can provide console access now or set it up later. To set it up now, skip to Step 3. If not, choose the "No thanks" option and click Save.
  8. Your device is now connected. You can see if the device is healthy on the Security Devices page. It may take a few minutes to see the device listed as healthy.

To check if alerts are coming through, navigate to the Alerts Analysis page. Scroll to the device you want to check and click View alerts. Switch to grid view, then check the list for device alerts. It can take 36 to 72 hours for alerts to appear after setup, as we tune your device.

 

Step 3: Edit the device to add console access

Expel uses console access to your device to allow our SOC analysts to dig deeper during incident investigations. Additionally, our engineering teams use this access to investigate potential health issues, including proper alert ingestion.

Note

Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.

  1. Open Workbench. Go to Organization Settings > Security Devices. Next to the device you just connected, click the down arrow and click Edit.
  2. In the Console Login area, type these details:
    • Console URL: type the console URL from the Server address in the Connection Settings area above. At the end of the URL, type /login.
    • Username: type the user name you created above.
    • Password: type the password you created above.
    • Two-factor secret key (32-character code): depending on how your organization enforces log-ins, this field may not apply to you. In these cases, you can leave it blank. This field is optional and if you have questions or concerns, reach out to your engagement manager or to support.
  3. Click Save.