Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -816,7 +816,7 @@ plaid/assets/logs/ @DataDog/saa
/anomali_threatstream/ @DataDog/saas-integrations
/anomali_threatstream/*.md @DataDog/saas-integrations @DataDog/documentation
/anomali_threatstream/manifest.json @DataDog/saas-integrations @DataDog/documentation
/anomali_threatstream/assets/logs/ @DataDog/saas-integrations @DataDog/documentation @DataDog/logs-integrations-reviewers


/palo_alto_networks_cortex_xsoar/ @DataDog/saas-integrations
/palo_alto_networks_cortex_xsoar/*.md @DataDog/saas-integrations @DataDog/documentation
Expand Down
52 changes: 27 additions & 25 deletions anomali_threatstream/README.md
Original file line number Diff line number Diff line change
@@ -1,39 +1,41 @@
# Agent Check: Anomali ThreatStream

## Overview

This check monitors [Anomali ThreatStream][1].

## Setup

### Installation
[Anomali ThreatStream][1] is a threat intelligence platform (TIP) that automates the collection, curation, and analysis of threat data from global, open-source, and premium feeds.

The Anomali ThreatStream check is included in the [Datadog Agent][2] package.
No additional installation is needed on your server.
This integration collects the following indicator types:

### Configuration
- IPv4
- Domain
- SHA256

!!! Add list of steps to set up this integration !!!
Integrate Anomali ThreatStream with Datadog to enhance your security logs with threat intelligence, enabling analysis of matched Indicators of Compromise (IOCs) through pre-built dashboards. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.

### Validation

!!! Add steps to validate integration is functioning as expected !!!

## Data Collected
## Setup

### Metrics
### Obtaining Anomali ThreatStream API credentials and domain

Anomali ThreatStream does not include any metrics.
1. Log in to the Anomali ThreatStream instance.
2. Navigate to **Settings** > **My profile**.
3. Under **Account Information**, click **Reveal** next to the **API Key** and copy it. Also, copy your **Email**.
4. Identify your Anomali ThreatStream Domain using the URL of your Anomali ThreatStream instance.
- For example, if your Anomali ThreatStream instance URL is `https://ui.threatstream.com/`, then your Anomali ThreatStream domain is `ui.threatstream.com`.

### Events
### Connect your Anomali ThreatStream account to Datadog

Anomali ThreatStream does not include any events.
1. Provide the following details:
| Parameter | Description |
| ---------- | ---------------------------------------------- |
| Domain | Your Anomali ThreatStream domain. |
| Email | Email address associated with your ThreatStream account. |
| API Key | API key of your Anomali ThreatStream account. |
| Collect IPv4 IOCs | Enable to collect IPv4 IOCs. The default value is `true`. |
| Collect Domain IOCs | Enable to collect Domain IOCs. The default value is `true`. |
| Collect SHA256 IOCs | Enable to collect SHA256 IOCs. The default value is `true`. |
2. Click **Save**.

## Troubleshooting

Need help? Contact [Datadog support][3].

[1]: **LINK_TO_INTEGRATION_SITE**
[2]: https://app.datadoghq.com/account/settings/agent/latest
[3]: https://docs.datadoghq.com/help/
Need help? Contact [Datadog support][2].

[1]: https://www.anomali.com/products/threatstream
[2]: https://docs.datadoghq.com/help/
18 changes: 18 additions & 0 deletions anomali_threatstream/assets/anomali_threatstream.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Loading