Datadog Launches AI Security Analyst to Slash Cloud SIEM Investigation Times

Datadog's Bits AI Security Analyst for Cloud SIEM is now generally available, promising to cut alert investigation times by up to 98% and reduce mean time to resolution by more than 90%.

Layla Haddad
Cyber Policy & Digital Risk Correspondent3 min read
Datadog Bits AI Security Analyst for Cloud SIEM dashboard interface

Datadog Bits AI Security Analyst for Cloud SIEM dashboard interface

Datadog has made its Bits AI Security Analyst for Cloud SIEM generally available worldwide, offering security operations teams an autonomous investigation agent designed to handle alert triage, evidence gathering, and escalation decisions that would otherwise take analysts hours to complete.

The company says the tool can reduce mean time to resolution by more than 90%, with some investigations completing in as little as 30 seconds — a reduction of up to 98% compared to manual workflows.

Addressing Alert Fatigue at Scale

The launch comes as security operations centre teams face mounting pressure from rising alert volumes across cloud environments, identity systems, and endpoint tools. Datadog argues that AI-enabled attacks are compounding the problem, stretching already understaffed teams further.

Traditional analyst workflows require acknowledging alerts, correlating signals, gathering evidence, assessing findings, and deciding whether to escalate — each step adding time and cognitive load. Bits AI Security Analyst is designed to handle those steps autonomously within Cloud SIEM, drawing on the security and observability data already available in the Datadog platform.

Tim Knudsen, Vice President of Security Products at Datadog, said the product directly addresses structural weaknesses in legacy SIEM tools.

"Traditional SIEMs are leaving enterprises increasingly exposed because queues keep growing and investigations take longer to correlate and enrich context. On top of this, you have security talent shortages. Datadog Cloud SIEM with Bits AI Security Analyst solves this problem by autonomously investigating alerts, and leveraging security and observability signals to deliver accurate, fully explained verdicts that dramatically reduce remediation times."

A Unified Data Advantage

A core part of Datadog's pitch is that its combined observability and security data platform gives the AI agent richer context than tools operating in isolation. The agent draws on a unified view spanning infrastructure, cloud services, identities, endpoint detection and response systems, and observability telemetry.

Fragmentation has long been a pain point in security operations, where alerts may originate in one system while the supporting evidence sits in another. By keeping both data sets within a single environment, Datadog argues its agent can automate more of the investigation process without analysts needing to pivot between tools.

The product also integrates with Datadog's existing role-based access controls and integration base, lowering the deployment barrier for customers already running Cloud SIEM.

AI Agents Move to the Centre of Cyber Security

The release reflects a broader shift in how security vendors are positioning generative AI. The competitive focus has moved beyond alert summarisation toward autonomous systems capable of replacing the judgement calls that experienced analysts would otherwise make.

Yanbing Li, Chief Product Officer at Datadog, framed the product in the context of the company's existing enterprise footprint.

"One-in-four Fortune 500 companies rely on Datadog Security to help them detect, prioritise and remediate threats, vulnerabilities and misconfigurations. We are already a trusted partner and we continuously evolve our Cloud SIEM capabilities to directly face today's sophisticated threats, especially as GenAI attacks intensify. To combat modern attacks, SOCs need intelligent, autonomous systems that can investigate and report clearly. That's exactly what Bits AI Security Analyst delivers — a trusted AI agent that acts as an always-on senior SOC analyst teammate."

For security teams, a key practical concern will be transparency. Datadog says the tool delivers fully explained verdicts, which is likely to matter for organisations that need to justify escalation decisions and maintain audit trails during incident response. According to the company, teams using competing SIEM products can spend hours working through the same steps that Bits AI Security Analyst handles in minutes.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.