Dt Obs Log Semantic Mapping

by Dynatrace9529e72715d9Apache-2.0161 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 days ago

Suggest and validate semantic dictionary (SD) mappings for audit log integrations using raw vendor log payloads or live ingested events. Use when: mapping a vendor audit log feed, authentication logs, user activity logs to the Dynatrace SD; checking required semantic fields; proposing OpenPipeline processor extraction rules based on DQL; running runtime validation (fetches live logs by log.source, then applies static validation).

AI-generated overview

Suggests and validates Dynatrace semantic dictionary mappings for vendor audit and HTTP log integrations.

What it does
It maps raw vendor audit, authentication, authorization, user action and HTTP log payloads to Dynatrace semantic dictionary fields, and validates existing mappings against pasted ingested events or live tenant logs. It inventories buried versus promoted content fields, checks required fields and enum/type rules, and proposes OpenPipeline processor extraction rules written in DQL. Outputs include mapping tables, diff tables, OpenPipeline sketches and validation summaries.
When to use it
Use when onboarding a vendor audit log feed, authentication logs or user activity logs into the Dynatrace semantic dictionary, when checking whether required semantic fields are populated, or when validating a mapping against a pasted event or live tenant data. Also useful when proposing OpenPipeline extraction rules to promote buried fields. Suitable for sparse integrations such as GitHub or Sonatype that populate only core fields.
Requirements
Instructions only; no scripts. Requires the referenced files in references/ and samples/. Workflow B2 needs live Dynatrace tenant access to fetch logs by log.source. Proposing OpenPipeline extraction rules requires loading the dt-dql-essentials skill.

dt-obs-log-semantic-mapping

Build and validate semantic-dictionary-aligned mappings for audit log integrations.

Purpose

Use this skill when a user wants to:

  • Suggest a mapping from a raw vendor audit log payload to Dynatrace fetch logs fields (Workflow A).
  • Validate a mapping against a pasted ingested log event (Workflow B1 — static).
  • Validate against live tenant data via live tenant access (Workflow B2 — runtime: fetches logs by log.source, then runs B1 on the result).

Log Classes

ClassDescriptionKey namespacesExample sources
authenticationLogin, logout, MFA, tokenaudit.*, actor.*, browser.*, device.*CyberArk, Okta, Azure SignInLogs
authorizationAccess decisions, permission changesaudit.*, actor.*, object.*CyberArk, Okta
user_actionCRUD on platform resourcesaudit.*, actor.*, object.*, product.*Okta, GitHub, Sonatype
httpHTTP request/response (WAF, network devices)http.*, url.*, server.*, geo.*, client.*Akamai SIEM, Cloudflare

Workflows

ModeInputSource
Workflow A — Suggest mappingRaw vendor log payloadreferences/mapping-workflow.md § Workflow A
Workflow B1 — Static validationPasted ingested log eventreferences/mapping-workflow.md § Workflow B1
Workflow B2 — Runtime validationlog.source value + live tenant accessreferences/runtime-validation.md — fetches logs, then runs B1

Key Concepts

Content field burial: The primary validation concern. Fields in content (the raw vendor payload) that could be promoted to top-level semantic attributes but are not. The skill always inventories buried vs promoted fields and proposes OpenPipeline extraction rules to fix gaps.

Prerequisite: When proposing OpenPipeline processor extraction rules, load the dt-dql-essentials skill first. OpenPipeline processors use DQL functions (parse, fieldsAdd, splitString, etc.) — using non-DQL syntax produces invalid rules.

Sparse mappings are valid: Integrations like GitHub or Sonatype may only populate core fields. Minimum required: timestamp, log.source, content, loglevel, audit.action, audit.identity.

References

  • references/data-model-notes.md — Log SD field taxonomy, audit namespace, enums, sample-derived patterns and known discrepancies
  • references/mapping-workflow.md — Intake checklist, Workflow A and B1 procedures, content field analysis, field priority order
  • references/validation-rules.md — Required fields, content/enum/type rules, discrepancy severity
  • references/openpipeline-constraints.md — OpenPipeline processor command/function/operator/matcher restrictions; parseJson unavailability + parse→fieldsFlatten alternative; iterative operators for array casting
  • references/report-format.md — Mapping table, diff table, OpenPipeline sketch, Validation Summary templates
  • references/runtime-validation.md — Workflow B2: fetch live records, then run B1
  • samples/audit-logs.json — Mapped samples: CyberArk, Okta, Azure SignInLogs, Sonatype, GitHub
  • samples/http-logs.json — Mapped samples: Akamai SIEM (WAF/HTTP class)
  • Dynatrace Log Semantic Dictionary

Source and attribution

Source:Dynatrace/dynatrace-for-aiinskills/dt-obs-log-semantic-mappingat commit9529e72

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from Dynatrace/dynatrace-for-ai

Dt Setup React Native

Dynatrace

Integrate the Dynatrace React Native Plugin into a React Native or Expo project — dependency setup, dynatrace.config.js, Babel registration, npx instrumentation, navigation tracking, user privacy options, and verification. Handles both bare React Native and Expo (babel-preset-expo) Babel configuration automatically. Trigger: "add Dynatrace to React Native", "React Native plugin setup", "instrument React Native app", "integrate Dynatrace RN", "mobile observability React Native", "react-native-plugin", "dynatrace react native", "add Dynatrace to Expo", "instrument Expo app", "Dynatrace Expo setup". Do NOT use for: querying RN RUM data (use dt-obs-frontends), non-React Native mobile setups, or Dynatrace server-side configuration.

Awaiting classification161updated 7 days ago

Dt Setup Android

Dynatrace

Instruments an existing Android project with the Dynatrace Mobile Agent for basic monitoring.

DevOps & Cloud161updated 7 days ago

Dt Sec Contextualization

Dynatrace

Maps security findings and IoC matches to Dynatrace Smartscape runtime entities and correlates them across entity levels.

Security161updated 7 days ago

Dt Obs Services

Dynatrace

Guides Dynatrace DQL queries for monitoring service performance, RED metrics, service mesh, messaging, and runtime telemetry.

DevOps & Cloud161updated 7 days ago

Dt Obs Predictive Analytics

Dynatrace

Guides Dynatrace predictive analytics: forecasting, capacity saturation, trend and anomaly detection using DQL and analyzer tools.

Data & Analytics161updated 7 days ago

Dt Obs Logs

Dynatrace

Query, filter and analyze Dynatrace log data with DQL for troubleshooting and monitoring.

Data & Analytics161updated 7 days ago