Audit Trail: Security Investigation
Answer common security investigation questions using pup audit-logs.
Prerequisites
Command Execution Order
- Clarify the investigation scope: who, what resource type, what time window.
- Run the most specific query first; broaden only if results are empty.
- If results are large, pipe to
jqto group or summarize. - Highlight anomalies: bulk operations, unusual geo, off-hours activity, support user actions.
Common Investigation Queries
Who deleted resources in a time window?
Who modified a specific resource (by ID)?
What did a specific user do?
Login activity — all logins with geo
Failed logins only
Who changed roles or permissions?
What actions came from a specific IP?
Who created or deleted API keys?
Event Category Reference
Anomaly Flags to Surface
When presenting investigation results, call out:
- Actor type
SUPPORT_USER— Datadog support accessed the org - Bulk deletions — same user, same action, many resources in a short window
- Unexpected geography — country not seen in prior logins for this user
- Off-hours activity — actions at unusual times for the user's typical timezone
- First-time ASN — action from a cloud provider or VPN not seen before (
@network.client.geoip.as.name)


