Datadog connector

The Datadog connector connects directly to the Datadog REST API. It lets a workflow or agent triage firing monitors — list monitors, fetch alert events, confirm with metric or log queries — then mute monitors, schedule downtimes, open or update incidents, and post events, without opening the Datadog console.

You can use this connector in Agent Builder and Workflows.

The Datadog connector uses Datadog's regional API hosts with API key and Application key authentication. You configure the Datadog site (region) and both keys when creating the connector.

You can create a Datadog connector in Stack Management > Connectors.

Datadog site
The Datadog site where the account lives (for example datadoghq.com for US1, datadoghq.eu for EU1, us3.datadoghq.com for US3). Requests go to the matching api.* host.
Authentication
API Key and Application Key. Both are required for monitor, downtime, incident, event, metric, and log actions. Create them under Organization Settings > API Keys and Organization Settings > Application Keys in Datadog.

The connector provides an ingest URL for Datadog webhooks. Each accepted request emits a datadog.alert workflow event. The event contains the raw JSON payload in event.body.

Use this JSON payload in the Datadog webhook configuration. Do not enable form encoding:

{
  "message": "$EVENT_MSG",
  "last_updated": "$LAST_UPDATED",
  "event_type": "$EVENT_TYPE",
  "title": "$EVENT_TITLE",
  "severity": "$ALERT_PRIORITY",
  "alert_type": "$ALERT_TYPE",
  "alert_query": "$ALERT_QUERY",
  "alert_transition": "$ALERT_TRANSITION",
  "date": "$DATE",
  "scopes": "$ALERT_SCOPE",
  "org": {
    "id": "$ORG_ID",
    "name": "$ORG_NAME"
  },
  "url": "$LINK",
  "tags": "$TAGS",
  "id": "$ID",
  "monitor_id": "$ALERT_ID"
}
		

The managed Datadog alert translation workflow uses monitor_id and scopes as the alert fingerprint. It sets status to inactive when alert_transition is Recovered, and to active for other transitions.

The ingest token authenticates the webhook request. The workflow runs with the identity of the last user who saved the connector.

Action Description
listMonitors List monitors and their alert states. Parameters: tags, monitorTags, name, groupStates, withDowntimes, page, pageSize.
getMonitor Get a single monitor's full definition and state. Parameters: monitorId (required), groupStates.
getAlertEvents Search alert-type events over a time range. Parameters: query (required), from (required), to (required), limit.
muteMonitor Mute a monitor (optionally for a scope or until a timestamp). Parameters: monitorId (required), scope, end.
unmuteMonitor Unmute a monitor. Parameters: monitorId (required), scope, allScopes.
scheduleDowntime Schedule a downtime for a scope and time window. Parameters: scope (required), start (required), end (required), message, monitorTags, monitorId.
cancelDowntime Cancel a downtime by ID. Parameters: downtimeId (required).
createIncident Create an incident. Parameters: title (required), customerImpacted, severity, detectionMethod, initialCell.
updateIncident Update an incident (at least one of title/customerImpacted/severity/state). Parameters: incidentId (required), title, customerImpacted, severity, state.
postEvent Post an event to the Events Explorer. Parameters: title (required), text (required), tags, alertType, aggregationKey, dateHappened.
queryTimeseries Query timeseries metrics. Parameters: query (required), from (required), to (required).
searchLogs Search logs over a time range. Parameters: query (required), from (required), to (required), indexes, limit, sort, storageTier.

Use the Action configuration settings to customize connector networking, such as proxies, certificates, or TLS settings. You can set configurations that apply to all your connectors or use xpack.actions.customHostSettings to set per-host configurations.

  1. Log in to your Datadog account (use the URL for your site).
  2. Go to Organization Settings > API Keys, create an API key, and copy it.
  3. Go to Organization Settings > Application Keys, create an application key, and copy it.
  4. Confirm your Datadog site from your browser URL (for example datadoghq.com, datadoghq.eu, or us3.datadoghq.com).
  5. When configuring the connector, enter the API Key and Application Key, and select the matching Datadog site. Both keys are required for monitor, downtime, incident, event, metric, and log actions.