Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions cyberhaven/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# CHANGELOG - cyberhaven

## 1.0.0 / 2026-10-12

***Added***:

* Initial Release
113 changes: 113 additions & 0 deletions cyberhaven/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,113 @@
## Overview

Cyberhaven is a Data Detection and Response (DDR) platform that tracks data lineage across endpoints, browsers, and cloud apps, distinguishing genuinely risky data movement from routine activity rather than relying on static content-matching alone. It combines policy-based detection with an AI risk-scoring layer (Linea AI) that assigns a blended risk score per incident and can independently flag severity (`ai_severity`), helping SOC and insider-risk teams triage the highest-risk activity first.

Coverage spans endpoint, browser, and cloud sensors, and extends to physical/offline vectors (removable storage, printers) and collaboration surfaces (email, IM, cloud share, source-code repositories). Every admin and user action inside the Cyberhaven console itself (logins, searches, policy/incident/role/API-key changes) is separately captured as an Audit Log, giving a "who changed what" trail independent of the DLP detection stream.

This integration streams Cyberhaven **Audit Logs**, **Incidents**, and **Events** to Datadog, and includes:

- **Data Streaming**: Cyberhaven forwards each log type to Datadog through a dedicated Streaming Destination (Audit Logs, Incidents, Events).
- **Log Processing**: A Datadog Log Pipeline parses, normalizes, and enriches Cyberhaven data for downstream analysis.
- **Dashboards**: Out-of-the-box dashboards for visualizing parsed and enriched Cyberhaven data.
- **Monitors**: Out-of-the-box monitors to help identify and alert on relevant activities and conditions.


## Setup

### Prerequisites

| Prerequisite | Detail |
|---|---|
| Datadog account | Cloud SIEM enabled; permission to create API keys |
| Cyberhaven admin access | Permission to create and configure streaming destinations |
| Datadog API key | Required. Create one following the steps below |

### Configuration

#### Generate a Datadog API key

1. Log in to your Datadog instance.
2. Click your user avatar in the bottom-left corner and select **Organization Settings**.
3. In the left sidebar, under **Access**, click **API Keys**.
4. Click **New Key**, give it a name (for example, `forwarding-to-cyberhaven`), and click **Create Key**.
5. Copy the generated key and store it safely.

#### Locate your Datadog site

1. Log in to your Datadog instance.
2. Click your user avatar in the bottom-left corner and select **My Preferences**.
3. Note your Datadog site in the top-right corner (for example, `datadoghq.com`).

#### Locate your Cyberhaven instance URL

1. While logged in to your organization's Cyberhaven Console, check your browser's address bar.
2. Note the host domain, which typically follows the pattern `<your-tenant-id>.cyberhaven.io`.

#### Forward logs from Cyberhaven to Datadog

The Cyberhaven Datadog integration supports collection, parsing, and visualization for Audit Logs, Incidents, and Events. Based on your organization's needs, you can configure any single source independently, combine any two, or enable all three.

For each log type, you create a **Destination** (where the logs are sent) and a **Configuration** (what gets sent and when) in the Cyberhaven Console under **Settings > Data Export**.

**Configure Audit Logs**

1. Under **Settings > Data Export**, click **Destinations > Add new**.
2. Name the destination (for example, `audit-logs-to-datadog-destination`).
3. Set **Type** to `HTTPS`.
4. Set **URI** to:

```text
https://http-intake.logs.<YOUR_DATADOG_SITE>/api/v2/logs?ddsource=cyberhaven&ddtags=cyberhaven.domain:<YOUR_CYBERHAVEN_INSTANCE_URL>,cyberhaven.logtype:cyberhaven-audit
```

Replace `<YOUR_DATADOG_SITE>` and `<YOUR_CYBERHAVEN_INSTANCE_URL>` with the values from the steps above.
5. Set **Format** to `JSON Array` and **Encoding** to `GZip`.
6. Under **HTTP Headers**, add a header named `DD-API-KEY` with your Datadog API key as the value.
7. Click **Save & Test**.
8. Under **Settings > Data Export**, click **Configurations > Add new**.
9. Name the configuration (for example, `audit-logs-to-datadog-configuration`).
10. Set **Destination** to the destination created above, **Source** to `Audit`, and **Schedule** to `Immediate`.
11. Ensure **Enabled** is checked, then click **Save**.

**Configure Incident Logs**

1. Repeat steps 1-7 above, naming the destination `incident-logs-to-datadog-destination` and using the logtype tag `cyberhaven.logtype:cyberhaven-incidents` in the URI.
2. Under **Settings > Data Export**, click **Configurations > Add new**.
3. Name the configuration (for example, `incident-logs-to-datadog-configuration`).
4. Set **Destination** to the destination created above, **Source** to `Incidents`, and **Schedule** to `Immediate`.
5. Set **Scope** to `Full Access`.
6. Check **Subscribe to new incidents**, **Subscribe to incident updates**, and **Include incident event details**.
7. Ensure **Enabled** is checked, then click **Save**.

**Configure Event Logs**

1. Repeat steps 1-7 above, naming the destination `events-logs-to-datadog-destination` and using the logtype tag `cyberhaven.logtype:cyberhaven-events` in the URI.
2. Under **Settings > Data Export**, click **Configurations > Add new**.
3. Name the configuration (for example, `events-logs-to-datadog-configuration`).
4. Set **Destination** to the destination created above, **Source** to `Events`, **Schedule** to `Immediate`, and **Scope** to `Full Access`.
5. Ensure **Enabled** is checked, then click **Save**.

### Validation

After saving each configuration, confirm logs are arriving by searching `source:cyberhaven` in the [Log Explorer][1].

## Data Collected

### Logs

The Cyberhaven integration collects Audit Logs, Incidents, and Events, tagged with `source:cyberhaven` and `cyberhaven.logtype:cyberhaven-audit` / `cyberhaven.logtype:cyberhaven-incidents` / `cyberhaven.logtype:cyberhaven-events`.

### Metrics

Cyberhaven does not include any metrics.

### Events

Cyberhaven does not include any events.

## Troubleshooting

Need help? Contact [Datadog support][2] or [Cyberhaven support](mailto:support@cyberhaven.com).

[1]: https://docs.datadoghq.com/logs/explorer/
[2]: https://docs.datadoghq.com/help/
6 changes: 6 additions & 0 deletions cyberhaven/assets/dataflows.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
provides:
- id: cyberhaven-logs
always_on: true
granular: false
data_type: logs
direction: inbound
1 change: 1 addition & 0 deletions cyberhaven/assets/logos/cyberhaven_dark_mode.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions cyberhaven/assets/logos/cyberhaven_light_mode.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions cyberhaven/assets/service_checks.json
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
[]
49 changes: 49 additions & 0 deletions cyberhaven/manifest.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
{

Check failure on line 1 in cyberhaven/manifest.json

View check run for this annotation

datadog-assets / validate-owner-validator

Error in owner-validator

Owner is a required internal-only field. Use a valid internal team handle. External contributors should leave this unset.
"manifest_version": "2.0.0",
"app_uuid": "c3ff5bcd-f252-4c9a-a17b-b7e39a60ecd4",
"app_id": "cyberhaven",
"display_on_public_website": false,
"tile": {
"overview": "README.md#Overview",
"configuration": "README.md#Setup",
"support": "README.md#Support",
"changelog": "CHANGELOG.md",
"description": "Monitors Cyberhaven incident, events and audit logs.",
"title": "Cyberhaven",
"media": [],
"classifier_tags": [
"Supported OS::Linux",
"Supported OS::Windows",
"Supported OS::macOS",
"Category::Cloud",
"Category::Incidents",
"Category::Log Collection",
"Category::Security",
"Category::SIEM",
"Offering::Integration",
"Submitted Data Type::Logs"
]
},
"assets": {
"integration": {
"auto_install": true,
"source_type_id": 90599096,
"source_type_name": "Cyberhaven",
"events": {
"creates_events": false
},
"service_checks": {
"metadata_path": "assets/service_checks.json"
}
},
"logs": {
"source": "cyberhaven"
}
},
"author": {
"support_email": "support@cyberhaven.com",
"name": "Cyberhaven",
"homepage": "https://www.cyberhaven.com/"
}
}