Dt Obs Log Semantic Mapping

作者 Dynatrace9529e72715d9Apache-2.0161 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 天前更新

Suggest and validate semantic dictionary (SD) mappings for audit log integrations using raw vendor log payloads or live ingested events. Use when: mapping a vendor audit log feed, authentication logs, user activity logs to the Dynatrace SD; checking required semantic fields; proposing OpenPipeline processor extraction rules based on DQL; running runtime validation (fetches live logs by log.source, then applies static validation).

AI 產生的概覽

為供應商稽核與 HTTP 日誌整合建議並驗證 Dynatrace 語意字典對應。

功能
此技能會將供應商的稽核、驗證、授權、使用者操作與 HTTP 日誌原始酬載對應到 Dynatrace 語意字典欄位,並針對貼上的已擷取事件或租戶即時日誌驗證現有對應。它會盤點被埋沒與已提升的 content 欄位,檢查必要欄位以及列舉與型別規則,並提出以 DQL 撰寫的 OpenPipeline 處理器擷取規則。產出包括對應表、差異表、OpenPipeline 草圖與驗證摘要。
適用情境
適用於將供應商稽核日誌、驗證日誌或使用者活動日誌導入 Dynatrace 語意字典時,檢查必要語意欄位是否已填入時,或針對貼上事件或租戶即時資料驗證對應時。也適用於提出 OpenPipeline 擷取規則以提升被埋沒欄位的情境,例如僅填入核心欄位的 GitHub 或 Sonatype 等稀疏整合。
執行需求
僅提供指示,不含指令碼。需要 references/ 與 samples/ 下的參考檔案。工作流程 B2 需要 Dynatrace 租戶的即時存取權限,以便依 log.source 取得日誌。提出 OpenPipeline 擷取規則前需先載入 dt-dql-essentials 技能。

dt-obs-log-semantic-mapping

Build and validate semantic-dictionary-aligned mappings for audit log integrations.

Purpose

Use this skill when a user wants to:

  • Suggest a mapping from a raw vendor audit log payload to Dynatrace fetch logs fields (Workflow A).
  • Validate a mapping against a pasted ingested log event (Workflow B1 — static).
  • Validate against live tenant data via live tenant access (Workflow B2 — runtime: fetches logs by log.source, then runs B1 on the result).

Log Classes

ClassDescriptionKey namespacesExample sources
authenticationLogin, logout, MFA, tokenaudit.*, actor.*, browser.*, device.*CyberArk, Okta, Azure SignInLogs
authorizationAccess decisions, permission changesaudit.*, actor.*, object.*CyberArk, Okta
user_actionCRUD on platform resourcesaudit.*, actor.*, object.*, product.*Okta, GitHub, Sonatype
httpHTTP request/response (WAF, network devices)http.*, url.*, server.*, geo.*, client.*Akamai SIEM, Cloudflare

Workflows

ModeInputSource
Workflow A — Suggest mappingRaw vendor log payloadreferences/mapping-workflow.md § Workflow A
Workflow B1 — Static validationPasted ingested log eventreferences/mapping-workflow.md § Workflow B1
Workflow B2 — Runtime validationlog.source value + live tenant accessreferences/runtime-validation.md — fetches logs, then runs B1

Key Concepts

Content field burial: The primary validation concern. Fields in content (the raw vendor payload) that could be promoted to top-level semantic attributes but are not. The skill always inventories buried vs promoted fields and proposes OpenPipeline extraction rules to fix gaps.

Prerequisite: When proposing OpenPipeline processor extraction rules, load the dt-dql-essentials skill first. OpenPipeline processors use DQL functions (parse, fieldsAdd, splitString, etc.) — using non-DQL syntax produces invalid rules.

Sparse mappings are valid: Integrations like GitHub or Sonatype may only populate core fields. Minimum required: timestamp, log.source, content, loglevel, audit.action, audit.identity.

References

  • references/data-model-notes.md — Log SD field taxonomy, audit namespace, enums, sample-derived patterns and known discrepancies
  • references/mapping-workflow.md — Intake checklist, Workflow A and B1 procedures, content field analysis, field priority order
  • references/validation-rules.md — Required fields, content/enum/type rules, discrepancy severity
  • references/openpipeline-constraints.md — OpenPipeline processor command/function/operator/matcher restrictions; parseJson unavailability + parse→fieldsFlatten alternative; iterative operators for array casting
  • references/report-format.md — Mapping table, diff table, OpenPipeline sketch, Validation Summary templates
  • references/runtime-validation.md — Workflow B2: fetch live records, then run B1
  • samples/audit-logs.json — Mapped samples: CyberArk, Okta, Azure SignInLogs, Sonatype, GitHub
  • samples/http-logs.json — Mapped samples: Akamai SIEM (WAF/HTTP class)
  • Dynatrace Log Semantic Dictionary

來源與署名

來源:Dynatrace/dynatrace-for-ai位於skills/dt-obs-log-semantic-mapping提交9529e72

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架