How-To: Export your RADIUS Logs to Datadog
Prerequisites
How To Export Your Cloud RADIUS Audit Logs To Datadog
How To Enable Log Export in EZRADIUS Portal
-
Go to your EZRADIUS Portal.
-
Click on Settings.

-
Scroll down to SIEM Settings and enable the Send Audit Logs to SIEM option.

How To Configure the Datadog Exporter in the Datadog Portal
-
In another tab, go to the Datadog Logs API docs: Datadog Docs.
-
Look on the top right and check that you have the correct Datadog site selected.

-
Select the correct site, then copy the corresponding URL.

-
Now go to your Datadog Instance. Here you will find your personal settings.

-
Hover over your username and click the API Keys option.

-
Then click the + New Key button

-
Give your key a name and click on the Create Key button

-
Copy your key and hit the Finish button.

How To Configure the Datadog SIEM in EZRADIUS Portal
-
Now go back to the EZRADIUS Portal.
-
Select Datadog as the SIEM Provider.

-
Input the values that you copied from the Datadog portals. Then, click Test Connection. This will create a test log in your Datadog SIEM (please allow a few minutes for the log to show up in the Datadog portal).

-
If the connection test is successful, click Save changes

-
EZRADIUS will now send your security alerts to your SIEM. If an error occurs it will email your subscription administrators. See below to see the different events EZRADIUS will send.
How To Create Alerts in Datadog to Monitor Your Cloud RADIUS Activity
Using a SIEM enables you to create alerts for critical operations or abnormal behavior. We recommend setting up alerts for any high criticality event, and closely monitor medium and low events. Below are sample queries for the Administrator events.
service:EZRadius @event_type:EZRadiusAdministrator @Action:SubscriptionUpdated