Dd Audit

by datadog-labs5b40c73824ecNo license177 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Audit Trail investigations - who changed what, key compromise, cost spike root cause, compliance evidence (SOC 2/PCI), and AI activity auditing.

AI-generated overview

Investigates Datadog Audit Trail logs for user activity, key compromise, cost spikes, compliance evidence, and AI activity.

What it does
This skill guides an agent through investigating Datadog Audit Trail events using the pup audit-logs command-line tool. It covers five sub-skills: security investigation of who changed what, API key compromise checks, cost spike root cause analysis, compliance evidence reports such as SOC 2 and PCI, and AI activity auditing. It supplies the event schema, Lucene-style search syntax, retention limits, and troubleshooting guidance needed to run and interpret queries.
When to use it
Use it when you need to answer questions about who changed a Datadog resource, whether an API key was compromised, why usage or LLM costs spiked, or what an AI assistant or MCP tool calls did. It also fits producing audit evidence for compliance auditors.
Requirements
Requires the pup CLI with Datadog authentication, either via pup auth login (OAuth2) or DD_API_KEY and DD_APP_KEY with the audit_logs_read scope, plus network access to Datadog. Queries beyond the default 90-day retention need archive configuration. Ships no scripts; instructions only.

Datadog Audit Trail

Investigate user activity, configuration changes, access patterns, and compliance evidence using pup audit-logs.

Sub-Skills

Sub-skillUse when
security-investigation"Who changed X?", "What did this user do?", "Show me deletions in the last 24h"
key-compromise"Was this API key compromised?", "What did key XYZ do?", "Investigate suspicious key activity"
cost-spike-investigation"Why did my bill go up?", "What caused this usage spike?", "Investigate LLM cost increase"
compliance-report"Generate SOC 2 evidence", "PCI audit log", "User provisioning report for auditor"
ai-activity-audit"What did the AI assistant do?", "Audit MCP tool calls", "AI governance report"

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Commands

bash
# List recent eventspup audit-logs list --from 1h --limit 100
# Search with a querypup audit-logs search --query "@action:deleted" --from 24h
# JSON output for piping to jqpup audit-logs search --query "@usr.email:[email protected]" --from 7d -o json | jq '.data[].attributes'

Event Schema Quick Reference

FieldDescriptionExample values
@usr.emailActor email[email protected]
@evt.actor.typeHow action was takenUSER, API_KEY, SUPPORT_USER
@actionVerbcreated, modified, deleted, accessed, login
@evt.nameEvent categoryDashboard, Monitor, Authentication, Access Management
@asset.typeResource typedashboard, monitor, api_key, role, user
@asset.idResource identifierabc-123
@metadata.api_key.idAPI key used (if applicable)key_abc123
@metadata.app_key.idApp key used (if applicable)app_abc123
@network.client.ipClient IP address1.2.3.4
@network.client.geoip.country.nameCountryUnited States
@network.client.geoip.as.nameASN nameAmazon.com
@http.url_details.pathAPI endpoint path/api/v1/dashboard/xyz

Search Syntax

Same Lucene-style syntax as Log Explorer:

QueryMeaning
@evt.name:DashboardExact field match
@action:deletedAction filter
@usr.email:[email protected]Specific user
@evt.name:Monitor AND @action:modifiedCompound
-@action:deletedNegation
@usr.email:*Field exists
@network.client.ip:1.2.3.4IP filter

Retention

Default retention is 90 days. If querying beyond 90 days, archive to S3/GCS/Azure Blob must be configured. Always check whether the requested time window falls within retention before running a query.

Troubleshooting

ProblemCauseFix
403 ForbiddenMissing audit_logs_read scopeAdd scope to app key in Datadog UI
Empty resultsTime window outside retentionCheck archive config; default max is 90 days
TimeoutQuery too broadNarrow time window or add more filters
No IP dataInternal action or pre-enrichment eventNot all events have geo data

References

Source and attribution

Source:datadog-labs/agent-skillsindd-auditat commit5b40c73

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal