Datadog connector
The Datadog connector connects directly to the Datadog REST API. It lets a workflow or agent triage firing monitors — list monitors, fetch alert events, confirm with metric or log queries — then mute monitors, schedule downtimes, open or update incidents, and post events, without opening the Datadog console.
You can use this connector in Agent Builder and Workflows.
The Datadog connector uses Datadog's regional API hosts with API key and Application key authentication. You configure the Datadog site (region) and both keys when creating the connector.
You can create a Datadog connector in Stack Management > Connectors.
- Datadog site
- The Datadog site where the account lives (for example
datadoghq.comfor US1,datadoghq.eufor EU1,us3.datadoghq.comfor US3). Requests go to the matchingapi.*host. - Authentication
- API Key and Application Key. Both are required for monitor, downtime, incident, event, metric, and log actions. Create them under Organization Settings > API Keys and Organization Settings > Application Keys in Datadog.
The connector provides an ingest URL for Datadog webhooks. Each accepted request emits a datadog.alert workflow event. The event contains the raw JSON payload in event.body.
Use this JSON payload in the Datadog webhook configuration. Do not enable form encoding:
{
"message": "$EVENT_MSG",
"last_updated": "$LAST_UPDATED",
"event_type": "$EVENT_TYPE",
"title": "$EVENT_TITLE",
"severity": "$ALERT_PRIORITY",
"alert_type": "$ALERT_TYPE",
"alert_query": "$ALERT_QUERY",
"alert_transition": "$ALERT_TRANSITION",
"date": "$DATE",
"scopes": "$ALERT_SCOPE",
"org": {
"id": "$ORG_ID",
"name": "$ORG_NAME"
},
"url": "$LINK",
"tags": "$TAGS",
"id": "$ID",
"monitor_id": "$ALERT_ID"
}
The managed Datadog alert translation workflow uses monitor_id and scopes as the alert fingerprint. It sets status to inactive when alert_transition is Recovered, and to active for other transitions.
The ingest token authenticates the webhook request. The workflow runs with the identity of the last user who saved the connector.
| Action | Description |
|---|---|
listMonitors |
List monitors and their alert states. Parameters: tags, monitorTags, name, groupStates, withDowntimes, page, pageSize. |
getMonitor |
Get a single monitor's full definition and state. Parameters: monitorId (required), groupStates. |
getAlertEvents |
Search alert-type events over a time range. Parameters: query (required), from (required), to (required), limit. |
muteMonitor |
Mute a monitor (optionally for a scope or until a timestamp). Parameters: monitorId (required), scope, end. |
unmuteMonitor |
Unmute a monitor. Parameters: monitorId (required), scope, allScopes. |
scheduleDowntime |
Schedule a downtime for a scope and time window. Parameters: scope (required), start (required), end (required), message, monitorTags, monitorId. |
cancelDowntime |
Cancel a downtime by ID. Parameters: downtimeId (required). |
createIncident |
Create an incident. Parameters: title (required), customerImpacted, severity, detectionMethod, initialCell. |
updateIncident |
Update an incident (at least one of title/customerImpacted/severity/state). Parameters: incidentId (required), title, customerImpacted, severity, state. |
postEvent |
Post an event to the Events Explorer. Parameters: title (required), text (required), tags, alertType, aggregationKey, dateHappened. |
queryTimeseries |
Query timeseries metrics. Parameters: query (required), from (required), to (required). |
searchLogs |
Search logs over a time range. Parameters: query (required), from (required), to (required), indexes, limit, sort, storageTier. |
Use the Action configuration settings to customize connector networking, such as proxies, certificates, or TLS settings. You can set configurations that apply to all your connectors or use xpack.actions.customHostSettings to set per-host configurations.
- Log in to your Datadog account (use the URL for your site).
- Go to Organization Settings > API Keys, create an API key, and copy it.
- Go to Organization Settings > Application Keys, create an application key, and copy it.
- Confirm your Datadog site from your browser URL (for example
datadoghq.com,datadoghq.eu, orus3.datadoghq.com). - When configuring the connector, enter the API Key and Application Key, and select the matching Datadog site. Both keys are required for monitor, downtime, incident, event, metric, and log actions.