From 3c8afe2eb8761f55936a56e8d3ce795512cd9ad4 Mon Sep 17 00:00:00 2001 From: Jenny Park Date: Mon, 10 Aug 2026 21:35:04 -0400 Subject: [PATCH] Clarify Risk Insights supported log sources and OCSF requirement The Prerequisites section listed four supported log sources and did not mention that Risk Insights requires an active OCSF pipeline, so a reader could configure a supported source and still see no entities. - List the supported log sources, grouped by the entities each provides - State that an active OCSF pipeline is part of the requirement - Add guidance for when a supported source produces no entities Removes the AWS, Azure, and GCP config-guide link references, which are no longer used now that the source names are unlinked. Co-Authored-By: Claude --- .../triage_and_investigate/entities_and_risk_scoring.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/hugo/content/en/security/cloud_siem/triage_and_investigate/entities_and_risk_scoring.md b/hugo/content/en/security/cloud_siem/triage_and_investigate/entities_and_risk_scoring.md index 7b347eba866..1283a97be20 100644 --- a/hugo/content/en/security/cloud_siem/triage_and_investigate/entities_and_risk_scoring.md +++ b/hugo/content/en/security/cloud_siem/triage_and_investigate/entities_and_risk_scoring.md @@ -28,7 +28,10 @@ With Risk Insights, you can: ## Prerequisites -- For Risk Insights coverage, either GitHub, [Azure][6], [GCP][5], or [AWS][1] must be configured for Cloud SIEM. +- To use Risk Insights, configure at least one of the following supported log sources to send logs to Cloud SIEM, with an active Open Cybersecurity Schema Framework (OCSF) pipeline: + - **Sources that provide identity and resource entities** (such as users, service identities, assumed roles, compute instances, and storage containers): AWS, Azure, GCP, GitHub, Microsoft 365, and Okta. + - **Sources that provide user entities identified by email address**: 1Password, Cisco Duo, Cloudflare, CrowdStrike, Google Workspace, JumpCloud, LastPass, Salesforce, Slack, and Zscaler Internet Access (ZIA). +- Many supported sources use an [out-of-the-box OCSF pipeline][8] that requires no additional configuration. If a supported source is not producing entities, confirm that its out-of-the-box OCSF pipeline is active. Pipelines that predate OCSF support, and customized pipelines, may not include the required OCSF processing. - (Optional) To view associated Cloud Security insights in the entity panel, [Cloud Security must be configured][2]. @@ -109,10 +112,8 @@ The severity threshold of an entity is calculated by adding up the score impact {{< partial name="whats-next/whats-next.html" >}} -[1]: /security/cloud_siem/guide/aws-config-guide-for-cloud-siem/ [2]: https://docs.datadoghq.com/security/cloud_security_management/setup [3]: https://app.datadoghq.com/security [4]: https://app.datadoghq.com/security/siem/risk-insights -[5]: /security/cloud_siem/guide/google-cloud-config-guide-for-cloud-siem/ -[6]: /security/cloud_siem/guide/azure-config-guide-for-cloud-siem/ [7]: https://app.datadoghq.com/security/configuration/siem/risk-insights +[8]: /security/cloud_siem/ingest_and_enrich/open_cybersecurity_schema_framework/#supported-out-of-the-box-ocsf-pipelines