monitor.datadog
[ Introduction ] [ Valid tags and data tables ] [ Table structure ]
Introduction
The tags beginning with monitor.datadog
identify events generated by Datadog.
Valid tags and data tables
The full tag must have three levels. The first two are fixed as monitor.datadog
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Datadog Unified Observability and Security |
|
|
|
| |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables:
monitor.datadog.archival
Field | Type | Extra field | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
|
|
|
|
hostname |
|
|
|
|
account |
|
|
|
|
id |
|
|
|
|
date |
|
|
|
|
attributes__aws__firehose__arn |
|
|
|
|
attributes__aws__s3__bucket |
|
|
|
|
attributes__aws__s3__key |
|
|
|
|
attributes__aws__invoked_function_arn |
|
|
|
|
attributes__aws__arn |
|
|
|
|
attributes__aws__function_version |
|
|
|
|
attributes__syslog__severity |
|
|
|
|
attributes__syslog__hostname |
|
|
|
|
attributes__syslog__appname |
|
|
|
|
attributes__syslog__prival |
|
|
|
|
attributes__syslog__facility |
|
|
|
|
attributes__syslog__version |
|
|
|
|
attributes__syslog__timestamp |
|
|
|
|
attributes__duration |
|
|
|
|
attributes__service |
|
|
|
|
attributes__host |
|
|
|
|
attributes__http__protocol |
|
|
|
|
attributes__http__status_code |
|
|
|
|
attributes__http__url_details__scheme |
|
|
|
|
attributes__http__url_details__host |
|
|
|
|
attributes__http__url_details__port |
|
|
|
|
attributes__http__url_details__path |
|
|
|
|
attributes__http__method |
|
|
|
|
attributes__http__status_category |
|
|
|
|
attributes__http__useragent |
|
|
|
|
attributes__http__version |
|
|
|
|
attributes__http__ssl__cipher |
|
|
|
|
attributes__http__ssl__protocol |
|
|
|
|
attributes__http__useragent_details__os__family |
|
|
|
|
attributes__http__useragent_details__browser__major |
|
|
|
|
attributes__http__useragent_details__browser__family |
|
|
|
|
attributes__http__useragent_details__device__model |
|
|
|
|
attributes__http__useragent_details__device__family |
|
|
|
|
attributes__http__useragent_details__device__category |
|
|
|
|
attributes__http__useragent_details__device__brand |
|
|
|
|
attributes__http__url |
|
|
|
|
attributes__TraceId |
|
|
|
|
attributes__elb__performance__response_processing_time |
|
|
|
|
attributes__elb__performance__request_processing_time |
|
|
|
|
attributes__elb__performance__backend_processing_time |
|
|
|
|
attributes__elb__backend_status_code |
|
|
|
|
attributes__elb__name |
|
|
|
|
attributes__date_access |
|
|
|
|
attributes__network__bytes_written |
|
|
|
|
attributes__network__destination__port |
|
|
|
|
attributes__network__destination__ip |
|
|
|
|
attributes__network__client__port |
|
|
|
|
attributes__network__client__ip |
|
|
|
|
attributes__network__bytes_read |
|
|
|
|
source |
|
|
|
|
message |
|
|
|
|
service |
|
|
|
|
status |
|
|
|
|
tags_str |
|
| join(tags, ',') | tags |
host |
|
|
|
|
hostchain |
| ✓ |
|
|
tag |
| ✓ |
|
|
rawMessage |
| ✓ |
|
|
monitor.datadog.event
Field | Type | Extra field |
---|---|---|
eventdate |
|
|
hostname |
|
|
date_happened |
|
|
alert_type |
|
|
is_aggregate |
|
|
title |
|
|
url |
|
|
text |
|
|
tags |
|
|
comments |
|
|
children |
|
|
priority |
|
|
source |
|
|
host |
|
|
resource |
|
|
device_name |
|
|
id |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.datadog.monitor
Field | Type | Extra Label |
---|---|---|
eventdate |
|
|
hostname |
|
|
restricted_roles |
|
|
tags |
|
|
deleted |
|
|
query |
|
|
message |
|
|
matching_downtimes |
|
|
id |
|
|
multi |
|
|
name |
|
|
created |
|
|
created_at |
|
|
creator__id |
|
|
creator__handle |
|
|
creator__name |
|
|
creator__email |
|
|
org_id |
|
|
modified |
|
|
overall_state_modified |
|
|
overall_state |
|
|
type |
|
|
options__notify_audit |
|
|
options__locked |
|
|
options__timeout_h |
|
|
options__silenced |
|
|
options__include_tags |
|
|
options__no_data_timeframe |
|
|
options__require_full_window |
|
|
options__new_host_delay |
|
|
options__notify_no_data |
|
|
options__renotify_interval |
|
|
options__escalation_message |
|
|
options__thresholds__critical |
|
|
options__thresholds__warning |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |