Overview
The Datadog integration runs in two directions. A Datadog detection can assign a RansomLeak exercise to the people involved, so the response includes coaching. And training and human-risk events stream into Datadog, so awareness data sits alongside the signals you already watch.
The two halves are independent. Run either on its own, or both together:
- A detection assigns a lesson, via a Workflow action
- Training events stream in as logs and metrics
- Failures as high-signal events, plus hourly risk gauges
- Coaching assigned within about a minute
Turn a detection into coaching
When a detection fires on risky user activity, a Datadog Workflow action calls RansomLeak and assigns the matching exercise to the person involved. It uses the assignment API, so it fits the detection rules and playbooks you already maintain. No agent on your side does the work; the coaching is a downstream step in the workflow.
-
In RansomLeak, go to Admin → Integrations and generate an API token for the assignment API.
-
In Datadog, add a Workflow Automation with an HTTP Send POST request action that calls RansomLeak's assignment endpoint, with the token as a Bearer header.
-
Map the request body to the signal: the exercise to assign and the affected user's email. RansomLeak resolves the person and assigns the module within about a minute.
The same assignment endpoint powers our service-desk and SOAR integrations, so a Datadog detection, a Jira ticket, or a SOAR playbook can all end the same way: a short lesson for the person involved, and a completion you can act on.
Stream training events to Datadog
Install the RansomLeak integration from Datadog and approve access once. RansomLeak creates one API key in your Datadog org and uses it only to send training and human-risk data, as logs, metrics, and events tagged by tenant.
-
In Datadog, open Integrations, find RansomLeak, and click Connect Accounts. Enter your RansomLeak subdomain and sign in.
-
Approve access in Datadog. You land back on Admin → Integrations → Datadog in RansomLeak, which shows Connected.
-
Open the RansomLeak Overview dashboard in Datadog. Hourly metrics arrive straight away; logs arrive as people complete training.
You can also start in RansomLeak: choose your Datadog site and select Connect with Datadog. If you prefer not to use OAuth, select Use an API key instead and paste a Datadog API key.
| Data | How it arrives |
|---|---|
| Training completed | Log and count metric, as it happens. |
| Training failed | Log, count metric, and a high-signal event you can alert on. |
| Learning path completed | Log, count metric, and an event. |
| Enrollments, completion rate, overdue users, team risk score | Hourly metrics under ransomleak.*, for the dashboard and monitors. |
How it fits together
The two directions close a loop. A detection in Datadog can trigger coaching, and the result of that coaching streams back into Datadog as data you can watch and alert on.
- Detection fires on a named user
- A lesson is assigned to that user
- Completion streams back to Datadog
Training and human-risk events also reach any SIEM through the same export and webhooks, so the awareness data is not locked to Datadog. See the integrations overview for the full set of destinations.
Permissions and data handling
The event stream asks Datadog for one permission: to create an API key in your org. RansomLeak stores that key encrypted and uses it only to send data. The detection-to-coaching loop uses a RansomLeak API token your Workflow holds.
- API keys and tokens encrypted at rest
- User IDs and outcomes only, no names, emails or training content
- Uninstall or disconnect stops the stream
Disconnecting in RansomLeak revokes our access. Datadog doesn't let integrations delete their own key, so revoke the RansomLeak key under Organization Settings → API Keys afterwards. Uninstalling the tile in Datadog also revokes access. For how RansomLeak handles data, see the privacy policy and the security and compliance page.
Frequently asked questions
Does RansomLeak integrate with Datadog?
Yes, both ways. A Datadog detection can assign a RansomLeak exercise to the people involved through a Workflow action, and training and human-risk events stream into Datadog so they sit in the dashboards and monitors your SOC already watches.
How does a Datadog detection assign training?
You add a Datadog Workflow Automation with an HTTP "Send POST request" action that calls RansomLeak's assignment API with an API token. The action passes the exercise and the user, by email, from the signal, and RansomLeak assigns the matching module within about a minute. You build it on the detection rules and playbooks you already run.
What training data streams into Datadog?
Every completed or failed exercise arrives as a log (source:ransomleak) and a count metric, failures and finished learning paths also as events, and every hour RansomLeak sends enrollments by status, completion rate, overdue users and the Human Risk Score per team. The RansomLeak Overview dashboard and monitors ship with the integration.
What do I need to set this up?
For the event stream, install the RansomLeak tile in Datadog and approve access (or paste a Datadog API key instead). For the detection-to-coaching loop, a RansomLeak API token that your Datadog Workflow action uses to call the assignment API. The two are independent, so you can run either or both.
Does completion write back to Datadog?
Training and human-risk events stream into Datadog continuously, so a completion shows up there on its own. If your Workflow passes a callback, RansomLeak also posts the result back when the exercise finishes, so the playbook can act on it.
Is the detection-to-coaching loop a one-click feature?
No, and that is deliberate. The outbound event stream is a one-click connection from the Datadog tile. The detection-to-coaching loop is a Datadog Workflow you configure against RansomLeak's assignment API, the same open endpoint our service-desk and SOAR integrations use, so it fits the playbooks you already maintain.
Need a hand?
Email support@ransomleak.com and we will help you connect Datadog to your tenant.