dd-audit

작성자: datadog-labs

감사 추적 조사 - 누가 무엇을 변경했는지, 키 손상, 비용 급증 근본 원인, 규정 준수 증거(SOC 2/PCI), AI 활동 감사.

npx skills add https://github.com/datadog-labs/agent-skills --skill dd-audit

Datadog Audit Trail

Investigate user activity, configuration changes, access patterns, and compliance evidence using pup audit-logs.

Sub-Skills

Sub-skillUse when
security-investigation"Who changed X?", "What did this user do?", "Show me deletions in the last 24h"
key-compromise"Was this API key compromised?", "What did key XYZ do?", "Investigate suspicious key activity"
cost-spike-investigation"Why did my bill go up?", "What caused this usage spike?", "Investigate LLM cost increase"
compliance-report"Generate SOC 2 evidence", "PCI audit log", "User provisioning report for auditor"
ai-activity-audit"What did the AI assistant do?", "Audit MCP tool calls", "AI governance report"

Prerequisites

pup auth login   # OAuth2 (recommended)
# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Commands

# List recent events
pup audit-logs list --from 1h --limit 100

# Search with a query
pup audit-logs search --query "@action:deleted" --from 24h

# JSON output for piping to jq
pup audit-logs search --query "@usr.email:alice@example.com" --from 7d -o json | jq '.data[].attributes'

Event Schema Quick Reference

FieldDescriptionExample values
@usr.emailActor emailalice@example.com
@evt.actor.typeHow action was takenUSER, API_KEY, SUPPORT_USER
@actionVerbcreated, modified, deleted, accessed, login
@evt.nameEvent categoryDashboard, Monitor, Authentication, Access Management
@asset.typeResource typedashboard, monitor, api_key, role, user
@asset.idResource identifierabc-123
@metadata.api_key.idAPI key used (if applicable)key_abc123
@metadata.app_key.idApp key used (if applicable)app_abc123
@network.client.ipClient IP address1.2.3.4
@network.client.geoip.country.nameCountryUnited States
@network.client.geoip.as.nameASN nameAmazon.com
@http.url_details.pathAPI endpoint path/api/v1/dashboard/xyz

Search Syntax

Same Lucene-style syntax as Log Explorer:

QueryMeaning
@evt.name:DashboardExact field match
@action:deletedAction filter
@usr.email:alice@example.comSpecific user
@evt.name:Monitor AND @action:modifiedCompound
-@action:deletedNegation
@usr.email:*Field exists
@network.client.ip:1.2.3.4IP filter

Retention

Default retention is 90 days. If querying beyond 90 days, archive to S3/GCS/Azure Blob must be configured. Always check whether the requested time window falls within retention before running a query.

Troubleshooting

ProblemCauseFix
403 ForbiddenMissing audit_logs_read scopeAdd scope to app key in Datadog UI
Empty resultsTime window outside retentionCheck archive config; default max is 90 days
TimeoutQuery too broadNarrow time window or add more filters
No IP dataInternal action or pre-enrichment eventNot all events have geo data

References

datadog-labs의 다른 스킬

agent-install
datadog-labs
Datadog Operator를 사용하여 Kubernetes에 Datadog Agent를 설치합니다 — Single Step Instrumentation(SSI)을 활성화하기 전에 필요하며, 이는 자동으로…
official
agent-observability-auto-experiment
datadog-labs
실제 Datadog LLM-Obs 데이터를 대상으로 반복적 코드 개선 힐클라임을 로컬에서 Claude Code를 에이전트로 사용하여 실행합니다. 기준 평가를 설정하고, 하나의…
official
agent-observability-eval-bootstrap
datadog-labs
프로덕션 트레이스에서 평가자를 부트스트랩합니다 — 기본적으로 온라인 LLM-판정 평가자를 제안하고, 확인 후 Datadog에 비활성화된 초안으로 생성합니다…
official
agent-observability-eval-pipeline
datadog-labs
계측된 ml_app을 위한 엔드투엔드 에이전트 관측성 파이프라인 — 프로덕션 트레이스를 분류하고, 실패의 근본 원인을 분석하며, 평가기를 부트스트랩한 다음, (선택적으로)…
official
agent-observability-experiment-analyzer
datadog-labs
LLM 실험 결과를 분석합니다. 단일 또는 비교 실험, 탐색적 또는 Q&A 모드를 처리합니다. 사용자가 "실험 분석", "비교…"라고 말할 때 사용하세요.
official
agent-observability-replay-trace
datadog-labs
개발자가 마음에 들지 않는 출력을 생성한 특정 Agent Observability / LLM Obs 트레이스 하나를 반복 작업하고자 할 때 사용합니다 — 해당 트레이스를 다시 실행하여…
official
agent-observability-trace-rca
datadog-labs
프로덕션 LLM 트레이스에 대한 근본 원인 분석. LLM 애플리케이션이 실패하는 이유를 진단하며, 평가 판정, 런타임 오류 또는 구조적 문제를 기반으로 작동합니다…
official
agent-skills
datadog-labs
AI 에이전트를 위한 Datadog 스킬. 필수적인 모니터링, 로깅, 트레이싱 및 관찰 가능성.
official