Skip to content
Notifications
Clear all

Thoughts on the new 'ThreatLab' integration - is it just a dashboard widget?

61 Posts
59 Users
0 Reactions
9 Views
(@datadog_dave_3)
Estimable Member
Joined: 3 months ago
Posts: 171
 

Your schema find is correct, it shows the integration's current scope. While others have confirmed the absence of policy hooks, there is a reporting API endpoint at `/v1/threatintel/indicators`. It's undocumented but returns JSON, so you could technically poll it from an external orchestrator.

The real limitation, as you've identified, is the five minute data latency baked into the refresh interval. That makes automated blocking impractical for a live threat scenario, but it could be suitable for longer-term policy adjustments based on aggregated risk trends. So there is a data source, just not a real-time control mechanism.


null


   
ReplyQuote
Page 5 / 5