dd-audit

Điều tra dấu vết kiểm toán - ai đã thay đổi cái gì, xâm phạm khóa, nguyên nhân gốc rễ của sự tăng vọt chi phí, bằng chứng tuân thủ (SOC 2/PCI) và kiểm toán hoạt động AI.

npx skills add https://github.com/datadog-labs/agent-skills --skill dd-audit

Datadog Audit Trail

Investigate user activity, configuration changes, access patterns, and compliance evidence using pup audit-logs.

Sub-Skills

Sub-skillUse when
security-investigation"Who changed X?", "What did this user do?", "Show me deletions in the last 24h"
key-compromise"Was this API key compromised?", "What did key XYZ do?", "Investigate suspicious key activity"
cost-spike-investigation"Why did my bill go up?", "What caused this usage spike?", "Investigate LLM cost increase"
compliance-report"Generate SOC 2 evidence", "PCI audit log", "User provisioning report for auditor"
ai-activity-audit"What did the AI assistant do?", "Audit MCP tool calls", "AI governance report"

Prerequisites

pup auth login   # OAuth2 (recommended)
# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Commands

# List recent events
pup audit-logs list --from 1h --limit 100

# Search with a query
pup audit-logs search --query "@action:deleted" --from 24h

# JSON output for piping to jq
pup audit-logs search --query "@usr.email:alice@example.com" --from 7d -o json | jq '.data[].attributes'

Event Schema Quick Reference

FieldDescriptionExample values
@usr.emailActor emailalice@example.com
@evt.actor.typeHow action was takenUSER, API_KEY, SUPPORT_USER
@actionVerbcreated, modified, deleted, accessed, login
@evt.nameEvent categoryDashboard, Monitor, Authentication, Access Management
@asset.typeResource typedashboard, monitor, api_key, role, user
@asset.idResource identifierabc-123
@metadata.api_key.idAPI key used (if applicable)key_abc123
@metadata.app_key.idApp key used (if applicable)app_abc123
@network.client.ipClient IP address1.2.3.4
@network.client.geoip.country.nameCountryUnited States
@network.client.geoip.as.nameASN nameAmazon.com
@http.url_details.pathAPI endpoint path/api/v1/dashboard/xyz

Search Syntax

Same Lucene-style syntax as Log Explorer:

QueryMeaning
@evt.name:DashboardExact field match
@action:deletedAction filter
@usr.email:alice@example.comSpecific user
@evt.name:Monitor AND @action:modifiedCompound
-@action:deletedNegation
@usr.email:*Field exists
@network.client.ip:1.2.3.4IP filter

Retention

Default retention is 90 days. If querying beyond 90 days, archive to S3/GCS/Azure Blob must be configured. Always check whether the requested time window falls within retention before running a query.

Troubleshooting

ProblemCauseFix
403 ForbiddenMissing audit_logs_read scopeAdd scope to app key in Datadog UI
Empty resultsTime window outside retentionCheck archive config; default max is 90 days
TimeoutQuery too broadNarrow time window or add more filters
No IP dataInternal action or pre-enrichment eventNot all events have geo data

References

Thêm skills từ datadog-labs

agent-install
datadog-labs
Install the Datadog Agent on Kubernetes using the Datadog Operator — required before enabling Single Step Instrumentation (SSI), which automatically…
official
agent-observability-auto-experiment
datadog-labs
Chạy leo đồi cải thiện mã lặp đi lặp lại dựa trên dữ liệu Datadog LLM-Obs thực tế, cục bộ, với Claude Code làm tác nhân. Thiết lập đánh giá cơ sở, thực hiện một…
official
agent-observability-eval-bootstrap
datadog-labs
Khởi tạo bộ đánh giá từ dấu vết sản xuất — theo mặc định đề xuất bộ đánh giá LLM-judge trực tuyến và, sau khi bạn xác nhận, tạo chúng trong Datadog dưới dạng bản nháp bị vô hiệu hóa…
official
agent-observability-eval-pipeline
datadog-labs
Đường ống quan sát Agent từ đầu đến cuối cho ml_app được instrument hóa — phân loại các trace production, truy tìm nguyên nhân gốc rễ của sự cố, khởi tạo các bộ đánh giá, sau đó (tùy chọn)…
official
agent-observability-experiment-analyzer
datadog-labs
Phân tích kết quả thử nghiệm LLM. Xử lý các thử nghiệm đơn lẻ hoặc so sánh, chế độ khám phá hoặc hỏi đáp. Sử dụng khi người dùng nói "phân tích thử nghiệm", "so sánh…
official
agent-observability-replay-trace
datadog-labs
Sử dụng khi nhà phát triển muốn lặp lại trên MỘT trace Agent Observability / LLM Obs cụ thể mà họ không hài lòng với kết quả đầu ra — chạy lại trace đó với…
official
agent-observability-trace-rca
datadog-labs
Phân tích nguyên nhân gốc rễ trên các dấu vết LLM trong production. Chẩn đoán lý do ứng dụng LLM gặp lỗi — hoạt động từ phán quyết của bộ đánh giá, lỗi runtime, hoặc các vấn đề cấu trúc…
official
agent-skills
datadog-labs
Kỹ năng Datadog cho các tác tử AI. Giám sát, ghi nhật ký, theo dõi và quan sát thiết yếu.
official