Dt Obs Log Semantic Mapping

作者 Dynatrace9529e72715d9Apache-2.0161 个星标收录于 2026年10月8日更新于 2026年10月8日仓库7天前更新

Suggest and validate semantic dictionary (SD) mappings for audit log integrations using raw vendor log payloads or live ingested events. Use when: mapping a vendor audit log feed, authentication logs, user activity logs to the Dynatrace SD; checking required semantic fields; proposing OpenPipeline processor extraction rules based on DQL; running runtime validation (fetches live logs by log.source, then applies static validation).

AI 生成的概览

为供应商审计与 HTTP 日志集成建议并验证 Dynatrace 语义字典映射。

功能
该技能将供应商的审计、认证、授权、用户操作和 HTTP 日志原始负载映射到 Dynatrace 语义字典字段,并针对粘贴的已摄取事件或租户实时日志验证现有映射。它会盘点被埋没与已提升的 content 字段,检查必需字段以及枚举和类型规则,并提出以 DQL 编写的 OpenPipeline 处理器提取规则。产出包括映射表、差异表、OpenPipeline 草图和验证摘要。
适用场景
适用于将供应商审计日志、认证日志或用户活动日志接入 Dynatrace 语义字典时,检查必需语义字段是否已填充时,或针对粘贴事件或租户实时数据验证映射时。也适用于提出 OpenPipeline 提取规则以提升被埋没字段的场景,例如仅填充核心字段的 GitHub 或 Sonatype 等稀疏集成。
运行要求
仅提供说明,不含脚本。需要 references/ 与 samples/ 下的参考文件。工作流 B2 需要 Dynatrace 租户的实时访问权限,以便按 log.source 获取日志。提出 OpenPipeline 提取规则前需先加载 dt-dql-essentials 技能。

dt-obs-log-semantic-mapping

Build and validate semantic-dictionary-aligned mappings for audit log integrations.

Purpose

Use this skill when a user wants to:

  • Suggest a mapping from a raw vendor audit log payload to Dynatrace fetch logs fields (Workflow A).
  • Validate a mapping against a pasted ingested log event (Workflow B1 — static).
  • Validate against live tenant data via live tenant access (Workflow B2 — runtime: fetches logs by log.source, then runs B1 on the result).

Log Classes

ClassDescriptionKey namespacesExample sources
authenticationLogin, logout, MFA, tokenaudit.*, actor.*, browser.*, device.*CyberArk, Okta, Azure SignInLogs
authorizationAccess decisions, permission changesaudit.*, actor.*, object.*CyberArk, Okta
user_actionCRUD on platform resourcesaudit.*, actor.*, object.*, product.*Okta, GitHub, Sonatype
httpHTTP request/response (WAF, network devices)http.*, url.*, server.*, geo.*, client.*Akamai SIEM, Cloudflare

Workflows

ModeInputSource
Workflow A — Suggest mappingRaw vendor log payloadreferences/mapping-workflow.md § Workflow A
Workflow B1 — Static validationPasted ingested log eventreferences/mapping-workflow.md § Workflow B1
Workflow B2 — Runtime validationlog.source value + live tenant accessreferences/runtime-validation.md — fetches logs, then runs B1

Key Concepts

Content field burial: The primary validation concern. Fields in content (the raw vendor payload) that could be promoted to top-level semantic attributes but are not. The skill always inventories buried vs promoted fields and proposes OpenPipeline extraction rules to fix gaps.

Prerequisite: When proposing OpenPipeline processor extraction rules, load the dt-dql-essentials skill first. OpenPipeline processors use DQL functions (parse, fieldsAdd, splitString, etc.) — using non-DQL syntax produces invalid rules.

Sparse mappings are valid: Integrations like GitHub or Sonatype may only populate core fields. Minimum required: timestamp, log.source, content, loglevel, audit.action, audit.identity.

References

  • references/data-model-notes.md — Log SD field taxonomy, audit namespace, enums, sample-derived patterns and known discrepancies
  • references/mapping-workflow.md — Intake checklist, Workflow A and B1 procedures, content field analysis, field priority order
  • references/validation-rules.md — Required fields, content/enum/type rules, discrepancy severity
  • references/openpipeline-constraints.md — OpenPipeline processor command/function/operator/matcher restrictions; parseJson unavailability + parse→fieldsFlatten alternative; iterative operators for array casting
  • references/report-format.md — Mapping table, diff table, OpenPipeline sketch, Validation Summary templates
  • references/runtime-validation.md — Workflow B2: fetch live records, then run B1
  • samples/audit-logs.json — Mapped samples: CyberArk, Okta, Azure SignInLogs, Sonatype, GitHub
  • samples/http-logs.json — Mapped samples: Akamai SIEM (WAF/HTTP class)
  • Dynatrace Log Semantic Dictionary

来源与署名

来源:Dynatrace/dynatrace-for-ai位于skills/dt-obs-log-semantic-mapping提交9529e72

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架