Case Study 04 — Cloud SIEM
Enter password
Carlos Diaz
Staff Product Designer
Work About
Case Study 04 — Cloud SIEM

Content Packs

A single, scalable experience that surfaces the true value of Cloud SIEM integrations — from day one and beyond.

42%Faster time-to-signal
2.7×Gallery visits
53Packs shipped
38%Fewer tickets
Project overview video
01Context

Cloud SIEM has dozens of integrations — each bundled with detection rules, dashboards, and workflows. But customers had no single place to see what was available or how to turn it on.

Detection rules lived in one part of the product. Dashboards in another. Docs on a separate site. Users who wanted to enable an integration had to visit three or four different pages, figure out the right log source configuration (which lived in an entirely separate product — Logs), and hope they got everything right.

The result: missed signals, broken setups, and support tickets from customers who thought they were configured but were actually missing critical log sources. The value was there — customers just couldn't find it or activate it.

RoleDesign Lead
TimelineQ1–Q2 2023 (3 months)
Shipped toCloud SIEM, CSM, ASM
TeamsPMs, Eng, Detection, GTM
Add image
02The Problem

Customers were paying for Cloud SIEM but not getting its full value — because the activation path was too fragmented to navigate.

🏗️

Activation required a scavenger hunt

Enabling one integration meant configuring log sources in Logs, finding detection rules in SIEM, then discovering dashboards elsewhere. Miss a step and the whole chain breaks silently.

👁️

Value was invisible until after setup

Users had no way to preview what an integration would give them before committing to configuration. Decisions about which integrations to prioritize were made blind.

♾️

Every integration was different

No shared pattern for surfacing content or monitoring health. Each integration had its own structure, making it impossible to scale onboarding as Datadog added more sources.

Add image
03Process

Three months from exploration to GA. Designed a system that launched with 53 integrations and is still scaling.

Month 1

Research + Audit

Ran heuristic reviews across every SIEM setup flow. Identified that the biggest drop-off happened between "I found an integration" and "I have it working" — the activation gap. Catalogued high-value content scattered across docs, product UI, and GTM materials.

Month 2

Architecture

Defined a three-level information architecture: Gallery (browse all integrations) → Content Pack (see everything one integration offers) → Activation Panel (configure and verify). Introduced pre-activation and post-activation states so the UI adapts to where you are in the setup journey.

Month 3

Test + Ship

Built and tested three UI directions: tile-based grid, side panel drill-in, and accordion expand. Validated with stakeholders and detection PMs. Landed on gallery + detail panel for the best balance of discoverability and depth at scale.

Add image
04Solution

One reusable pattern that shows what each integration delivers, guides activation, and catches misconfigurations before they become silent failures.

Modular Content Packs

Each Content Pack bundles everything for a single integration — detection rules, dashboards, workflows, documentation — into one scrollable page. No more jumping between four different product areas to understand what an integration offers.

Content pack detail

Preview Before Activation

Users can browse every detection rule, dashboard, and workflow before they configure anything. An "Activate This Content Pack" CTA makes the commitment clear. Empty states explain exactly what log sources to configure — making invisible prerequisites visible.

Pre-activation

Post-Activation Transparency

After activation, status indicators show whether log sources are actually flowing. "Broken Configuration" banners surface problems before they cause missed signals. Newly added content — like a dashboard update — appears instantly instead of getting buried in a changelog.

Post-activation

Gallery for Discovery

A single browsable index of all available integrations — what is activated, what is available, what is partially configured. The top 5 integrations are surfaced on the Cloud SIEM Overview page. This became the starting point for every security onboarding flow.

Gallery

Built to Scale

We designed for 30+ integrations. We shipped 53 at launch, with 20+ in the roadmap. The same pattern is now shared across Cloud SIEM, CSM, and ASM — and engineering is reusing the pack layout for Marketplace rule publishing.

Cross-product
05Outcomes

Launched with 53 Content Packs. Now the default onboarding pattern for all security products at Datadog.

42%

Faster Time-to-Signal

Dropped from 2.5 days to 1.4 days. 22% more orgs enabled at least one integration in their first week.

2.7×

Better Discoverability

Content Pack Gallery visits increased 2.7× after launch. Top integrations now visible directly on the Cloud SIEM Overview.

38%

Fewer Support Tickets

Audit Logs misconfiguration tickets dropped 38%. Empty state nudges drove a 48% increase in proper log ingestion.

4.3/5

Onboarding Satisfaction

Up from 3.1 to 4.3 out of 5. Global source enablements increased 35% across the platform.

53

Packs at Launch

20+ more in the roadmap. The pattern now powers all Security Onboarding and Setup flows.

Reusable

Platform System

Engineering reusing the layout in Marketplace publishing. Architecture supports future AI recommendations and usage insights.

Add image
← Signal Side Panel NextNatural Language Queries →