Repository navigation
Conversation
Documents Standalone as the default Cloud SIEM product for new organizations, including gigabyte-based analyzed log usage, included ingestion for logs indexed in the Cloud SIEM index, and the 12-month signal retention period. Adds a features-by-product table to the "Determine the Cloud SIEM product your organization is using" guide, makes the rule deprecation retention period product-dependent, and replaces "legacy SKU" with "Cloud SIEM Legacy" on the MITRE ATT&CK Map page. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Retention for Standalone is 365 days (12 months) and applies to data, not only to security signals. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
| - [Rule editor][3] for that specific rule | ||
| 2. Once the rule is deprecated, there is a 15 month period before the rule is deleted. This is due to the signal retention period of 15 months. During this time, you can re-enable the rule by [cloning the rule][3] in the UI. | ||
| 3. Once the rule is deleted, you can no longer clone and re-enable it. | ||
| 2. After the rule is deprecated, the rule remains available for the length of your retention period before it is deleted. During this time, you can re-enable the rule by [cloning the rule][3] in the UI. The retention period depends on your [Cloud SIEM product][7]: |
There was a problem hiding this comment.
For the 12m Standalone SKU, while logs are retained and indexed for 12mo, signals are actually still retained for 15mo
| 2. Once the rule is deprecated, there is a 15 month period before the rule is deleted. This is due to the signal retention period of 15 months. During this time, you can re-enable the rule by [cloning the rule][3] in the UI. | ||
| 3. Once the rule is deleted, you can no longer clone and re-enable it. | ||
| 2. After the rule is deprecated, the rule remains available for the length of your retention period before it is deleted. During this time, you can re-enable the rule by [cloning the rule][3] in the UI. The retention period depends on your [Cloud SIEM product][7]: | ||
| - Standalone: 365 days (12 months) |
There was a problem hiding this comment.
We offer 2 standalone SKUs actually - one that has 12 mo retention measured in GB and another that has 15 mo retention measured in events
reference: https://datadoghq.atlassian.net/wiki/spaces/PMM/pages/7142343276/Cloud+SIEM+SKUs+FAQs+Updated+9+2026
| - Add-on with Flex Logs | ||
| - Legacy | ||
|
|
||
| Standalone is the default product for new Cloud SIEM organizations. In Standalone: |
There was a problem hiding this comment.
There are 2 versions of standalone - sorry that's a bit confusing. Open to different naming
https://datadoghq.atlassian.net/wiki/spaces/PMM/pages/7142343276/Cloud+SIEM+SKUs+FAQs+Updated+9+2026
| ## Features by Cloud SIEM product{#features} | ||
|
|
||
| The following table lists the Cloud SIEM features available in each product. | ||
|
|
There was a problem hiding this comment.
I would say let's leave Add-on out of this table as it maps to exactly what Standalone offers
There was a problem hiding this comment.
Is this true? Security and log index filters don't match in the below table
There was a problem hiding this comment.
We just don't publicly advertise Add on today - I'm wondering if it makes sense to keep it as a discoverability item - like to understand if you are on Add on, but not to have customers inquire about Add on, if that makes sense
There was a problem hiding this comment.
Yeah, I think docs tend to describe what's possible rather than trying to encourage people to go one way or the other
| Standalone 12 months is the default product for new Cloud SIEM organizations. In Standalone: | ||
| - Usage is measured in gigabytes of analyzed logs, rather than in millions of analyzed events. | ||
| - Ingestion of logs indexed in the Cloud SIEM index is included in the analyzed log cost, rather than billed separately. | ||
| - Data is retained for 365 days (12 months), rather than for 15 months. |
There was a problem hiding this comment.
Does "data" here refer to logs AND signals? If so, we should clarify they have different retention periods here as well.
There was a problem hiding this comment.
@shrey4b let me know how to make this clearer!
| - Ingestion of logs indexed in the Cloud SIEM index is included in the analyzed log cost, rather than billed separately. | ||
| - Data is retained for 365 days (12 months), rather than for 15 months. | ||
|
|
||
| Organizations that adopted Standalone before gigabyte-based usage was introduced have a 15-month retention period. Both are referred to as Standalone in the documentation, because they provide the same features. |
There was a problem hiding this comment.
| Organizations that adopted Standalone before gigabyte-based usage was introduced have a 15-month retention period. Both are referred to as Standalone in the documentation, because they provide the same features. | |
| Organizations that adopted Standalone before gigabyte-based usage was introduced have a 15-month retention period. Both are referred to as Standalone in the documentation because they provide the same features. |
Suggesting a small nit fix, but bigger question: I wonder if it makes more sense to consolidate this explanation with the list above (L10) since it introduces both the 12 and 15 month products as Standalone.
maxvp
left a comment
There was a problem hiding this comment.
Left a few comments and suggestions for clarity!
Co-authored-by: Max Phillips <maxvphillips@gmail.com>
| - Standalone | ||
| - 12 months (365 days, usage measured in GB) | ||
| - 15 months (450 days, usage measured in millions of events) | ||
| <div class="alert alert-info">Organizations that adopted Standalone before 12-month retention was introduced have a 15-month retention period. The documentation refers to both as Standalone, because they provide the same features.</div> |
There was a problem hiding this comment.
@maxvp This is ready for re-review when you have a second! Thanks for the suggestion to move this - how does this look to you?
What does this PR do? What is the motivation?
Fixes DOCS-15474
Documents Standalone as the default Cloud SIEM product for new organizations, and stops describing products as "SKUs" in user-facing content.
Determine the Cloud SIEM product your organization is using
Detect and monitor
MITRE ATT&CK Map
Customize which logs Cloud SIEM analyzes
Reviewer notes
/security/cloud_siem/detect_and_monitor/critical_assets/, which Rename Cloud SIEM Critical Assets to Dynamic Severity #39624 renames todynamic_severity. Whichever PR merges second needs a one-line link update.Merge readiness
For Datadog employees:
<name>/<description>convention and include the forward slash (/). If you've already created your PR with an incorrect branch name, please rename your branch and open a fresh PR./reviewto run an automated check that catches common issues before a Documentation team member reviews your PR.AI assistance
Claude Code read the Jira ticket, the linked internal resources, and the exported feature-mapping spreadsheet, then drafted the edits and this description. Reviewed and edited by me.
Additional notes