dt-obs-log-semantic-mapping
Build and validate semantic-dictionary-aligned mappings for audit log integrations.
Purpose
Use this skill when a user wants to:
- Suggest a mapping from a raw vendor audit log payload to Dynatrace
fetch logsfields (Workflow A). - Validate a mapping against a pasted ingested log event (Workflow B1 — static).
- Validate against live tenant data via live tenant access (Workflow B2 — runtime: fetches logs by
log.source, then runs B1 on the result).
Log Classes
Workflows
Key Concepts
Content field burial: The primary validation concern. Fields in content (the raw vendor payload) that could be promoted to top-level semantic attributes but are not. The skill always inventories buried vs promoted fields and proposes OpenPipeline extraction rules to fix gaps.
Prerequisite: When proposing OpenPipeline processor extraction rules, load the
dt-dql-essentialsskill first. OpenPipeline processors use DQL functions (parse,fieldsAdd,splitString, etc.) — using non-DQL syntax produces invalid rules.
Sparse mappings are valid: Integrations like GitHub or Sonatype may only populate core fields. Minimum required: timestamp, log.source, content, loglevel, audit.action, audit.identity.
References
references/data-model-notes.md— Log SD field taxonomy, audit namespace, enums, sample-derived patterns and known discrepanciesreferences/mapping-workflow.md— Intake checklist, Workflow A and B1 procedures, content field analysis, field priority orderreferences/validation-rules.md— Required fields, content/enum/type rules, discrepancy severityreferences/openpipeline-constraints.md— OpenPipeline processor command/function/operator/matcher restrictions;parseJsonunavailability +parse→fieldsFlattenalternative; iterative operators for array castingreferences/report-format.md— Mapping table, diff table, OpenPipeline sketch, Validation Summary templatesreferences/runtime-validation.md— Workflow B2: fetch live records, then run B1samples/audit-logs.json— Mapped samples: CyberArk, Okta, Azure SignInLogs, Sonatype, GitHubsamples/http-logs.json— Mapped samples: Akamai SIEM (WAF/HTTP class)- Dynatrace Log Semantic Dictionary

