Skip to content

[DOCS-15474] Add default Standalone product info to Cloud SIEM docs - #39641

Open
janine-c wants to merge 3 commits into
masterfrom
janine/docs-15474-siem-standalone-sku
Open

[DOCS-15474] Add default Standalone product info to Cloud SIEM docs#39641
janine-c wants to merge 3 commits into
masterfrom
janine/docs-15474-siem-standalone-sku

Conversation

@janine-c

@janine-c janine-c commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do? What is the motivation?

Fixes DOCS-15474

Documents Standalone as the default Cloud SIEM product for new organizations, and stops describing products as "SKUs" in user-facing content.

Determine the Cloud SIEM product your organization is using

  • Adds a Standalone summary to the overview: usage measured in gigabytes of analyzed logs (not millions of events), ingestion included for logs indexed in the Cloud SIEM index, and a 12-month signal retention period.
  • Notes that earlier Standalone organizations have a 15-month retention period, and that both are called Standalone because the feature sets are identical.
  • Adds a Features by Cloud SIEM product table comparing Standalone, Add-on with Flex Logs, and Legacy.

Detect and monitor

  • Rule deprecation no longer hardcodes 15 months. The window now follows the signal retention period for the reader's product (12 months for Standalone, 15 months for Add-on with Flex Logs and Legacy).

MITRE ATT&CK Map

  • Replaces "legacy SKU" with "Cloud SIEM Legacy", linked to the product-determination guide. Also capitalizes Security Filters to match the rest of the docs.

Customize which logs Cloud SIEM analyzes

  • Notes that Standalone is the default product for new organizations.
  • Drive-by typo fix: "logs that would the main filter query would otherwise process".

Reviewer notes

  • Merge order: the features table links to /security/cloud_siem/detect_and_monitor/critical_assets/, which Rename Cloud SIEM Critical Assets to Dynamic Severity and Crown Jewels to Critical Assets #39624 renames to dynamic_severity. Whichever PR merges second needs a one-line link update.
  • Retention scope: Standalone retention is documented here as 365 days (12 months) applying to data generally, not only to security signals (the docs previously described 15 months as specifically the signal retention period). Please confirm that signals and indexed logs share a single retention period, rather than differing.
  • Features table omissions: the source feature mapping lists content anomaly detection, detections on Audit Trail events, and detections on events as available in all products but flags that availability as still under review, so those rows are left out for now. Behavior AI, UEBA user inventory, Bits AI SOC agent, risk-based alerting, and Threat Hunting are also omitted because they have no public documentation to link to. Happy to add any of these if they should be listed.
  • Out of scope, flagging for a follow-up: Pricing still defines an analyzed log as billed "based on the millions of events per month analyzed". That needs updating for gigabyte-based usage, but the correct wording for Add-on and Legacy organizations wasn't clear to me.

Merge readiness

  • Ready for merge

For Datadog employees:

  • ⚠️ Your branch name MUST follow the <name>/<description> convention and include the forward slash (/). If you've already created your PR with an incorrect branch name, please rename your branch and open a fresh PR.
  • 🤖 New: Comment with /review to run an automated check that catches common issues before a Documentation team member reviews your PR.

AI assistance

Claude Code read the Jira ticket, the linked internal resources, and the exported feature-mapping spreadsheet, then drafted the edits and this description. Reviewed and edited by me.

Additional notes

Documents Standalone as the default Cloud SIEM product for new
organizations, including gigabyte-based analyzed log usage, included
ingestion for logs indexed in the Cloud SIEM index, and the 12-month
signal retention period.

Adds a features-by-product table to the "Determine the Cloud SIEM
product your organization is using" guide, makes the rule deprecation
retention period product-dependent, and replaces "legacy SKU" with
"Cloud SIEM Legacy" on the MITRE ATT&CK Map page.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@janine-c
janine-c requested a review from a team as a code owner September 1, 2026 20:40
@janine-c janine-c added the WORK IN PROGRESS No review needed, it's a wip ;) label Sep 1, 2026
janine-c and others added 2 commits September 1, 2026 15:14
Retention for Standalone is 365 days (12 months) and applies to data,
not only to security signals.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

WORK IN PROGRESS No review needed, it's a wip ;)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant