All skills
datadog-labs avatar

/compliance-report

@0d12930 official
by Datadog Labsdatadog-labs/agent-skills176 stars
29

Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output.

  • 2 files
  • 10.5 KB
  • Updated 5 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/datadog-labs/agent-skills/compliance-report

This session only. Nothing lands on disk.

SKILL.md

โ‰ˆ48 tokens always: the name and description. โ‰ˆ1.6k when used: this file. โ‰ˆ944 more on demand in 1 file.

Audit Trail: Compliance Evidence Report

Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.

Prerequisites

pup auth login   # OAuth2 (recommended)
# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Read First

See references/control-mapping.md for the full control โ†’ query mapping table and retention requirements by framework.

Retention Check (Run First)

PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:

pup audit-logs search --query "@evt.name:\"Audit Trail\" @action:modified" --from 90d -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource: .attributes.attributes.asset.type
    }]'

If the requested time window exceeds 90 days and no archive is confirmed, surface this gap in the report header.

Workflow

  1. Confirm: framework (SOC 2 / PCI DSS), time window, org scope
  2. Run retention check
  3. Run each relevant control query
  4. Format output using the Evidence Report template

SOC 2 Queries

CC6.2 โ€” User Provisioning / Deprovisioning

pup audit-logs search \
  --query "@evt.name:\"Access Management\" @asset.type:user @action:(created OR deleted OR modified)" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      affected_user: .attributes.attributes.asset.id
    }]'

CC6.3 โ€” Role and Permission Changes

pup audit-logs search \
  --query "@evt.name:\"Access Management\" @asset.type:role" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      role_id: .attributes.attributes.asset.id
    }]'

CC6.6 โ€” Failed Logins and Suspicious Access

pup audit-logs search \
  --query "@evt.name:Authentication @action:login @status:error" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      ip: .attributes.attributes.network.client.ip,
      country: .attributes.attributes.network.client.geoip.country.name
    }]'

CC7.2 โ€” Privileged / Support User Actions

pup audit-logs search \
  --query "@evt.actor.type:SUPPORT_USER" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      support_actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id
    }]'

PCI DSS Queries

PCI 10.2.2 โ€” Actions by Privileged Users

Same as CC7.2 above. Also include org-level admin actions:

pup audit-logs search \
  --query "@evt.name:\"Organization Management\"" \
  --from PERIOD_START --to PERIOD_END --limit 200 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type
    }]'

PCI 10.2.3 โ€” Access to Audit Trail Itself

pup audit-logs search \
  --query "@evt.name:\"Audit Trail\"" \
  --from PERIOD_START --to PERIOD_END --limit 200 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type
    }]'

PCI 10.2.4 โ€” Invalid Access Attempts

Same as CC6.6 failed logins above.

PCI 10.2.5 โ€” All Authentication Events

pup audit-logs search \
  --query "@evt.name:Authentication @action:login" \
  --from PERIOD_START --to PERIOD_END --limit 1000 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      auth_method: .attributes.attributes.auth_method,
      result: .attributes.attributes.status,
      ip: .attributes.attributes.network.client.ip,
      country: .attributes.attributes.network.client.geoip.country.name
    }]'

PCI 10.2.7 โ€” Object Creation and Deletion

pup audit-logs search \
  --query "@action:(created OR deleted)" \
  --from PERIOD_START --to PERIOD_END --limit 1000 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id,
      ip: .attributes.attributes.network.client.ip
    }]'

Evidence Report Template

# Datadog Audit Trail โ€” Compliance Evidence Report
Framework: [SOC 2 / PCI DSS]
Organization: [org name]
Period: [start] to [end]
Generated: [date]

## Scope Boundary
This report covers administrative actions within the Datadog platform.
It does not cover actions taken within systems that Datadog monitors.

## Retention Status
[โœ“ Full period covered by Audit Trail retention]
[โš  Requested period exceeds 90-day default. Archive config required for complete coverage.]

---

## [Control ID] โ€” [Control Name]
Events found: [N]

| Timestamp | Actor | Action | Resource Type | Resource ID | IP | Country |
|-----------|-------|--------|---------------|-------------|-----|---------|
| ...       | ...   | ...    | ...           | ...         | ... | ...     |

[Repeat per control]

---

## Gaps
[List any controls where data was unavailable or incomplete, and why]

Scope Caveat

Datadog Audit Trail covers the Datadog platform as the system being audited. For PCI purposes, this is evidence that the monitoring platform's access controls are functioning โ€” not direct evidence about the cardholder data environment (CDE) itself. Auditors should understand this scope boundary.

References

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 0d12930. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
Other metadata
metadata
{
  "version": "0.1.0",
  "author": "datadog-labs",
  "repository": "https://github.com/datadog-labs/agent-skills",
  "tags": "datadog,audit,compliance,soc2,pci,dd-audit",
  "alwaysApply": "false"
}
  • datadog
  • audit-logs
  • compliance
  • soc2
  • pci-dss
  • access-management
  • authentication
  • audit-trail

README badge

README badge for datadog-labs/agent-skills/compliance-report

Generates auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS frameworks by mapping control requirements to specific query patterns. Produces formatted reports with user provisioning, authentication events, privileged access, and audit trail access logs, with checks for retention gaps beyond Datadog's 90-day default window.

Generated from the current SKILL.md.

Does this skill work with both SOC 2 and PCI DSS?
Yes. The skill includes separate query templates for SOC 2 controls (CC6.2, CC6.3, CC6.6, CC7.2) and PCI DSS requirements (10.2.2 through 10.2.7), with a shared retention check workflow.
What data retention do I need configured?
Datadog Audit Trail defaults to 90-day retention. PCI DSS requires 12 months, so you must configure archiving for periods beyond 90 days. The skill includes a retention check query to surface this gap.
Does this cover cardholder data environment (CDE) activity or just Datadog platform access?
This skill audits only Datadog platform administrative actions (user provisioning, role changes, authentication events, etc.). It does not provide direct evidence of CDE activity โ€” auditors must understand this scope boundary for PCI compliance.
What authentication is required to run the queries?
You need either OAuth2 via pup auth login (recommended) or API/App keys with the audit_logs_read scope.
Does the skill format the output automatically?
The skill provides query templates and a markdown Evidence Report template with jq formatters. You run each query and populate the template manually, checking for retention gaps first.

Generated from the current SKILL.md. These answers refresh after source changes.