Skip to technology filters Skip to main content
Dynatrace Hub

Extend the platform,
empower your team.

Popular searches:
Home hero bg
SnykSnyk
Snyk

Snyk

Ingest Snyk vulnerability findings, scans, and audit logs.

Extension
Free trialDocumentation
Vulnerability findings overview.Security coverage overview.Sample Jira workflow.Sample Slack workflow.
  • Product information
  • Release notes

Overview

Dynatrace integrates with Snyk products to enable visibility, orchestration, and prioritization of code, library, and container vulnerability findings.

Capabilities:

  • Single pane of glass: Ingest vulnerability findings, scan events, and audit logs from Snyk products into Dynatrace (powered by OpenPipeline™)

  • Unified analysis: Dynatrace transforms and maps the findings to a unified format for vulnerability findings (powered by Dynatrace Semantic Dictionary)

  • Findings operationalization: Prioritize, visualize, and automate vulnerability findings with runtime context

  • Unveil blind spots: Discover and eliminate coverage gaps in your Software Development Lifecycle (SDLC)

Use cases

  • Overview: Visualize and report your current security posture and trends around vulnerability findings across vulnerability scanners with Dashboards.

  • Prioritization: Analyze and prioritize vulnerability findings across multiple tools and products uniformly with Notebooks.

  • Automation: Create notifications and tickets for critical vulnerability findings with Workflows.

  • Investigation: Use vulnerability findings as an additional dimension for threat hunting and incident forensics using Security Investigator.

Get started

For more information on the installation and configuration, please see Snyk extension in the Dynatrace Documentation.

Details

Compatibility information

  • Snyk REST API v2
  • Snyk v1 API
Dynatrace
DocumentationMore Information
By Dynatrace
Dynatrace support center
Subscribe to new releases
Copy to clipboard

Related to Snyk

ActiveGate logo

ActiveGate

Route traffic, monitor clouds and remote technologies & run Synthetic monitors.

Extensions logo

Extensions

Manage Dynatrace extensions for hundreds of technologies.

OpenPipeline logo

OpenPipeline

Configure ingest, processing, and persistence of data sent to Grail.

Full version history

To have more information on how to install the downloaded package, please follow the instructions on this page.
ReleaseDate

Full version history

🚀 Improved in this version:

  • Vulnerability finding events now have vulnerability.cvss.base_score and vulnerability.cvss.vector fields.

ℹ️ This version requires ActiveGate version 1.313.0 or higher.

Full version history

🚀 Improved in this version:

  • Ingested security events are now enriched with the fields dt.security_context, dt.cost.costcenter and dt.cost.product defined in the monitoring configuration.

ℹ️ This version requires ActiveGate version 1.313.0 or higher.

Full version history

🚀 Improved in this version:

  • Adjusted mappings for vulnerability findings and scan events:
    • Added a new field finding.type.
    • Events for which object.type was mapped to snyk.project now have object.type mapped to a semantic dictionary type. ⚠️ Dashboards and automations which were explicitly filtering for object.type == snyk.project will need to be updated ⚠️
    • object.name is now aligned with artifact.name.
    • Mapped artifact and code namespaces where relevant.
  • Added proxy support to connect to the Dynatrace environment.
  • Updated dashboards.
  • Added an optional filter for issue severity type.
  • Added an optional filter for project origin.

🪲 Fixed in this version:

  • Fixed issue where audit logs would not be properly collected when monitoring multiple organizations.

ℹ️ This version requires ActiveGate version 1.313.0 or higher.

Full version history

🪲 Fixed in this version:

  • Fixed another issue where events would be missed due to ActiveGate timezone mismatches.

ℹ️ This version requires ActiveGate version 1.313.0 or higher.

Full version history

🚀 Improved in this version:

  • The field finding.url is now populated with the issue URL for finding events.

🪲 Fixed in this version:

  • Fixed issue where events would sometimes be missed if the extension execution time exceeded the configured value.
  • Fixed issue where events would be missed due to ActiveGate timezone mismatches.
  • Fixed some of the out-of-the-box dashboard tiles showing errors.

ℹ️ This version requires ActiveGate version 1.313.0 or higher.

Full version history

🚀 Improved in this version:

  • The fields dt.extension.config.id and extension.config.name were added to the ingested audit logs.
  • To align with the new security.events OpenPipeline endpoint, the bundled ready-made dashboards now query this table instead of events. We recommend all users to adjust their monitoring configurations to ingest data to this new endpoint. You can find the official guidance here.

🪲 Fixed in this version:

  • Project tags for scan events are now properly formatted.

ℹ️ This version requires ActiveGate version 1.299.0 or higher.

Full version history

🚀 Improved in this version:

  • Improved logging when no Snyk organizations are found.

ℹ️ This version requires ActiveGate version 1.299.0 or higher.

Full version history

✨ New in this version:

  • Added five ready-made dashboards which are deployed upon installing the extension.

🚀 Improved in this version:

  • It is now possible to separately toggle audit log and security events ingest.

⚠️ Breaking change -- This change requires monitoring configurations to be recreated upon upgrading the extension as the auto-update will fail ⚠️

🪲 Fixed in this version:

  • Fixed bug where an organization with no projects would cause the extension to crash.
  • Fixed bug where container image digest would not be properly reported for scan events.

ℹ️ This version requires ActiveGate version 1.299.0 or higher.

Full version history

  • Improvements to avoid memory-usage issues when working with a large number of projects

Full version history

🪲 Fixed in this version:

  • When container related findings are reported, the container ID is reported as well as the container digest, since the digest is sometimes not available. Since this fix requires access to a new API, the permissions required have been updated. Please refer to the official documentation.

ℹ️ This version requires ActiveGate version 1.299.0 or higher.

Full version history

🪲 Fixed in this version:

  • The Dynatrace severity score for vulnerability findings is now mapped from the severity level provided by Snyk instead of the CVSS score, due to a misalignment between the two.

ℹ️ This version requires ActiveGate version 1.299.0 or higher.

Full version history

✨ New in this version:

  • Added vulnerability finding and scan event monitoring.
  • Added audit log monitoring.

ℹ️ This version requires ActiveGate version 1.299.0 or higher.

Dynatrace Hub
Hub HomeBuild your own app
Dynatrace Intelligence - Agentic Operations SystemThe Dynatrace Agentic AI ecosystem
All (914)Log Management and AnalyticsKubernetesAI and LLM ObservabilityInfrastructure ObservabilitySoftware DeliveryApplication ObservabilityApplication SecurityBusiness ObservabilityDigital Experience
Filter
Type
Built and maintained by
Deployment model
SaaS
  • SaaS
  • Managed
Partner FinderBecome a partnerDynatrace Developer

Get data into Dynatrace

Dynatrace supports a wide range of methods for data ingestion. Below are some of the most popular ways to get data into Dynatrace and start observing your whole environment.

Start observing

Hyperscalers

Hyperscalers

Dynatrace seamlessly integrates with all of your hyperscalers and cloud environments.
Read more
OpenTelemetry

OpenTelemetry

Ingest OpenTelemetry traces & metrics, pin them to a dashboard, set alarms, analyze them in the context of metric, log, and diagnostic data.
Read more
OpenPipeline

OpenPipeline

Ingest, process and persist your observability, business and security data from any source in any format and any scale.
Read more

Ingest data using Dynatrace technology

Automatically collects all observability signals with OneAgent, monitor remote extensions, or stay flexible with our versatile API ingest.

OneAgent logo

OneAgent

The simplest way to capture all observation signals automatically and in context.

ActiveGate logo

ActiveGate

Route traffic, monitor clouds and remote technologies & run Synthetic monitors.

Custom Data ingest via API logo

Custom Data ingest via API

Extend Dynatrace with custom ingest APIs.

Get data using these popular technologies

OpenTelemetry logo

OpenTelemetry

Ingest and analyze OTel traces & metrics, set health alerts & view in context.

Prometheus logo

Prometheus

Unlock Prometheus power with intelligent analytics and automated insights.

Micrometer logo

Micrometer

Ingest Spring metrics and put them in context of trace, log and diagnostics data.

Telegraf logo

Telegraf

Monitor hundreds of Telegraf provided plugins and metrics with Dynatrace.

OpenTracing logo

OpenTracing

Ingest and chart OpenTracing data, set alerts, and analyze everything in the context of traces, metrics, logs, and diagnostics data.

StatsD logo

StatsD

The easiest way to get your custom application metrics into Dynatrace.

Stream Log Data

Use these popular Open Source data processing pipelines.

Logstash logo

Logstash

Stream log data from Logstash and analyze it in Dynatrace.

Fluentd logo

Fluentd

Stream log data to Dynatrace via Fluentd for analysis.

Fluent Bit logo

Fluent Bit

Stream logs to Dynatrace via Fluent Bit for analysis and AI observability.

Get data from container platforms

Seamlessly monitor and trace requests of microservices in your container platforms.

See more (5)
Docker logo

Docker

Automated distributed tracing and metrics for microservices running in Docker.

OpenShift Control Plane logo

OpenShift Control Plane

Get insights into your OpenShift control plane with metrics from its components.

containerd logo

containerd

Distributed tracing and metrics for services in containerd in Kubernetes.

VMware Tanzu logo

VMware Tanzu

Harness automation and AI to simplify Kubernetes observability at scale.

Cloud Foundry logo

Cloud Foundry

Harness automation and AI to simplify observability on Cloud Foundry at scale.

Pivotal Platform logo

Pivotal Platform

Multi-cloud platform for the deployment, management, and continuous delivery of applications. Pivotal is now VMware Tanzu.

Get real user monitoring data from mobile and web applications

iOS logo

iOS

Optimize iOS app performance with real-time monitoring and UX insights.

Android logo

Android

Monitor Android app stability, performance, and usage in real-time.

React Native logo

React Native

Monitor mobile applications built with React Native running on iOS or Android.

Mobile logo

Mobile

Analyze real user monitoring data of mobile apps in context with the backend.

OneAgent logo

OneAgent

The simplest way to capture all observation signals automatically and in context.

ActiveGate logo

ActiveGate

Route traffic, monitor clouds and remote technologies & run Synthetic monitors.

Get data from security products and tools

See more (18)
Amazon ECR logo

Amazon ECR

Ingest Amazon Elastic Container Registry vulnerability findings and scan events.

Google Artifact Registry logo

Google Artifact Registry

Ingest Google Artifact Registry vulnerability findings.

OCSF logo

OCSF

Ingest security findings in Open Cybersecurity Schema Framework (OCSF) format.

Tenable logo

Tenable

Ingest Tenable vulnerability findings, scan events, and audit logs.

Snyk logo

Snyk

Ingest Snyk vulnerability findings, scans, and audit logs.

Sonatype Lifecycle logo

Sonatype Lifecycle

Ingest Sonatype vulnerability findings, scans, and audit logs.

Are you looking for something different?

We have hundreds of apps, extensions, and other technologies to customize your environment