Datadog Cloud SIEM

SOCaaS

Datadog Cloud SIEM is a self-service cloud SIEM and security monitoring product inside Datadog's observability platform. After an alert, Datadog generates security signals, notifications, cases and workflow hooks, while the buyer owns triage, investigation, containment, remediation and rule tuning.

What they do
Monitor and notify
Works with
Their platform
Built for
Enterprise / Mid-Market
Price
Published from $5 per 1M analyzed events/month
Best for
Cloud-native teams already using Datadog for logs, infrastructure monitoring or APM

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications
  • Containers & Kubernetes
  • Code & Applications

Your team still owns

  • Triage, investigation and response decisions after Datadog creates a signal
  • Tuning detection rules, routing notifications and managing false positives
  • Connecting log sources, agents, cloud accounts and security integrations
  • Running containment actions through internal tools or customer-configured workflows
  • Forecasting event volume, log retention and related Datadog module costs

Pricing

Line Figure
Published price Datadog pricing list Separate Datadog products, retention choices, data routing and contract terms can materially change the final bill. Published from $5 per 1M analyzed events/month
Billing model Tiered, Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Clear first-lane fit for buyers that want security monitoring and notification, not outsourced response
  • Works naturally for teams already sending logs, traces and infrastructure telemetry to Datadog
  • Published event-based Cloud SIEM pricing is easier to compare than most managed SOC quotes
  • Case management, notifications and workflows give internal teams an operating path after a signal fires

Watch out for

  • No Datadog-managed SOC analysts investigate or contain threats for the buyer
  • Buyers need internal security ownership for rule tuning, triage, response and after-hours coverage
  • Pricing can expand when Cloud SIEM is combined with log retention, CSM, AAP, workload protection or observability modules
  • Review and Reddit themes repeatedly mention cost forecasting, learning curve and noise tuning

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Gartner themes mention cloud visibility, centralized log monitoring and event correlation
  • G2 reviewers value Datadog's ability to connect logs, metrics, traces and alerts during incidents
  • Reddit users often separate Datadog's technical value from its pricing complexity

Watch out for

  • Gartner critical themes mention high cost, setup effort and source-forwarding friction
  • G2 reviewers repeatedly describe a broad interface and learning curve
  • Reddit pricing threads warn that ingestion, indexing, retention and negotiated terms can make bills hard to forecast

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which signals only notify our team, and which workflows can safely run without manual approval?
  2. What event volume, retention and Datadog log-management costs are assumed in the quote?
  3. Who will own rule tuning, case assignment, after-hours triage and containment when a high-severity signal fires?

Integrations

Datadog Cloud SIEMDatadog Log ManagementCrowdStrike FalconMicrosoft WindowsAWSAzureGCPMicrosoft 365Google WorkspaceAWS CloudTrailOktaAuth01PasswordCisco MerakiPalo Alto NetworksPagerDutySlackJira

Editorial notes

Why monitor and notify

Datadog Cloud SIEM creates security signals, notifications, cases and workflow triggers, but the buyer operates the SIEM. Public sources do not show Datadog analysts taking ownership of alert triage or incident response for this product.

Scope boundary

This profile covers Datadog Cloud SIEM and closely related security monitoring workflow, not Datadog's whole observability and cloud security portfolio. CSM, workload protection, application protection, code security and incident management can be separately licensed.

Pricing boundary

Datadog publishes Cloud SIEM event pricing, but buyers still need to model ingestion, retention, event volume, cloud egress and adjacent Datadog modules. Public reviews and Reddit discussions repeatedly warn that Datadog costs can be hard to forecast.

AI and workflow boundary

Datadog markets AI investigations and workflow automation, but those features support the buyer's team. They do not make Datadog a managed investigation or response provider unless a separate service owns that work.

Questions

Is Datadog Cloud SIEM an MDR service?
No. Datadog Cloud SIEM is a self-service SIEM and security monitoring product. It creates signals, notifications, cases and workflow hooks, but the buyer owns triage, investigation, containment and remediation.
Why is Datadog classified as Monitor and notify?
The public product evidence supports detection, alerting, notification, case tracking and customer-configured workflow automation. It does not show Datadog analysts investigating and responding to alerts on the buyer's behalf.
How is Datadog Cloud SIEM priced?
Datadog publishes Cloud SIEM pricing from $5 per 1 million analyzed events per month. Buyers should also model log management, retention, adjacent security modules, cloud data transfer and negotiated contract terms.