kimo
Security

Datadog + Kimo

Infrastructure metrics, logs and monitors. Correlate alerts and telemetry with intelligence feeds and assets, and cut the noise your analysts wade through.

Auth
API key
Sync
Real time
Setup
≈ 3 min
Request access

Live demo workspace with fictional data · no signup, no credentials needed

kimo / connectors / datadogSyncing
Sync logreal time
  • Succeeded:monitors+450 rowsnow
  • Succeeded:metrics+2,069 rows2m ago
  • Succeeded:monitors+2,012 rows4m ago
  • Succeeded:metrics+1,231 rows6m ago
Rows synced · 30 days
82M
Workspaces
12%
Simulated demo data
What you can do

What teams build with Datadog

Datadog on its own answers half the question. Joined with the rest of your stack in Kimo, it answers the other half.

01

Alerts by ATT&CK tactic

Group detections by MITRE technique and see which ones actually fire in your estate.

MITRE heatmap
02

MTTD / MTTR tracking

Measure detection and response times per team, severity and asset criticality.

MTTR p50
03

Enrich with intelligence

Correlate indicators from alerts with OSINT and threat feeds in one view.

IOC matches
Objects & tables

Exactly what gets synced

Kimo maps Datadog into clean, typed tables with primary keys and incremental cursors, so syncs stay fast and joins just work.

2 tables · 9 fields

metrics

Streaming≈ 5,580,000 rows
FieldTypeNotes
tstimestampIncremental cursor
metricstring
hoststring
valuedecimalMeasure
tagsjsonNested · flattened on demand
Custom fields and extra objects are discovered automatically on each sync. Row counts are illustrative.
Sample model

From raw Datadog tables to a certified metric

A starter model Kimo suggests the moment Datadog is connected. Every join is editable.

Datadog · SOC overview

Events and alerts joined with assets and threat intelligence on host and indicator.

Template
  • Datadog
    metrics
  • OSINT Feeds
    indicators
  • Apache Kafka
    topic.telemetry
Model
host · indicator
Measuresalertsincidents
Alerts · last 30 days
1,659-2.1% wk/wk

Fictional data · hover the chart for daily values

Setup

Connect Datadog in 3 min

No engineers, no pipelines to maintain. Kimo asks for the minimum access it needs and tells you exactly what it will read.

  1. 1

    Create a read-only key in Datadog

    Use a dedicated key scoped to read access, so it can be rotated independently.

  2. 2

    Paste it into Kimo

    Keys are encrypted with a per-workspace key and never shown again.

  3. 3

    Choose streams

    Pick which objects to sync, starting with metrics.

  4. 4

    Validate and sync

    Kimo tests the key, backfills history and keeps it fresh (real time).

Read-only, encrypted, revocable. Credentials are encrypted with a per-workspace key, never logged, and can be rotated without breaking your models.

Connect Datadog
Step 2 of 3 · Kimo demo workspace
  • Reaching host
  • Authenticating
  • Reading schema
Read-only access
Illustration only · placeholder values, never real secrets
FAQ

Datadog questions, answered

Datadog is ingested as a stream. New records typically appear in models and maps within a few seconds.

Datadog · API key · Real time

See your Datadog data in Kimo in 3 min.

Try it on the live demo workspace first, then connect your own account when you are ready.

Request access