Aqua Blog

Integrate Aqua and Datadog to Connect Runtime Security with Application Performance

Integrate Aqua and Datadog to Connect Runtime Security with Application Performance

TL;DR AI is compressing the time between vulnerability discovery and exploitation, while security teams still depend on workflows that require people to review alerts and piece together context. A vulnerable or unauthorized image, a runtime policy violation or a change in workload protection can become relevant to application availability before teams understand what happened. Aqua monitors images and running workloads and enforces controls where applications execute. The Aqua integration with Datadog brings that granular security information into the same monitoring environment teams use for application performance, so they can identify unusual activity quickly and understand its impact on availability.

What does the Aqua integration with Datadog do?

 

AI has changed the speed of application security. Attacks can exploit known and unknown vulnerabilities faster than traditional investigation and remediation processes can respond. When activity unfolds at machine speed, collecting information for someone to review later is not enough. Teams need to understand what is happening inside running workloads and enforce controls at the point of execution.

Application and security teams often see different parts of that problem. Datadog provides insight into containerized application performance, while Aqua gathers security information across the images and containers supporting those applications. Aqua identifies image vulnerabilities and other security issues, containers running from unauthorized images and runtime policy violations.

When that information remains in separate tools, application teams may see an availability problem without the security context surrounding it. Security teams may identify a policy violation or unauthorized image without immediately seeing what was happening to the application at the same time.

The Aqua integration with Datadog connects those views. Datadog’s prebuilt Aqua dashboard displays security metrics and events gathered by Aqua, including images waiting to be scanned, image vulnerabilities, runtime policy violations, audit events, deployed Aqua Enforcers and running containers identified and protected by Aqua.

Datadog anomaly detection can then help teams recognize unexpected changes in that information. Instead of reviewing each security metric separately, teams can customize monitoring around the vulnerabilities, unauthorized images and runtime activity that matter to their environment.

How does the Aqua and Datadog integration work?

 

The integration starts with Datadog’s prebuilt Aqua dashboard, which provides a central view of the security metrics and events Aqua gathers.

Teams can monitor images waiting to be scanned for vulnerabilities, secrets, malware and other security issues. The dashboard also provides granular insight into the image scan queue, image vulnerabilities, policy violations and audit events.

The dashboard tracks the number of Aqua Enforcers deployed across hosts or cluster nodes and monitored by Aqua. It also shows the number of running containers Aqua has identified and protected, helping teams see whether security coverage is keeping pace as workloads and infrastructure change.

Datadog anomaly detection applies another layer of monitoring to this information. Teams can customize how they evaluate known vulnerabilities, security issues in images, containers running from unauthorized images and runtime policy violations. An unusual increase in one of those conditions can be investigated alongside changes in application performance.

Aqua audit logs are sent to Datadog through a webhook. An administrator connects to the Aqua account, opens the Log Management section of the Integration page and activates the Webhook integration. They then enable the integration and add the Datadog log intake endpoint:

http-intake.logs.datadoghq.com/v1/input/<DATADOG_API_KEY>?ddsource=aqua

The administrator replaces <DATADOG_API_KEY> with the Datadog API key. Once configured, Aqua audit logs appear in Datadog, where teams can compare security activity with application performance and availability data.

The integration does not assume that every security event caused an application problem. It gives teams the context needed to investigate whether unusual security activity and a change in application availability are connected.

What does this integration mean for Aqua customers?

 

Aqua monitors the behavior of running workloads and enforces security controls where attacks execute. Datadog makes the security information gathered by Aqua available within the application monitoring workflow.

For Aqua customers, that means security posture is no longer separated from the operational view of the application. Teams can compare image vulnerabilities, unauthorized images, policy violations and audit events with application behavior from the same period.

The integration also makes workload protection easier to monitor as the environment changes. Teams can track Aqua Enforcers across hosts and cluster nodes and see how many running containers Aqua has identified and protected. A change in those numbers can help teams recognize when new infrastructure or workloads may require attention.

Datadog anomaly detection helps surface changes that may be difficult to recognize through fixed thresholds alone. Teams can customize monitoring around the normal behavior of their environment and investigate when Aqua security metrics move outside those patterns.

Aqua remains responsible for gathering granular security information and enforcing security practices across the environment. Datadog places that information beside application performance, giving application and security teams a shared view from which to understand the issue and its potential operational impact.

Where does this matter most?

 

Application incident investigation. When application availability changes, teams can review Aqua security events from the same period. They can determine whether an unauthorized image, policy violation, vulnerability or change in protection coverage occurred while the application problem was developing.

Runtime security monitoring. Runtime policy violations reflect activity occurring inside running containers. Bringing those events into Datadog allows teams to review security activity through the monitoring workflows they already use for applications and infrastructure.

Image security operations. Teams can monitor images waiting to be scanned for vulnerabilities, secrets, malware and other security issues. Visibility into the scan queue helps them identify unexpected growth that may delay insight into image risk.

Workload protection coverage. Container environments change as applications scale and cluster nodes are added or replaced. Tracking Aqua Enforcers and protected containers helps teams see whether monitoring and enforcement coverage is keeping pace with those changes.

Collaboration between application and security teams. Datadog provides insight into containerized application performance while Aqua provides security information and enforcement. Combining those views helps teams identify issues quickly and analyze their impact on application availability without reconstructing the environment across separate systems.

What do you need to get started with Aqua and Datadog?

 

Teams need access to their Aqua account, permission to configure the Webhook integration in the Log Management section and a Datadog API key.

To collect Aqua audit logs, an administrator activates the Webhook integration in Aqua and adds the Datadog log intake endpoint with the correct API key. Once enabled, Aqua sends audit logs to Datadog for monitoring and investigation.

Teams can then use the prebuilt Aqua dashboard to view image scan activity, vulnerabilities, policy violations, audit events, Aqua Enforcers and protected containers. Datadog anomaly detection can be customized around the security conditions that matter to the organization.

Customers can request an Aqua demo to see how the integration brings container security information and application performance together.

FAQ
What Aqua information can teams view in Datadog?

Teams can view images in the scan queue, image vulnerabilities, policy violations, audit events, Aqua Enforcers and the number of running containers identified and protected by Aqua.

What security issues can teams monitor?

Teams can monitor known vulnerabilities and other security issues in images, containers running from unauthorized images and runtime policy violations. They can also monitor images waiting to be scanned for vulnerabilities, secrets and malware.

How does Datadog anomaly detection support the integration?

Datadog anomaly detection allows teams to customize how they monitor Aqua security information and identify activity that is unusual for their environment. Teams can then investigate that activity alongside application performance and availability.

Can teams monitor Aqua protection coverage?

Yes. The dashboard shows the number of Aqua Enforcers deployed across hosts or cluster nodes and monitored by Aqua. It also shows the number of running containers Aqua has identified and protected.

How are Aqua audit logs sent to Datadog?

Aqua audit logs are sent through a webhook configured in the Log Management section of the Aqua Integration page. The webhook uses the Datadog log intake endpoint and the customer’s Datadog API key.

Does Datadog replace Aqua’s runtime security controls?

No. Aqua gathers the security information and enforces controls across the environment. Datadog brings that information into the application monitoring workflow so teams can understand how security conditions may relate to application availability.

Aqua Team
Aqua Security is the pioneer in securing containerized cloud native applications from development to production. The Aqua full lifecycle solution prevents attacks by enforcing pre-deployment hygiene and mitigates attacks in real time in production, reducing mean time to repair and overall business risk. The Aqua Platform, a Cloud Native Application Protection Platform (CNAPP), integrates security from Code to Cloud, combining the power of agent and agentless technology into a single solution. With enterprise scale that doesn’t slow development pipelines, Aqua secures your future in the cloud. Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL protecting over 500 of the world’s largest enterprises.
Need to secure enterprise workloads?

Aqua Cloud Native Application Protection Platform (CNAPP)

Go cloud native with the experts!