From 4d0e581afb7fa42bde4dabdbb12da17d26310f3d Mon Sep 17 00:00:00 2001 From: bhargav-cyberhaven <327847505+bhargav-cyberhaven@users.noreply.github.com> Date: Tue, 29 Sep 2026 17:05:21 +0530 Subject: [PATCH] adding initial folder structure for cyberhaven datadog integration --- cyberhaven/CHANGELOG.md | 7 ++ cyberhaven/README.md | 113 ++++++++++++++++++ cyberhaven/assets/dataflows.yaml | 6 + .../assets/logos/cyberhaven_dark_mode.svg | 1 + .../assets/logos/cyberhaven_light_mode.svg | 1 + cyberhaven/assets/service_checks.json | 1 + cyberhaven/manifest.json | 49 ++++++++ 7 files changed, 178 insertions(+) create mode 100644 cyberhaven/CHANGELOG.md create mode 100644 cyberhaven/README.md create mode 100644 cyberhaven/assets/dataflows.yaml create mode 100644 cyberhaven/assets/logos/cyberhaven_dark_mode.svg create mode 100644 cyberhaven/assets/logos/cyberhaven_light_mode.svg create mode 100644 cyberhaven/assets/service_checks.json create mode 100644 cyberhaven/manifest.json diff --git a/cyberhaven/CHANGELOG.md b/cyberhaven/CHANGELOG.md new file mode 100644 index 0000000000..8d908c536c --- /dev/null +++ b/cyberhaven/CHANGELOG.md @@ -0,0 +1,7 @@ +# CHANGELOG - cyberhaven + +## 1.0.0 / 2026-10-12 + +***Added***: + +* Initial Release diff --git a/cyberhaven/README.md b/cyberhaven/README.md new file mode 100644 index 0000000000..9634717dd5 --- /dev/null +++ b/cyberhaven/README.md @@ -0,0 +1,113 @@ +## Overview + +Cyberhaven is a Data Detection and Response (DDR) platform that tracks data lineage across endpoints, browsers, and cloud apps, distinguishing genuinely risky data movement from routine activity rather than relying on static content-matching alone. It combines policy-based detection with an AI risk-scoring layer (Linea AI) that assigns a blended risk score per incident and can independently flag severity (`ai_severity`), helping SOC and insider-risk teams triage the highest-risk activity first. + +Coverage spans endpoint, browser, and cloud sensors, and extends to physical/offline vectors (removable storage, printers) and collaboration surfaces (email, IM, cloud share, source-code repositories). Every admin and user action inside the Cyberhaven console itself (logins, searches, policy/incident/role/API-key changes) is separately captured as an Audit Log, giving a "who changed what" trail independent of the DLP detection stream. + +This integration streams Cyberhaven **Audit Logs**, **Incidents**, and **Events** to Datadog, and includes: + +- **Data Streaming**: Cyberhaven forwards each log type to Datadog through a dedicated Streaming Destination (Audit Logs, Incidents, Events). +- **Log Processing**: A Datadog Log Pipeline parses, normalizes, and enriches Cyberhaven data for downstream analysis. +- **Dashboards**: Out-of-the-box dashboards for visualizing parsed and enriched Cyberhaven data. +- **Monitors**: Out-of-the-box monitors to help identify and alert on relevant activities and conditions. + + +## Setup + +### Prerequisites + +| Prerequisite | Detail | +|---|---| +| Datadog account | Cloud SIEM enabled; permission to create API keys | +| Cyberhaven admin access | Permission to create and configure streaming destinations | +| Datadog API key | Required. Create one following the steps below | + +### Configuration + +#### Generate a Datadog API key + +1. Log in to your Datadog instance. +2. Click your user avatar in the bottom-left corner and select **Organization Settings**. +3. In the left sidebar, under **Access**, click **API Keys**. +4. Click **New Key**, give it a name (for example, `forwarding-to-cyberhaven`), and click **Create Key**. +5. Copy the generated key and store it safely. + +#### Locate your Datadog site + +1. Log in to your Datadog instance. +2. Click your user avatar in the bottom-left corner and select **My Preferences**. +3. Note your Datadog site in the top-right corner (for example, `datadoghq.com`). + +#### Locate your Cyberhaven instance URL + +1. While logged in to your organization's Cyberhaven Console, check your browser's address bar. +2. Note the host domain, which typically follows the pattern `.cyberhaven.io`. + +#### Forward logs from Cyberhaven to Datadog + +The Cyberhaven Datadog integration supports collection, parsing, and visualization for Audit Logs, Incidents, and Events. Based on your organization's needs, you can configure any single source independently, combine any two, or enable all three. + +For each log type, you create a **Destination** (where the logs are sent) and a **Configuration** (what gets sent and when) in the Cyberhaven Console under **Settings > Data Export**. + +**Configure Audit Logs** + +1. Under **Settings > Data Export**, click **Destinations > Add new**. +2. Name the destination (for example, `audit-logs-to-datadog-destination`). +3. Set **Type** to `HTTPS`. +4. Set **URI** to: + + ```text + https://http-intake.logs./api/v2/logs?ddsource=cyberhaven&ddtags=cyberhaven.domain:,cyberhaven.logtype:cyberhaven-audit + ``` + + Replace `` and `` with the values from the steps above. +5. Set **Format** to `JSON Array` and **Encoding** to `GZip`. +6. Under **HTTP Headers**, add a header named `DD-API-KEY` with your Datadog API key as the value. +7. Click **Save & Test**. +8. Under **Settings > Data Export**, click **Configurations > Add new**. +9. Name the configuration (for example, `audit-logs-to-datadog-configuration`). +10. Set **Destination** to the destination created above, **Source** to `Audit`, and **Schedule** to `Immediate`. +11. Ensure **Enabled** is checked, then click **Save**. + +**Configure Incident Logs** + +1. Repeat steps 1-7 above, naming the destination `incident-logs-to-datadog-destination` and using the logtype tag `cyberhaven.logtype:cyberhaven-incidents` in the URI. +2. Under **Settings > Data Export**, click **Configurations > Add new**. +3. Name the configuration (for example, `incident-logs-to-datadog-configuration`). +4. Set **Destination** to the destination created above, **Source** to `Incidents`, and **Schedule** to `Immediate`. +5. Set **Scope** to `Full Access`. +6. Check **Subscribe to new incidents**, **Subscribe to incident updates**, and **Include incident event details**. +7. Ensure **Enabled** is checked, then click **Save**. + +**Configure Event Logs** + +1. Repeat steps 1-7 above, naming the destination `events-logs-to-datadog-destination` and using the logtype tag `cyberhaven.logtype:cyberhaven-events` in the URI. +2. Under **Settings > Data Export**, click **Configurations > Add new**. +3. Name the configuration (for example, `events-logs-to-datadog-configuration`). +4. Set **Destination** to the destination created above, **Source** to `Events`, **Schedule** to `Immediate`, and **Scope** to `Full Access`. +5. Ensure **Enabled** is checked, then click **Save**. + +### Validation + +After saving each configuration, confirm logs are arriving by searching `source:cyberhaven` in the [Log Explorer][1]. + +## Data Collected + +### Logs + +The Cyberhaven integration collects Audit Logs, Incidents, and Events, tagged with `source:cyberhaven` and `cyberhaven.logtype:cyberhaven-audit` / `cyberhaven.logtype:cyberhaven-incidents` / `cyberhaven.logtype:cyberhaven-events`. + +### Metrics + +Cyberhaven does not include any metrics. + +### Events + +Cyberhaven does not include any events. + +## Troubleshooting + +Need help? Contact [Datadog support][2] or [Cyberhaven support](mailto:support@cyberhaven.com). + +[1]: https://docs.datadoghq.com/logs/explorer/ +[2]: https://docs.datadoghq.com/help/ diff --git a/cyberhaven/assets/dataflows.yaml b/cyberhaven/assets/dataflows.yaml new file mode 100644 index 0000000000..78c07afffa --- /dev/null +++ b/cyberhaven/assets/dataflows.yaml @@ -0,0 +1,6 @@ +provides: + - id: cyberhaven-logs + always_on: true + granular: false + data_type: logs + direction: inbound diff --git a/cyberhaven/assets/logos/cyberhaven_dark_mode.svg b/cyberhaven/assets/logos/cyberhaven_dark_mode.svg new file mode 100644 index 0000000000..6266237775 --- /dev/null +++ b/cyberhaven/assets/logos/cyberhaven_dark_mode.svg @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/cyberhaven/assets/logos/cyberhaven_light_mode.svg b/cyberhaven/assets/logos/cyberhaven_light_mode.svg new file mode 100644 index 0000000000..ca99978afa --- /dev/null +++ b/cyberhaven/assets/logos/cyberhaven_light_mode.svg @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/cyberhaven/assets/service_checks.json b/cyberhaven/assets/service_checks.json new file mode 100644 index 0000000000..fe51488c70 --- /dev/null +++ b/cyberhaven/assets/service_checks.json @@ -0,0 +1 @@ +[] diff --git a/cyberhaven/manifest.json b/cyberhaven/manifest.json new file mode 100644 index 0000000000..12201b4b90 --- /dev/null +++ b/cyberhaven/manifest.json @@ -0,0 +1,49 @@ +{ + "manifest_version": "2.0.0", + "app_uuid": "c3ff5bcd-f252-4c9a-a17b-b7e39a60ecd4", + "app_id": "cyberhaven", + "display_on_public_website": false, + "tile": { + "overview": "README.md#Overview", + "configuration": "README.md#Setup", + "support": "README.md#Support", + "changelog": "CHANGELOG.md", + "description": "Monitors Cyberhaven incident, events and audit logs.", + "title": "Cyberhaven", + "media": [], + "classifier_tags": [ + "Supported OS::Linux", + "Supported OS::Windows", + "Supported OS::macOS", + "Category::Cloud", + "Category::Incidents", + "Category::Log Collection", + "Category::Security", + "Category::SIEM", + "Offering::Integration", + "Submitted Data Type::Logs" + ] + }, + "assets": { + "integration": { + "auto_install": true, + "source_type_id": 90599096, + "source_type_name": "Cyberhaven", + "events": { + "creates_events": false + }, + "service_checks": { + "metadata_path": "assets/service_checks.json" + } + }, + "logs": { + "source": "cyberhaven" + } + }, + "author": { + "support_email": "support@cyberhaven.com", + "name": "Cyberhaven", + "homepage": "https://www.cyberhaven.com/" + } +} +