Datadog Expands Observability and Security Support for AWS Serverless Workloads
November 27, 2023
Share this

Datadog announced expanded security and observability support for AWS serverless applications built on AWS Lambda and Step Functions services.

The functionality helps AWS Lambda and Step Functions users detect security threats, get a high-level overview of how their state machine is performing at a single point in time and monitor services instrumented with OpenTelemetry.

Serverless applications eliminate the need to provision and manage infrastructure components, including servers, databases, queues and containers, so teams can focus on writing code while minimizing their operational overhead. These applications also come with unique challenges as they need to be monitored and secured in different ways than traditional applications. Datadog already provides out-of-the-box observability for AWS serverless applications and today expanded these capabilities to include:

- Support for W3C Trace Context Propagation Across All Lambda Runtimes: Teams can now view complete distributed traces across upstream and downstream services that have been instrumented by various OpenTelemetry-compatible instrumentation libraries. This provides teams with improved visibility into their serverless applications so they can efficiently troubleshoot any issues.

- AWS Lambda OpenTelemetry API Compatibility Custom Instrumentation: Developers can now use vendor-neutral code instrumentation to submit custom OpenTelemetry spans from Lambda applications to Datadog in Node.JS and Python runtimes, allowing them to adhere to open source standards.

- Threat Detection for Serverless Applications Deployed on AWS Lambda Functions: The new support enables both DevOps and security engineers to detect and protect against attacks targeting their applications running on AWS Lambda functions.

- Open Source Vulnerability Detection for AWS Lambda Functions: Available in public beta, this capability provides engineers with real-time, continuous vulnerability detection in third-party libraries that are being run in their AWS Lambda applications.

- AWS Step Function Execution Visualization on State Machine Maps: To make troubleshooting issues within AWS Step Functions easier, developers can see the exact path of a Step Function execution, drill into anomalous executions and identify problematic states with ease.

"Datadog helps us detect attacks against our serverless applications and triggers an automated response to block those attempts as they happen," said Micha Katz, CISO at Yellow Card. "Application Security Management was simple to enable and further configure to meet our needs. It provides an informative, well-organized UI, where we can drill into attack details, trigger additional actions using predefined workflows, and gain important insights that help us calibrate and optimize our detection rules. Additionally, with vulnerability detection and contextualized severity ratings, we can better prioritize our remediation efforts within our service layers."

"Securing serverless applications can be a unique challenge because they are highly distributed and comprise several ephemeral, stateless components," said Vikram Varakantam, Senior Director of Product Management at Datadog. "By providing full visibility into serverless applications on AWS Lambda, Datadog Application Security Management's threat detection capability helps DevOps and security teams understand and prioritize the risks and attacks associated with their serverless applications so that they can work to resolve and mitigate any potential breach."

The new features are available now.

Share this

The Latest

July 25, 2024

The 2024 State of the Data Center Report from CoreSite shows that although C-suite confidence in the economy remains high, a VUCA (volatile, uncertain, complex, ambiguous) environment has many business leaders proceeding with caution when it comes to their IT and data ecosystems, with an emphasis on cost control and predictability, flexibility and risk management ...

July 24, 2024

In June, New Relic published the State of Observability for Energy and Utilities Report to share insights, analysis, and data on the impact of full-stack observability software in energy and utilities organizations' service capabilities. Here are eight key takeaways from the report ...

July 23, 2024

The rapid rise of generative AI (GenAI) has caught everyone's attention, leaving many to wonder if the technology's impact will live up to the immense hype. A recent survey by Alteryx provides valuable insights into the current state of GenAI adoption, revealing a shift from inflated expectations to tangible value realization across enterprises ... Here are five key takeaways that underscore GenAI's progression from hype to real-world impact ...

July 22, 2024
A defective software update caused what some experts are calling the largest IT outage in history on Friday, July 19. The impact reverberated through multiple industries around the world ...
July 18, 2024

As software development grows more intricate, the challenge for observability engineers tasked with ensuring optimal system performance becomes more daunting. Current methodologies are struggling to keep pace, with the annual Observability Pulse surveys indicating a rise in Mean Time to Remediation (MTTR). According to this survey, only a small fraction of organizations, around 10%, achieve full observability today. Generative AI, however, promises to significantly move the needle ...

July 17, 2024

While nearly all data leaders surveyed are building generative AI applications, most don't believe their data estate is actually prepared to support them, according to the State of Reliable AI report from Monte Carlo Data ...

July 16, 2024

Enterprises are putting a lot of effort into improving the digital employee experience (DEX), which has become essential to both improving organizational performance and attracting and retaining talented workers. But to date, most efforts to deliver outstanding DEX have focused on people working with laptops, PCs, or thin clients. Employees on the frontlines, using mobile devices to handle logistics ... have been largely overlooked ...

July 15, 2024

The average customer-facing incident takes nearly three hours to resolve (175 minutes) while the estimated cost of downtime is $4,537 per minute, meaning each incident can cost nearly $794,000, according to new research from PagerDuty ...

July 12, 2024

In MEAN TIME TO INSIGHT Episode 8, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses AutoCon with the conference founders Scott Robohn and Chris Grundemann ...

July 11, 2024

Numerous vendors and service providers have recently embraced the NaaS concept, yet there is still no industry consensus on its definition or the types of networks it involves. Furthermore, providers have varied in how they define the NaaS service delivery model. I conducted research for a new report, Network as a Service: Understanding the Cloud Consumption Model in Networking, to refine the concept of NaaS and reduce buyer confusion over what it is and how it can offer value ...