Datadog

SFTP To Go

SFTP To Go is a fully managed secure, scalable, and reliable cloud file storage service supporting SFTP, FTPS, S3, and HTTPS protocols. It allows sharing and integration with third parties using popular and secure protocols, and automates data management and processing using APIs and webhooks.

  • Secure data transfer and transparent encryption at rest
  • Reliable offsite backup
  • Compatibility and ease of use

Datadog

Datadog is a cloud monitoring, log management, observability, and security platform used to collect, search, analyze, and alert on operational and security data. By connecting SFTP To Go with Datadog, you can stream SFTP To Go audit log events into Datadog Logs through the Datadog Logs HTTP intake, then use those events for log monitoring, dashboards, alerts, investigations, and Cloud SIEM detection rules where Datadog Cloud SIEM is enabled.

  • Stream SFTP To Go audit log events to Datadog Logs through the HTTP intake
  • Search and filter SFTP activity by source, service, organization, event type, user, and file activity
  • Use SFTP audit events in Datadog dashboards, log monitors, alerts, and Cloud SIEM detection rules

How does it work?

  1. In Datadog, confirm which Datadog site your organization uses. SFTP To Go sends Datadog audit log events to the Logs HTTP intake for the selected Datadog site.
  2. Create or select the Datadog API key that SFTP To Go should use for log intake. Keep this key limited to the correct Datadog organization and rotate it according to your internal security policy.
  3. In SFTP To Go, add Datadog as a streaming audit log destination by following the SFTP To Go documentation for Datadog destinations. Complete the SFTP To Go destination setup there before continuing with the Datadog search, filtering, monitoring, and Cloud SIEM steps below.
  4. After the destination is saved in SFTP To Go, generate a test event by performing an auditable action, such as a login, failed login, upload, download, delete, or access-denied attempt.
  5. In Datadog, open Logs Explorer and confirm that the SFTP To Go audit event arrives. Start with the filters source:sftptogo and service:audit-logs. If you stream logs from more than one SFTP To Go organization, use the org:<id> tag to separate them.
  6. Inspect the log payload in Datadog. SFTP To Go wraps each audit event in the Datadog ingest envelope, and the message field carries the audit log object. Use that object to review the event type, principal, username, session, IP address, location, user agent, timestamp, file activity, and event-specific fields.
  7. Create Datadog facets only for the SFTP To Go audit log fields that your team needs to filter, group, or use in monitors. Good candidates include event type, username, principal type, source IP address, session ID, organization ID, and file path fields.
  8. If your Datadog account uses custom log pipelines, create or adjust a pipeline for SFTP To Go audit logs. Use a filter such as source:sftptogo service:audit-logs, then add processors only where needed to normalize attributes, remap status, enrich records, or align the logs with your organization’s naming conventions.
  9. Decide whether SFTP To Go audit logs should use a dedicated Datadog index or the same index as other security logs. A dedicated index can help with retention, quota, usage tracking, and compliance reporting if your organization keeps security audit records separate from operational logs.
  10. Create Datadog log monitors for high-priority SFTP To Go security events. Useful starting points include repeated failed logins, access-denied events, unexpected downloads, delete activity, access from unusual locations, or spikes in file activity over a short time window.
  11. If Datadog Cloud SIEM is enabled, create or tune detection rules that analyze the ingested SFTP To Go audit logs. Use the SFTP To Go audit log fields to detect suspicious activity such as repeated login failures, explicit access-denied events, unusual download volumes, unexpected delete activity, or access from unfamiliar IP addresses or locations.
  12. Review resulting Cloud SIEM security signals in Datadog when a detection rule matches. Use the matched logs, event fields, user information, IP address, file path, and activity type to support triage and investigation.
  13. Build dashboards or saved views for common SFTP To Go investigations. For example, create views for recent failed logins, file deletes, high-volume downloads, access-denied events, activity by user, and activity by organization.
  14. Test the complete workflow by triggering each important event type in SFTP To Go and confirming that it appears in Datadog with the expected source, service, organization tag, message object, parsed fields, facets, monitors, dashboards, and Cloud SIEM signals where applicable.
  15. Monitor delivery health in SFTP To Go and log intake behavior in Datadog. If events stop arriving, check the SFTP To Go destination status, Datadog API key validity, selected Datadog site, log intake settings, and any Datadog pipeline or index filters that could prevent expected logs from appearing.
  16. As your security monitoring requirements change, update your Datadog facets, pipelines, indexes, monitors, dashboards, and Cloud SIEM detection rules without changing the underlying SFTP To Go file transfer environment.

You can find further insight here, here, here, here, here, and here.