Investigates Datadog Audit Trail logs for user activity, key compromise, cost spikes, compliance evidence, and AI activity.
- What it does
- This skill guides an agent through investigating Datadog Audit Trail events using the pup audit-logs command-line tool. It covers five sub-skills: security investigation of who changed what, API key compromise checks, cost spike root cause analysis, compliance evidence reports such as SOC 2 and PCI, and AI activity auditing. It supplies the event schema, Lucene-style search syntax, retention limits, and troubleshooting guidance needed to run and interpret queries.
- When to use it
- Use it when you need to answer questions about who changed a Datadog resource, whether an API key was compromised, why usage or LLM costs spiked, or what an AI assistant or MCP tool calls did. It also fits producing audit evidence for compliance auditors.
- Requirements
- Requires the pup CLI with Datadog authentication, either via pup auth login (OAuth2) or DD_API_KEY and DD_APP_KEY with the audit_logs_read scope, plus network access to Datadog. Queries beyond the default 90-day retention need archive configuration. Ships no scripts; instructions only.
Datadog Audit Trail
Investigate user activity, configuration changes, access patterns, and compliance evidence using pup audit-logs.
Sub-Skills
Prerequisites
Commands
Event Schema Quick Reference
Search Syntax
Same Lucene-style syntax as Log Explorer:
Retention
Default retention is 90 days. If querying beyond 90 days, archive to S3/GCS/Azure Blob must be configured. Always check whether the requested time window falls within retention before running a query.
Troubleshooting
References