Dd Audit

作者 datadog-labs5b40c73824ec无许可证177 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Audit Trail investigations - who changed what, key compromise, cost spike root cause, compliance evidence (SOC 2/PCI), and AI activity auditing.

AI 生成的概览

调查 Datadog Audit Trail 日志,涵盖用户活动、密钥泄露、成本激增、合规证据和 AI 活动审计。

功能
该技能指导代理使用 pup audit-logs 命令行工具调查 Datadog Audit Trail 事件。它包含五个子技能:调查谁更改了什么的安全调查、API 密钥泄露排查、成本激增根因分析、SOC 2 和 PCI 等合规证据报告,以及 AI 活动审计。它提供事件字段结构、Lucene 风格搜索语法、保留期限和故障排查说明,用于执行和解读查询。
适用场景
当需要回答谁更改了 Datadog 资源、某个 API 密钥是否泄露、用量或 LLM 成本为何激增,或 AI 助手与 MCP 工具调用做了什么时使用。它也适用于为合规审计人员生成审计证据。
运行要求
需要 pup CLI 并完成 Datadog 身份验证,可通过 pup auth login(OAuth2)或设置具有 audit_logs_read 权限的 DD_API_KEY 与 DD_APP_KEY,同时需要访问 Datadog 的网络。查询超过默认 90 天保留期的数据需配置归档。不包含脚本,仅为说明文档。

Datadog Audit Trail

Investigate user activity, configuration changes, access patterns, and compliance evidence using pup audit-logs.

Sub-Skills

Sub-skillUse when
security-investigation"Who changed X?", "What did this user do?", "Show me deletions in the last 24h"
key-compromise"Was this API key compromised?", "What did key XYZ do?", "Investigate suspicious key activity"
cost-spike-investigation"Why did my bill go up?", "What caused this usage spike?", "Investigate LLM cost increase"
compliance-report"Generate SOC 2 evidence", "PCI audit log", "User provisioning report for auditor"
ai-activity-audit"What did the AI assistant do?", "Audit MCP tool calls", "AI governance report"

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Commands

bash
# List recent eventspup audit-logs list --from 1h --limit 100
# Search with a querypup audit-logs search --query "@action:deleted" --from 24h
# JSON output for piping to jqpup audit-logs search --query "@usr.email:[email protected]" --from 7d -o json | jq '.data[].attributes'

Event Schema Quick Reference

FieldDescriptionExample values
@usr.emailActor email[email protected]
@evt.actor.typeHow action was takenUSER, API_KEY, SUPPORT_USER
@actionVerbcreated, modified, deleted, accessed, login
@evt.nameEvent categoryDashboard, Monitor, Authentication, Access Management
@asset.typeResource typedashboard, monitor, api_key, role, user
@asset.idResource identifierabc-123
@metadata.api_key.idAPI key used (if applicable)key_abc123
@metadata.app_key.idApp key used (if applicable)app_abc123
@network.client.ipClient IP address1.2.3.4
@network.client.geoip.country.nameCountryUnited States
@network.client.geoip.as.nameASN nameAmazon.com
@http.url_details.pathAPI endpoint path/api/v1/dashboard/xyz

Search Syntax

Same Lucene-style syntax as Log Explorer:

QueryMeaning
@evt.name:DashboardExact field match
@action:deletedAction filter
@usr.email:[email protected]Specific user
@evt.name:Monitor AND @action:modifiedCompound
-@action:deletedNegation
@usr.email:*Field exists
@network.client.ip:1.2.3.4IP filter

Retention

Default retention is 90 days. If querying beyond 90 days, archive to S3/GCS/Azure Blob must be configured. Always check whether the requested time window falls within retention before running a query.

Troubleshooting

ProblemCauseFix
403 ForbiddenMissing audit_logs_read scopeAdd scope to app key in Datadog UI
Empty resultsTime window outside retentionCheck archive config; default max is 90 days
TimeoutQuery too broadNarrow time window or add more filters
No IP dataInternal action or pre-enrichment eventNot all events have geo data

References

来源与署名

来源:datadog-labs/agent-skills位于dd-audit提交5b40c73

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架