Dd Logs

by datadog-labs5b40c73824ecNo license177 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Log management - search, archives, metrics, and cost control.

Instructions onlyDevOps & Cloud
AI-generated overview

Guides Datadog log search, pipelines, archives, metrics, and cost-control exclusions via the pup CLI.

What it does
This skill provides instructions for working with Datadog logs through the pup command-line tool. It covers log search queries and syntax, log configuration APIs such as archives, restriction queries, and custom destinations, plus processor and exclusion-filter examples for cost control. It also describes log-based metrics, sensitive-data scrubbing rules, and troubleshooting steps, producing commands and configuration snippets rather than files.
When to use it
Use it when searching Datadog logs, configuring log pipelines or exclusion filters, setting up archives, or creating log-based metrics. It is also relevant when reducing logging costs or scrubbing sensitive data from logs.
Requirements
Requires the Datadog Pup CLI to be installed and authenticated (pup auth login), plus access to a Datadog account. Network access to Datadog is needed; no scripts ship with the skill.

Datadog Logs

Search, process, and archive logs with cost awareness.

Prerequisites

Datadog Pup should already be installed. See Setup Pup if not.

Command Execution Order (Token-Efficient)

For scoped commands, use this order:

  1. Check context first (prior outputs, conversation, saved values).
  2. If a required value is missing, run a discovery command first.
  3. If still ambiguous, ask the user to confirm.
  4. Then run the target command.
  5. Avoid speculative commands likely to fail.

Quick Start

bash
pup auth login

Search Logs

bash
# Basic searchpup logs search --query="status:error" --from="1h"
# With filterspup logs search --query="service:api status:error" --from="1h" --limit 100
# JSON outputpup logs search --query="@http.status_code:>=500" --from="1h"

Search Syntax

QueryMeaning
errorFull-text search
status:errorTag equals
@http.status_code:500Attribute equals
@http.status_code:>=400Numeric range
service:api AND env:prodBoolean
@message:*timeout*Wildcard

Configuration APIs

Available log configuration commands in pup 0.42.0:

bash
# List log archivespup logs archives list
# List log restriction queriespup logs restriction-queries list
# List custom log destinationspup logs custom-destinations list

Common Processors

json
{  "name": "API Logs",  "filter": {"query": "service:api"},  "processors": [    {      "type": "grok-parser",      "name": "Parse nginx",      "source": "message",      "grok": {"match_rules": "%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}"}    },    {      "type": "status-remapper",      "name": "Set severity",      "sources": ["level", "severity"]    },    {      "type": "attribute-remapper",      "name": "Remap user_id",      "sources": ["user_id"],      "target": "usr.id"    }  ]}

Exclusion Filters (Cost Control)

Index only what matters:

json
{  "name": "Drop debug logs",  "filter": {"query": "status:debug"},  "is_enabled": true}

High-Volume Exclusions

bash
# Find noisiest log sourcespup logs search --query="*" --from="1h" | jq 'group_by(.service) | map({service: .[0].service, count: length}) | sort_by(-.count)[:10]'
ExcludeQuery
Health checks@http.url:"/health" OR @http.url:"/ready"
Debug logsstatus:debug
Static assets@http.url:*.css OR @http.url:*.js
Heartbeats@message:*heartbeat*

Archives

Store logs cheaply for compliance:

bash
# List archivespup logs archives list
# Archive config (S3 example){  "name": "compliance-archive",  "query": "*",  "destination": {    "type": "s3",    "bucket": "my-logs-archive",    "path": "/datadog"  },  "rehydration_tags": ["team:platform"]}

Rehydrate (Restore)

bash
# No `pup logs rehydrate` command in pup 0.42.0.# Use Datadog UI/API for rehydration workflows.

Log-Based Metrics

Create metrics from logs (cheaper than indexing):

bash
# List log-based metricspup logs metrics list
# Get one metric by IDpup logs metrics get api.errors.count

Cardinality warning: Group by bounded values only.

Sensitive Data

Scrubbing Rules

json
{  "type": "hash-remapper",  "name": "Hash emails",  "sources": ["email", "@user.email"]}

Never Log

python
# In your app - sanitize before sendingimport re
def sanitize_log(message: str) -> str:    # Remove credit cards    message = re.sub(r'\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b', '[REDACTED]', message)    # Remove SSNs    message = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED]', message)    return message

Troubleshooting

ProblemFix
Logs not appearingCheck agent, pipeline filters
High costsAdd exclusion filters
Search slowNarrow time range, use indexes
Missing attributesCheck grok parser

References/Documentation

Source and attribution

Source:datadog-labs/agent-skillsindd-logsat commit5b40c73

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal