Capability
Other metadata
- metadata
{
"version": "0.1.0",
"author": "datadog-labs",
"repository": "https://github.com/datadog-labs/agent-skills",
"tags": "datadog,audit,audit-trail,security,compliance,dd-audit",
"alwaysApply": "false"
}
Topics
- Security
- API
- datadog
- audit
- audit-trail
- compliance
- investigation
- logging
What it does
Queries Datadog Audit Trail to investigate user activity, configuration changes, and compliance events using the pup audit-logs command. Covers security investigations (who changed what), key compromise auditing, cost spike root cause analysis, SOC 2/PCI compliance reporting, and AI assistant activity tracking.
Generated from the current SKILL.md.
Frequently asked
What time window can I query?
Default retention is 90 days. Queries beyond 90 days require archive configuration to S3/GCS/Azure Blob. Always verify the requested time window falls within retention before running a query.
What permissions do I need?
The API key or app key must have the `audit_logs_read` scope. Use OAuth2 login with `pup auth login` or set DD_API_KEY and DD_APP_KEY with the appropriate scope.
Can I audit AI assistant activity?
Yes. The skill includes an ai-activity-audit sub-skill for auditing MCP tool calls and generating AI governance reports.
What fields can I search on?
You can filter by user email, actor type, action verb, event category, resource type, API/app key ID, client IP, geolocation, and HTTP path using Lucene-style syntax matching the Log Explorer syntax.
What should I do if a query times out?
Narrow the time window or add more filters to reduce the result set scope.
Generated from the current SKILL.md. These answers refresh after source changes.