Dd Logs

作者 datadog-labs5b40c73824ec无许可证177 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Log management - search, archives, metrics, and cost control.

仅含说明DevOps & Cloud
AI 生成的概览

通过 pup 命令行工具指导 Datadog 日志搜索、管道、归档、指标与成本控制排除规则。

功能
该技能提供通过 pup 命令行工具处理 Datadog 日志的操作说明。内容涵盖日志搜索查询与语法、日志配置 API(如归档、限制查询和自定义目标),以及用于成本控制的处理器与排除过滤器示例。它还介绍基于日志的指标、敏感数据脱敏规则和故障排查步骤,产出的是命令与配置片段而非文件。
适用场景
适用于搜索 Datadog 日志、配置日志管道或排除过滤器、设置归档或创建基于日志的指标。也适合在降低日志成本或从日志中脱敏敏感数据时使用。
运行要求
需要安装并认证 Datadog Pup 命令行工具(pup auth login),并拥有 Datadog 账户访问权限。需要访问 Datadog 的网络连接;该技能不附带脚本。

Datadog Logs

Search, process, and archive logs with cost awareness.

Prerequisites

Datadog Pup should already be installed. See Setup Pup if not.

Command Execution Order (Token-Efficient)

For scoped commands, use this order:

  1. Check context first (prior outputs, conversation, saved values).
  2. If a required value is missing, run a discovery command first.
  3. If still ambiguous, ask the user to confirm.
  4. Then run the target command.
  5. Avoid speculative commands likely to fail.

Quick Start

bash
pup auth login

Search Logs

bash
# Basic searchpup logs search --query="status:error" --from="1h"
# With filterspup logs search --query="service:api status:error" --from="1h" --limit 100
# JSON outputpup logs search --query="@http.status_code:>=500" --from="1h"

Search Syntax

QueryMeaning
errorFull-text search
status:errorTag equals
@http.status_code:500Attribute equals
@http.status_code:>=400Numeric range
service:api AND env:prodBoolean
@message:*timeout*Wildcard

Configuration APIs

Available log configuration commands in pup 0.42.0:

bash
# List log archivespup logs archives list
# List log restriction queriespup logs restriction-queries list
# List custom log destinationspup logs custom-destinations list

Common Processors

json
{  "name": "API Logs",  "filter": {"query": "service:api"},  "processors": [    {      "type": "grok-parser",      "name": "Parse nginx",      "source": "message",      "grok": {"match_rules": "%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}"}    },    {      "type": "status-remapper",      "name": "Set severity",      "sources": ["level", "severity"]    },    {      "type": "attribute-remapper",      "name": "Remap user_id",      "sources": ["user_id"],      "target": "usr.id"    }  ]}

Exclusion Filters (Cost Control)

Index only what matters:

json
{  "name": "Drop debug logs",  "filter": {"query": "status:debug"},  "is_enabled": true}

High-Volume Exclusions

bash
# Find noisiest log sourcespup logs search --query="*" --from="1h" | jq 'group_by(.service) | map({service: .[0].service, count: length}) | sort_by(-.count)[:10]'
ExcludeQuery
Health checks@http.url:"/health" OR @http.url:"/ready"
Debug logsstatus:debug
Static assets@http.url:*.css OR @http.url:*.js
Heartbeats@message:*heartbeat*

Archives

Store logs cheaply for compliance:

bash
# List archivespup logs archives list
# Archive config (S3 example){  "name": "compliance-archive",  "query": "*",  "destination": {    "type": "s3",    "bucket": "my-logs-archive",    "path": "/datadog"  },  "rehydration_tags": ["team:platform"]}

Rehydrate (Restore)

bash
# No `pup logs rehydrate` command in pup 0.42.0.# Use Datadog UI/API for rehydration workflows.

Log-Based Metrics

Create metrics from logs (cheaper than indexing):

bash
# List log-based metricspup logs metrics list
# Get one metric by IDpup logs metrics get api.errors.count

Cardinality warning: Group by bounded values only.

Sensitive Data

Scrubbing Rules

json
{  "type": "hash-remapper",  "name": "Hash emails",  "sources": ["email", "@user.email"]}

Never Log

python
# In your app - sanitize before sendingimport re
def sanitize_log(message: str) -> str:    # Remove credit cards    message = re.sub(r'\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b', '[REDACTED]', message)    # Remove SSNs    message = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED]', message)    return message

Troubleshooting

ProblemFix
Logs not appearingCheck agent, pipeline filters
High costsAdd exclusion filters
Search slowNarrow time range, use indexes
Missing attributesCheck grok parser

References/Documentation

来源与署名

来源:datadog-labs/agent-skills位于dd-logs提交5b40c73

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架