Dd Logs

作者 datadog-labs5b40c73824ec無授權條款177 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Log management - search, archives, metrics, and cost control.

僅含說明DevOps & Cloud
AI 產生的概覽

透過 pup 命令列工具指導 Datadog 日誌搜尋、管道、封存、指標與成本控制排除規則。

功能
此技能提供透過 pup 命令列工具操作 Datadog 日誌的說明。內容涵蓋日誌搜尋查詢與語法、日誌設定 API(例如封存、限制查詢與自訂目的地),以及用於成本控制的處理器與排除篩選器範例。它也說明以日誌為基礎的指標、敏感資料遮蔽規則與疑難排解步驟,產出的是指令與設定片段而非檔案。
適用情境
適用於搜尋 Datadog 日誌、設定日誌管道或排除篩選器、設定封存,或建立以日誌為基礎的指標。也適合在降低日誌成本或從日誌中遮蔽敏感資料時使用。
執行需求
需要安裝並驗證 Datadog Pup 命令列工具(pup auth login),並具備 Datadog 帳戶存取權。需要連線至 Datadog 的網路;此技能未隨附指令碼。

Datadog Logs

Search, process, and archive logs with cost awareness.

Prerequisites

Datadog Pup should already be installed. See Setup Pup if not.

Command Execution Order (Token-Efficient)

For scoped commands, use this order:

  1. Check context first (prior outputs, conversation, saved values).
  2. If a required value is missing, run a discovery command first.
  3. If still ambiguous, ask the user to confirm.
  4. Then run the target command.
  5. Avoid speculative commands likely to fail.

Quick Start

bash
pup auth login

Search Logs

bash
# Basic searchpup logs search --query="status:error" --from="1h"
# With filterspup logs search --query="service:api status:error" --from="1h" --limit 100
# JSON outputpup logs search --query="@http.status_code:>=500" --from="1h"

Search Syntax

QueryMeaning
errorFull-text search
status:errorTag equals
@http.status_code:500Attribute equals
@http.status_code:>=400Numeric range
service:api AND env:prodBoolean
@message:*timeout*Wildcard

Configuration APIs

Available log configuration commands in pup 0.42.0:

bash
# List log archivespup logs archives list
# List log restriction queriespup logs restriction-queries list
# List custom log destinationspup logs custom-destinations list

Common Processors

json
{  "name": "API Logs",  "filter": {"query": "service:api"},  "processors": [    {      "type": "grok-parser",      "name": "Parse nginx",      "source": "message",      "grok": {"match_rules": "%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}"}    },    {      "type": "status-remapper",      "name": "Set severity",      "sources": ["level", "severity"]    },    {      "type": "attribute-remapper",      "name": "Remap user_id",      "sources": ["user_id"],      "target": "usr.id"    }  ]}

Exclusion Filters (Cost Control)

Index only what matters:

json
{  "name": "Drop debug logs",  "filter": {"query": "status:debug"},  "is_enabled": true}

High-Volume Exclusions

bash
# Find noisiest log sourcespup logs search --query="*" --from="1h" | jq 'group_by(.service) | map({service: .[0].service, count: length}) | sort_by(-.count)[:10]'
ExcludeQuery
Health checks@http.url:"/health" OR @http.url:"/ready"
Debug logsstatus:debug
Static assets@http.url:*.css OR @http.url:*.js
Heartbeats@message:*heartbeat*

Archives

Store logs cheaply for compliance:

bash
# List archivespup logs archives list
# Archive config (S3 example){  "name": "compliance-archive",  "query": "*",  "destination": {    "type": "s3",    "bucket": "my-logs-archive",    "path": "/datadog"  },  "rehydration_tags": ["team:platform"]}

Rehydrate (Restore)

bash
# No `pup logs rehydrate` command in pup 0.42.0.# Use Datadog UI/API for rehydration workflows.

Log-Based Metrics

Create metrics from logs (cheaper than indexing):

bash
# List log-based metricspup logs metrics list
# Get one metric by IDpup logs metrics get api.errors.count

Cardinality warning: Group by bounded values only.

Sensitive Data

Scrubbing Rules

json
{  "type": "hash-remapper",  "name": "Hash emails",  "sources": ["email", "@user.email"]}

Never Log

python
# In your app - sanitize before sendingimport re
def sanitize_log(message: str) -> str:    # Remove credit cards    message = re.sub(r'\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b', '[REDACTED]', message)    # Remove SSNs    message = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED]', message)    return message

Troubleshooting

ProblemFix
Logs not appearingCheck agent, pipeline filters
High costsAdd exclusion filters
Search slowNarrow time range, use indexes
Missing attributesCheck grok parser

References/Documentation

來源與署名

來源:datadog-labs/agent-skills位於dd-logs提交5b40c73

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架