M ManySignal

Integration Category

Observability Platform Integrations

Datadog, New Relic, Elastic, Grafana, Dynatrace — ManySignal ingests application telemetry and infrastructure metrics to correlate performance anomalies with security events across your environment.

Observability integration FAQs

Why should SOC teams care about observability data?

Observability platforms capture application behaviour, infrastructure health, and distributed trace data that security tools rarely ingest. Supply chain attacks, API abuse, and insider threats often appear first in application telemetry — slow response times, anomalous API call volumes, or unusual trace patterns — before they generate a security alert.

How does ManySignal integrate with Datadog?

ManySignal ingests Datadog Security Signals via the Datadog Events API and log data via the Datadog Log Management API. Infrastructure metrics are used for entity enrichment — correlating a suspicious process event with the underlying host's anomalous CPU and memory patterns confirms active exploitation.

Does ManySignal correlate application traces with security events?

Yes. Distributed traces from Datadog APM, New Relic, or Dynatrace are correlated with security events on the same entity. An SQL injection attempt in a WAF log that corresponds to a database query spike in application traces provides confirmation that the attack succeeded.

Can ManySignal detect security incidents in application logs?

Yes. Application logs ingested from Datadog, Elastic, or Splunk Observability are parsed by ManySignal's normalisation layer to extract security-relevant events: authentication failures, privilege escalation attempts, data export operations, and API key usage anomalies.

How does Elastic (ELK Stack) integration work?

ManySignal connects to Elasticsearch via the Elasticsearch REST API, querying for security-relevant log indices. Beats agents deployed on endpoints stream logs to Elasticsearch which ManySignal then pulls. Existing Kibana detection alerts are also imported as signals into ManySignal's investigation layer.

Does ManySignal ingest infrastructure health metrics for security context?

Yes. Anomalous resource consumption is a security signal: a Lambda function consuming 10x its normal memory may indicate cryptomining; a database instance with unusual network egress may indicate data exfiltration. ManySignal uses infrastructure metrics from Datadog, New Relic, or Grafana as supporting evidence in investigations.

How does ManySignal handle alert noise from observability platforms?

Observability platforms generate high volumes of operational alerts. ManySignal applies security-specific filtering: only events matching security-relevant categories (authentication, access control, data operations, network anomalies) are ingested. Pure infrastructure availability alerts (CPU high, disk full) are excluded unless they correlate with active security investigations.

Does ManySignal support Grafana Loki for log ingestion?

Yes. ManySignal ingests log streams from Grafana Loki via the Loki HTTP push API. Grafana alerting rules can also send webhook notifications to ManySignal when security-relevant conditions are met, triggering investigation workflows.

Can ManySignal correlate Dynatrace Davis AI problems with security events?

Yes. Dynatrace Davis AI problems indicate application anomalies that may have security causes. ManySignal ingests Davis problem events and correlates them with concurrent security signals — a Davis problem about unusual API traffic, combined with a WAF event, elevates investigation priority.

How does ManySignal use Splunk Observability Cloud data?

ManySignal ingests SignalFx metric anomalies and distributed trace data from Splunk Observability Cloud. Note: Splunk Observability Cloud is distinct from Splunk Enterprise Security (SIEM). ManySignal treats Observability Cloud as an infrastructure telemetry source and Enterprise Security as a detection source, correlating both for complete visibility.

Bring observability telemetry into your security workflow

Connect Datadog or Elastic to ManySignal and correlate application anomalies with security events automatically.