monitor.datadog
[ Introduction ] [ Valid tags and data tables ] [ Table structure ]
Introduction
The tags beginning with monitor.datadog
identify events generated by Datadog.
Valid tags and data tablesÂ
The full tag must have three levels. The first two are fixed as monitor.datadog
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Datadog Unified Observability and Security |
|
|
|
| |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables:
monitor.datadog.archival
Field | Type | Extra field | Field transformation | Source field name |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
hostname |
| Â | Â | Â |
account |
| Â | Â | Â |
id |
| Â | Â | Â |
date |
| Â | Â | Â |
attributes__aws__firehose__arn |
| Â | Â | Â |
attributes__aws__s3__bucket |
| Â | Â | Â |
attributes__aws__s3__key |
| Â | Â | Â |
attributes__aws__invoked_function_arn |
| Â | Â | Â |
attributes__aws__arn |
| Â | Â | Â |
attributes__aws__function_version |
| Â | Â | Â |
attributes__syslog__severity |
| Â | Â | Â |
attributes__syslog__hostname |
| Â | Â | Â |
attributes__syslog__appname |
| Â | Â | Â |
attributes__syslog__prival |
| Â | Â | Â |
attributes__syslog__facility |
| Â | Â | Â |
attributes__syslog__version |
| Â | Â | Â |
attributes__syslog__timestamp |
| Â | Â | Â |
attributes__duration |
| Â | Â | Â |
attributes__service |
| Â | Â | Â |
attributes__host |
| Â | Â | Â |
attributes__http__protocol |
| Â | Â | Â |
attributes__http__status_code |
| Â | Â | Â |
attributes__http__url_details__scheme |
| Â | Â | Â |
attributes__http__url_details__host |
| Â | Â | Â |
attributes__http__url_details__port |
| Â | Â | Â |
attributes__http__url_details__path |
| Â | Â | Â |
attributes__http__method |
| Â | Â | Â |
attributes__http__status_category |
| Â | Â | Â |
attributes__http__useragent |
| Â | Â | Â |
attributes__http__version |
| Â | Â | Â |
attributes__http__ssl__cipher |
| Â | Â | Â |
attributes__http__ssl__protocol |
| Â | Â | Â |
attributes__http__useragent_details__os__family |
| Â | Â | Â |
attributes__http__useragent_details__browser__major |
| Â | Â | Â |
attributes__http__useragent_details__browser__family |
| Â | Â | Â |
attributes__http__useragent_details__device__model |
| Â | Â | Â |
attributes__http__useragent_details__device__family |
| Â | Â | Â |
attributes__http__useragent_details__device__category |
| Â | Â | Â |
attributes__http__useragent_details__device__brand |
| Â | Â | Â |
attributes__http__url |
| Â | Â | Â |
attributes__TraceId |
| Â | Â | Â |
attributes__elb__performance__response_processing_time |
| Â | Â | Â |
attributes__elb__performance__request_processing_time |
| Â | Â | Â |
attributes__elb__performance__backend_processing_time |
| Â | Â | Â |
attributes__elb__backend_status_code |
| Â | Â | Â |
attributes__elb__name |
| Â | Â | Â |
attributes__date_access |
| Â | Â | Â |
attributes__network__bytes_written |
| Â | Â | Â |
attributes__network__destination__port |
| Â | Â | Â |
attributes__network__destination__ip |
| Â | Â | Â |
attributes__network__client__port |
| Â | Â | Â |
attributes__network__client__ip |
| Â | Â | Â |
attributes__network__bytes_read |
| Â | Â | Â |
source |
| Â | Â | Â |
message |
| Â | Â | Â |
service |
| Â | Â | Â |
status |
| Â | Â | Â |
tags_str |
| Â | join(tags, ',') | tags |
host |
| Â | Â | Â |
hostchain |
| ✓ |  |  |
tag |
| ✓ |  |  |
rawMessage |
| ✓ |  |  |
monitor.datadog.event
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
date_happened |
| Â |
alert_type |
| Â |
is_aggregate |
| Â |
title |
| Â |
url |
| Â |
text |
| Â |
tags |
| Â |
comments |
| Â |
children |
| Â |
priority |
| Â |
source |
| Â |
host |
| Â |
resource |
| Â |
device_name |
| Â |
id |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
monitor.datadog.monitor
Field | Type | Extra Label |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
restricted_roles |
| Â |
tags |
| Â |
deleted |
| Â |
query |
| Â |
message |
| Â |
matching_downtimes |
| Â |
id |
| Â |
multi |
| Â |
name |
| Â |
created |
| Â |
created_at |
| Â |
creator__id |
| Â |
creator__handle |
| Â |
creator__name |
| Â |
creator__email |
| Â |
org_id |
| Â |
modified |
| Â |
overall_state_modified |
| Â |
overall_state |
| Â |
type |
| Â |
options__notify_audit |
| Â |
options__locked |
| Â |
options__timeout_h |
| Â |
options__silenced |
| Â |
options__include_tags |
| Â |
options__no_data_timeframe |
| Â |
options__require_full_window |
| Â |
options__new_host_delay |
| Â |
options__notify_no_data |
| Â |
options__renotify_interval |
| Â |
options__escalation_message |
| Â |
options__thresholds__critical |
| Â |
options__thresholds__warning |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |