How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Datadog Create API

The Create API from Datadog — 69 operation(s) for create.

Datadog Create API is one of 290 APIs that Datadog publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 4 JSON Schema definitions.

The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, an API reference, and 4 JSON Schemas.

This API exposes 69 operations across 69 paths, and defines 1281 schemas. It is described by OpenAPI 3.0.0, at version 1.0.

Requests are made against 3 base URLs: https://{subdomain}.{site}, {protocol}://{name}, https://{subdomain}.{site}.

69 operations 69 paths 1281 schemas 1 PATCH67 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
1.0
Base URL
https://api.datadoghq.com
Authentication
OAuth 2.0, API Key, API Key, HTTP Bearer
Resource Areas
1

Authentication & Security 4

Datadog Create API declares 4 security schemes for authenticating requests. It supports OAuth 2.0 (AuthZ) using the authorizationCode flow, exposing 68 scopes. An API key is passed in the header as DD-API-KEY (apiKeyAuth). An API key is passed in the header as DD-APPLICATION-KEY (appKeyAuth). It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

  • AuthZ — This API uses OAuth 2 with the implicit grant flow.
  • apiKeyAuth — Your Datadog API Key.
  • appKeyAuth — Your Datadog APP Key.

Paths & Operations 69

Across 69 paths, the API surfaces 69 operations — 1 PATCH, 67 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Create 69
POST
/api/v2/actions/connections
Datadog Create a New Action Connection
CreateActionConnection body → 201400403429
POST
/api/v2/api_keys
Datadog Create an Api Key
CreateAPIKey body → 201400403429
POST
/api/v2/apicatalog/openapideprecated
Datadog Create a New Api
CreateOpenAPI body → 201400403429
POST
/api/v2/apm/config/metrics
Datadog Create a Span-based Metric
CreateSpansMetric body → 200400403409429
POST
/api/v2/apm/config/retention-filters
Datadog Create a Retention Filter
CreateApmRetentionFilter body → 200400403409429
POST
/api/v2/app-builder/apps
Datadog Create App
CreateApp body → 201400403429
POST
/api/v2/authn_mappings
Datadog Create an Authn Mapping
CreateAuthNMapping body → 200400403404429
POST
/api/v2/cases
Datadog Create a Case
CreateCase body → 201400401403404429
POST
/api/v2/cases/projects
Datadog Create a Project
CreateProject body → 201400401403404429
POST
/api/v2/catalog/entity
Datadog Create or Update Entities
UpsertCatalogEntity body → 202400403429
POST
/api/v2/cloud_security_management/custom_frameworks
Datadog Create a Custom Framework
CreateCustomFramework body → 200400409429500
POST
/api/v2/cost/aws_cur_config
Datadog Create Cloud Cost Management Aws Cur Config
CreateCostAWSCURConfig body → 200400403429
POST
/api/v2/cost/azure_uc_config
Datadog Create Cloud Cost Management Azure Configs
CreateCostAzureUCConfigs body → 200400403429
PUT
/api/v2/cost/budget
Datadog Create or Update a Budget
UpsertBudget body → 200400404429
POST
/api/v2/current_user/application_keys
Datadog Create an Application Key for Current User
CreateCurrentUserApplicationKey body → 201400403429
POST
/api/v2/incidents
Datadog Create an Incident
CreateIncident body → 201400401403404429
POST
/api/v2/incidents/config/types
Datadog Create an Incident Type
CreateIncidentType body → 201400401403404429
PATCH
/api/v2/incidents/{incident_id}/attachments
Datadog Create, Update, and Delete Incident Attachments
UpdateIncidentAttachments 2 params body → 200400401403404429
POST
/api/v2/incidents/{incident_id}/relationships/integrations
Datadog Create an Incident Integration Metadata
CreateIncidentIntegration 1 param body → 201400401403404429
POST
/api/v2/incidents/{incident_id}/relationships/todos
Datadog Create an Incident Todo
CreateIncidentTodo 1 param body → 201400401403404429
POST
/api/v2/integration/aws/accounts
Datadog Create an Aws Integration
CreateAWSAccount body → 200400403409429
POST
/api/v2/integration/gcp/accounts
Datadog Create a New Entry for Your Service Account
CreateGCPSTSAccount body → 201400401403409429
POST
/api/v2/integration/gcp/sts_delegate
Datadog Create a Datadog Gcp Principal
MakeGCPSTSDelegate body → 200403409429
POST
/api/v2/integration/ms-teams/configuration/tenant-based-handles
Datadog Create Tenant-based Handle
CreateTenantBasedHandle body → 201400403404409412429
POST
/api/v2/integration/ms-teams/configuration/workflows-webhook-handles
Datadog Create Workflows Webhook Handle
CreateWorkflowsWebhookHandle body → 201400403404409412429
POST
/api/v2/integration/opsgenie/services
Datadog Create a New Service Object
CreateOpsgenieService body → 201400403409429
POST
/api/v2/logs/config/archives
Datadog Create an Archive
CreateLogsArchive body → 200400403429
POST
/api/v2/logs/config/custom-destinations
Datadog Create a Custom Destination
CreateLogsCustomDestination body → 200400403409429
POST
/api/v2/logs/config/metrics
Datadog Create a Log-based Metric
CreateLogsMetric body → 200400403409429
POST
/api/v2/logs/config/restriction_queries
Datadog Create a Restriction Query
CreateRestrictionQuery body → 200400403429
POST
/api/v2/metrics/{metric_name}/tags
Datadog Create a Tag Configuration
CreateTagConfiguration 1 param body → 201400403409429
POST
/api/v2/monitor/notification_rule
Datadog Create a Monitor Notification Rule
CreateMonitorNotificationRule body → 200400403429
POST
/api/v2/monitor/policy
Datadog Create a Monitor Configuration Policy
CreateMonitorConfigPolicy body → 200400403429
POST
/api/v2/on-call/escalation-policies
Datadog Create On-call Escalation Policy
CreateOnCallEscalationPolicy 1 param body → 201400401403429
POST
/api/v2/on-call/pages
Datadog Create On-call Page
CreateOnCallPage body → 200429
POST
/api/v2/on-call/schedules
Datadog Create On-call Schedule
CreateOnCallSchedule 1 param body → 201400401403429
POST
/api/v2/powerpacks
Datadog Create a New Powerpack
CreatePowerpack body → 200400429
POST
/api/v2/remote_config/products/asm/waf/custom_rules
Datadog Create a Waf Custom Rule
CreateApplicationSecurityWafCustomRule body → 201400403409429
POST
/api/v2/remote_config/products/asm/waf/exclusion_filters
Datadog Create a Waf Exclusion Filter
CreateApplicationSecurityWafExclusionFilter body → 200400403409429
POST
/api/v2/remote_config/products/cws/agent_rules
Datadog Create a Workload Protection Agent Rule
CreateCSMThreatsAgentRule body → 200400403409429
POST
/api/v2/remote_config/products/cws/policy
Datadog Create a Workload Protection Policy
CreateCSMThreatsAgentPolicy body → 200400403409429
POST
/api/v2/remote_config/products/obs_pipelines/pipelines
Datadog Create a New Pipeline
CreatePipeline body → 201400403409429
POST
/api/v2/roles
Datadog Create Role
CreateRole body → 200400403429
POST
/api/v2/roles/{role_id}/clone
Datadog Create a New Role by Cloning an Existing Role
CloneRole 1 param body → 200400403404409429
POST
/api/v2/rum/applications
Datadog Create a New Rum Application
CreateRUMApplication body → 200400429
POST
/api/v2/rum/applications/{app_id}/retention_filters
Datadog Create a Rum Retention Filter
CreateRetentionFilter 1 param body → 201400403429
POST
/api/v2/rum/config/metrics
Datadog Create a Rum-based Metric
CreateRumMetric body → 201400403409429
POST
/api/v2/scim/Groups
Datadog Create Group
CreateSCIMGroup body → 201400429
POST
/api/v2/scim/Users
Datadog Create User
CreateSCIMUser body → 201400429
POST
/api/v2/scorecard/outcomes/batch
Datadog Create Outcomes Batch
CreateScorecardOutcomesBatch body → 200400403429
POST
/api/v2/scorecard/rules
Datadog Create a New Rule
CreateScorecardRule body → 201400403429
POST
/api/v2/security/signals/notification_rules
Datadog Create a New Signal-based Notification Rule
CreateSignalNotificationRule body → 201400403429
POST
/api/v2/security/vulnerabilities/notification_rules
Datadog Create a New Vulnerability-based Notification Rule
CreateVulnerabilityNotificationRule body → 201400403429
POST
/api/v2/security_monitoring/cloud_workload_security/agent_rules
Datadog Create a Workload Protection Agent Rule (us1-fed)
CreateCloudWorkloadSecurityAgentRule body → 200400403409429
POST
/api/v2/security_monitoring/configuration/security_filters
Datadog Create a Security Filter
CreateSecurityFilter body → 200400403409429
POST
/api/v2/security_monitoring/configuration/suppressions
Datadog Create a Suppression Rule
CreateSecurityMonitoringSuppression body → 200400403409429
POST
/api/v2/security_monitoring/rules
Datadog Create a Detection Rule
CreateSecurityMonitoringRule body → 200400403429
POST
/api/v2/sensitive-data-scanner/config/groups
Datadog Create Scanning Group
CreateScanningGroup body → 200400403429
POST
/api/v2/sensitive-data-scanner/config/rules
Datadog Create Scanning Rule
CreateScanningRule body → 200400403429
POST
/api/v2/service_accounts
Datadog Create a Service Account
CreateServiceAccount body → 201400403429
POST
/api/v2/service_accounts/{service_account_id}/application_keys
Datadog Create an Application Key for This Service Account
CreateServiceAccountApplicationKey 1 param body → 201400403429
POST
/api/v2/servicesdeprecated
Datadog Create a New Incident Service
CreateIncidentService body → 201400401403404429
POST
/api/v2/services/definitions
Datadog Create or Update Service Definition
CreateOrUpdateServiceDefinitions body → 200400403409429
POST
/api/v2/slo/report
Datadog Create a New Slo Report
CreateSLOReportJob body → 200400403429
POST
/api/v2/team
Datadog Create a Team
CreateTeam body → 201403409429
POST
/api/v2/team/{team_id}/links
Datadog Create a Team Link
CreateTeamLink 1 param body → 200403404422429
POST
/api/v2/teamsdeprecated
Datadog Create a New Incident Team
CreateIncidentTeam body → 201400401403404429
POST
/api/v2/users
Datadog Create a User
CreateUser body → 201400403429
POST
/api/v2/workflows
Datadog Create a Workflow
CreateWorkflow body → 201400403429

Schemas 1281

The contract defines 1281 schemas that model the data the API accepts and returns. The most detailed are SecurityMonitoringStandardRuleResponse (24 properties), IncidentResponseAttributes (24 properties), CloudWorkloadSecurityAgentRuleAttributes (21 properties), SecurityMonitoringSignalRuleResponse (18 properties). Each schema is shown below with its type and property counts.

ServiceDefinitionV2
object
Service definition V2 for providing service metadata and integrations.
11 properties 2 required
ScheduleMemberRelationshipsUserDataType
string
Users resource type.
LogsArchiveDestinationAzure
object
The Azure archive destination.
6 properties 4 required
ActionQueryCondition
Whether to run this query. If specified, the query will only run if this condition evaluates to true in JavaScript and all other conditions are also met.
OrganizationAttributes
object
Attributes of the organization.
8 properties
ServiceDefinitionV2Dot1SlackType
string
Contact type.
ObservabilityPipelineSensitiveDataScannerProcessorActionHashAction
string
Action type that replaces the matched sensitive data with a hashed representation, preserving structure while securing content.
RelationshipToRuleDataObject
object
Rule relationship data.
2 properties
RelationshipToTeamLinks
object
Relationship between a team and a team link
2 properties
SpansMetricGroupBy
object
A group by rule.
2 properties 1 required
AccountFilteringConfig
object
The account filtering configuration.
3 properties
EntityToOncalls
object
Entity to oncalls relationship.
1 property
IncidentTodoCreateData
object
Incident todo data for a create request.
2 properties 2 required
ApplicationSecurityWafExclusionFilterCreateData
object
Object for creating a single WAF exclusion filter.
2 properties 2 required
Version
integer
Version of the notification rule. It is updated when the rule is modified.
GCPSTSDelegateAccountAttributes
object
Your delegate account attributes.
1 property
ServiceNowTicket
object
ServiceNow ticket attached to case
2 properties
TeamRelationships
object
Resources related to a team
2 properties
ObservabilityPipelineDedupeProcessorMode
string
The deduplication mode to apply to the fields.
CaseCreateRelationships
object
Relationships formed with the case on creation
2 properties 1 required
OutcomesBatchResponseAttributes
object
The JSON:API attributes for an outcome.
5 properties
EntityV3DatastoreDatadog
object
Datadog product integrations for the datastore entity.
3 properties
AzureStorageDestinationType
string
The destination type. The value should always be azurestorage.
CloudWorkloadSecurityAgentRuleUpdaterAttributes
object
The attributes of the user who last updated the Agent rule
2 properties
ObservabilityPipelineMetadataEntry
object
A custom metadata entry.
2 properties 2 required
PowerpackGroupWidgetDefinition
object
Powerpack group widget object.
5 properties 3 required
Permission
object
Permission object.
3 properties 1 required
CreateAppResponse
object
The response object after a new app is successfully created, with the app ID.
1 property
CustomDestinationHttpDestinationAuthCustomHeader
object
Custom header access authentication.
3 properties 3 required
TeamReference
object
Provides a reference to a team, including ID, type, and basic attributes/relationships.
3 properties 1 required
LogsArchiveIntegrationGCS
object
The GCS archive's integration destination.
2 properties 1 required
GCPSTSServiceAccountAttributes
object
Attributes associated with your service account.
11 properties
ServiceDefinitionV2Dot2
object
Service definition v2.2 for providing service metadata and integrations.
15 properties 2 required
AzureUCConfigPair
object
Azure config pair.
3 properties 2 required
ObservabilityPipelineSyslogNgDestinationType
string
The destination type. The value should always be syslogng.
PowerpackAttributes
object
Powerpack attribute object.
5 properties 2 required
ObservabilityPipelineEnrichmentTableFileEncodingType
string
Specifies the encoding format (e.g., CSV) used for enrichment tables.
AuthNMappingRelationships
object
All relationships associated with AuthN Mapping.
3 properties
ServiceDefinitionsCreateRequest
Create service definitions request.
ObservabilityPipelineFluentdSourceType
string
The source type. The value should always be fluentd.
TokenType
string
The definition of TokenType object.
ObservabilityPipelineOcsfMapperProcessorMappingMapping
Defines a single mapping rule for transforming logs into the OCSF schema.
IncidentTimelineCellCreateAttributes
The timeline cell's attributes for a create request.
XRayServicesIncludeAll
object
Include all services.
1 property 1 required
RoleCreateAttributes
object
Attributes of the created role.
3 properties 1 required
MSTeamsIntegrationMetadataTeamsItem
object
Item in the Microsoft Teams integration metadata teams array.
4 properties 4 required
CreateAppRequest
object
A request object for creating a new app.
1 property
State
string
The state of the rule evaluation.
LogsArchiveEncryptionS3
object
The S3 encryption settings.
2 properties 1 required
AWSNamespaceTagFilter
object
AWS Metrics Collection tag filters list. Defaults to []. The array of custom AWS resource tags (in the form key:value) defines a filter that Datadog uses when…
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationType
string
The destination type. Always googlecloudstorage.
FrameworkHandleAndVersionResponseData
object
Contains type and attributes for custom frameworks.
3 properties 3 required
DataRelationshipsTeamsDataItems
object
Relates a team to this schedule, identified by id and type (must be teams).
2 properties 2 required
MetricTagConfigurationCreateData
object
Object for a single metric to be configure tags on.
3 properties 2 required
SensitiveDataScannerConfigurationData
object
A Sensitive Data Scanner configuration data.
1 property
ApplicationSecurityWafExclusionFilterScope
object
Deploy on services based on their environment and/or service name.
2 properties
AnnotationDisplayBounds
object
The definition of AnnotationDisplayBounds object.
4 properties
IncidentTodoAssigneeHandle
string
Assignee's @-handle.
BudgetWithEntriesData
object
A budget and all its entries.
3 properties
LogsArchiveState
string
The state of the archive.
ObservabilityPipelineQuotaProcessorLimitEnforceType
string
Unit for quota enforcement in bytes for data size or events for count.
SecurityMonitoringRuleNewValueOptionsLearningDuration
integer
The duration in days during which values are learned, and after which signals will be generated for values that weren't learned. If set to 0, a signal will be…
SlackTriggerWrapper
object
Schema for a Slack-based trigger.
2 properties 1 required
Selectors
object
Selectors are used to filter security issues for which notifications should be generated. Users can specify rule severities, rule types, a query to filter secu…
4 properties 1 required
ObservabilityPipelineRsyslogDestinationType
string
The destination type. The value should always be rsyslog.
RetentionFilterAttributes
object
The attributes of the retention filter.
12 properties
MonitorNotificationRuleFilter
Filter used to associate the notification rule with monitors.
ErrorHandler
object
Used to handle errors in an action.
2 properties 2 required
SloReportCreateRequestData
object
The data portion of the SLO report request.
1 property 1 required
SpansMetricCompute
object
The compute rule to compute the span-based metric.
3 properties 1 required
ApplicationSecurityWafCustomRuleCreateData
object
Object for a single WAF custom rule.
2 properties 2 required
ObservabilityPipelineParseGrokProcessorType
string
The processor type. The value should always be parsegrok.
TeamTarget
object
Represents a team target for an escalation policy step, including the team's ID and resource type.
2 properties 2 required
ObservabilityPipelineAmazonOpenSearchDestinationType
string
The destination type. The value should always be amazonopensearch.
SecurityMonitoringRuleCaseActionOptionsUserBehaviorName
string
Used with the case action of type 'userbehavior'. The value specified in this field is applied as a risk tag to all users affected by the rule.
RestrictionQueryAttributes
object
Attributes of the restriction query.
3 properties
ObservabilityPipelineGeneratedMetric
object
Defines a log-based custom metric, including its name, type, filter, value computation strategy, and optional grouping fields.
5 properties 4 required
LogsMetricCreateAttributes
object
The object describing the Datadog log-based metric to create.
3 properties 1 required
AWSRegionsIncludeAll
object
Include all regions. Defaults to true.
1 property 1 required
ObservabilityPipelineGoogleChronicleDestination
object
The googlechronicle destination sends logs to Google Chronicle.
7 properties 5 required
LogsArchiveStorageClassS3Type
string
The storage class where the archive will be stored.
MicrosoftTeamsTenantBasedHandleType
string
Specifies the tenant-based handle resource type.
LayerAttributesInterval
object
Defines how often the rotation repeats, using a combination of days and optional seconds.
2 properties
AWSRegions
AWS Regions to collect data from. Defaults to includeall.
ObservabilityPipelineKafkaSource
object
The kafka source ingests data from Apache Kafka topics.
7 properties 4 required
ObservabilityPipelineSplunkTcpSource
object
The splunktcp source receives logs from a Splunk Universal Forwarder over TCP. TLS is supported for secure transmission.
3 properties 2 required
ActionQueryMockedOutputsObject
object
The mocked outputs of the action query.
2 properties 1 required
OpenAPIEndpoint
object
Endpoint info extracted from an OpenAPI specification.
2 properties
UserTeamPermissionType
string
User team permission type
LogsMetricResponseGroupBy
object
A group by rule.
2 properties
IncidentAttachmentUpdateRequest
object
The update request for an incident's attachments.
1 property 1 required
IncidentTeamResponseAttributes
object
The incident team's attributes from a response.
3 properties
IncidentTypeObject
object
Incident type response data.
3 properties 2 required
ActionQueryDebounceInMs
The minimum time in milliseconds that must pass before the query can be triggered again. This is useful for preventing accidental double-clicks from triggering…
ScheduleCreateRequest
object
The top-level request body for schedule creation, wrapping a data object.
1 property 1 required
CloudConfigurationRuleCreatePayload
object
Create a new cloud configuration rule.
9 properties 6 required
AppBuilderEvent
object
An event on a UI component that triggers a response or action in an app.
2 properties
ApplicationSecurityWafCustomRuleData
object
Object for a single WAF custom rule.
3 properties
TriggerSource
string
The type of security issues on which the rule applies. Notification rules based on security signals need to use the trigger source "securitysignals", while not…
EscalationPolicyStepTargetType
string
Specifies the type of escalation target (example users, schedules, or teams).
TeamType
string
Team type
SAMLAssertionAttributeAttributes
object
Key/Value pair of attributes used in SAML assertion attributes.
2 properties
IncidentCreateAttributes
object
The incident's attributes for a create request.
7 properties 2 required
EntityV3QueueDatadog
object
Datadog product integrations for the datastore entity.
3 properties
IncidentTypeResponse
object
Incident type response data.
1 property 1 required
ObservabilityPipelineSentinelOneDestination
object
The sentinelone destination sends logs to SentinelOne.
4 properties 4 required
Case
object
A case
4 properties 3 required
UserCreateAttributes
object
Attributes of the created user.
3 properties 1 required
ScheduleDataType
string
Schedules resource type.
ServiceDefinitionV2Opsgenie
object
Opsgenie integration for the service.
2 properties 1 required
MonitorNotificationRuleCreateRequestData
object
Object to create a monitor notification rule.
2 properties 1 required
ObservabilityPipelineAmazonOpenSearchDestinationAuthStrategy
string
The authentication strategy to use.
CustomFrameworkType
string
The type of the resource. The value must be customframework.
MicrosoftSentinelDestination
object
The microsoftsentinel destination forwards logs to Microsoft Sentinel.
7 properties 7 required
CloudConfigurationRegoRule
object
Rule details.
2 properties 2 required
CompletionConditionOperator
string
The definition of CompletionConditionOperator object.
MicrosoftTeamsWorkflowsWebhookHandleType
string
Specifies the Workflows webhook handle resource type.
AzureUCConfigPostRequest
object
Azure config Post Request.
1 property 1 required
OutcomesBatchRequest
object
Scorecard outcomes batch request.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorScopeExclude
object
Excludes specific fields from sensitive data scanning.
2 properties 2 required
AzureUCConfigPairsResponse
object
Response of Azure config pair.
1 property
ServiceDefinitionV2Pagerduty
string
PagerDuty service URL for the service.
IncidentTeamResponseData
object
Incident Team data from a response.
4 properties
CustomDestinationHttpDestinationAuthBasic
object
Basic access authentication.
3 properties 3 required
Connection
object
The definition of Connection object.
2 properties 2 required
IncidentNonDatadogCreator
object
Incident's non Datadog creator.
2 properties
RetentionFilterCreateAttributes
object
The object describing the configuration of the retention filter to create/update.
6 properties 5 required
ScheduleUserAttributes
object
Provides basic user information for a schedule, including a name and email address.
3 properties
EntityV3DatadogEvents
array
Events associations.
ObservabilityPipelineDatadogLogsDestination
object
The datadoglogs destination forwards logs to Datadog Log Management.
3 properties 3 required
IncidentIntegrationMetadataResponse
object
Response with an incident integration metadata.
2 properties 1 required
Team
object
A team
4 properties 3 required
ObservabilityPipelineAddEnvVarsProcessor
object
The addenvvars processor adds environment variable values to log events.
5 properties 5 required
MonitorNotificationRuleAttributes
object
Attributes of the monitor notification rule.
3 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorPattern
Pattern detection configuration for identifying sensitive data using either a custom regex or a library reference.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedact
object
Configuration for completely redacting matched sensitive data.
2 properties 2 required
RelationshipToOutcomeData
object
The JSON:API relationship to an outcome, which returns the related rule id.
2 properties
ApplicationSecurityWafExclusionFilterRulesTarget
object
Target WAF rules based either on an identifier or tags.
2 properties
MonitorTriggerWrapper
object
Schema for a Monitor-based trigger.
2 properties 1 required
LogsMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
AWSAccountPartition
string
AWS partition your AWS account is scoped to. Defaults to aws. See [Partitions](https://docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/pa…
MicrosoftTeamsTenantBasedHandleRequestAttributes
object
Tenant-based handle attributes.
4 properties 4 required
EntityData
object
Entity data.
5 properties
ServiceAccountCreateRequest
object
Create a service account.
1 property 1 required
ServiceDefinitionV2MSTeamsType
string
Contact type.
SensitiveDataScannerStandardPattern
object
Data containing the standard pattern id.
2 properties
ApplicationSecurityWafCustomRuleTagsCategory
string
The category of the WAF Rule, can be either businesslogic, attackattempt or securityresponse.
CustomDestinationForwardDestinationSplunk
object
The Splunk HTTP Event Collector (HEC) destination.
3 properties 3 required
IncidentTodoResponseIncludedItem
An object related to an incident todo that is included in the response.
ObservabilityPipelineSumoLogicSource
object
The sumologic source receives logs from Sumo Logic collectors.
2 properties 2 required
OutputSchemaParametersType
string
The definition of OutputSchemaParametersType object.
EntityV3APIVersion
string
The schema version of entity type. The field is known as schema-version in the previous version.
ObservabilityPipelineHttpClientSourceAuthStrategy
string
Optional authentication strategy for HTTP requests.
SecurityMonitoringSuppressionID
string
The ID of the suppression rule.
TeamLinkCreateRequest
object
Team link create request
1 property 1 required
APIKeyCreateRequest
object
Request used to create an API key.
1 property 1 required
ObservabilityPipelineOcsfMapperProcessorMapping
object
Defines how specific events are transformed to OCSF using a mapping configuration.
2 properties 2 required
MicrosoftSentinelDestinationType
string
The destination type. The value should always be microsoftsentinel.
ObservabilityPipelineQuotaProcessorLimit
object
The maximum amount of data or number of events allowed before the quota is enforced. Can be specified in bytes or events.
2 properties 2 required
ActionConnectionAttributes
object
The definition of ActionConnectionAttributes object.
2 properties 2 required
APIKeyResponseIncludedItem
An object related to an API key.
DataRelationshipsTeams
object
Associates teams with this schedule in a data structure.
1 property
ServiceDefinitionV2Dot1Integrations
object
Third party integrations that Datadog supports.
2 properties
OpsgenieServiceResponse
object
Response of an Opsgenie service.
1 property 1 required
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property 1 required
EntityToRelatedEntities
object
Entity to related entities relationship.
1 property
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties 2 required
CreateRuleResponse
object
Created rule in response.
1 property
ComponentProperties
object
Properties of a UI component. Different component types can have their own additional unique properties. See the [components documentation](https://docs.datado…
2 properties
EscalationPolicyUser
object
Represents a user object in the context of an escalation policy, including their id, type, and basic attributes.
3 properties 1 required
MicrosoftTeamsWorkflowsWebhookHandleRequestAttributes
object
Workflows Webhook handle attributes.
2 properties 2 required
SecurityMonitoringRuleCaseActionType
string
The action type.
ObservabilityPipelineSampleProcessor
object
The sample processor allows probabilistic sampling of logs at a fixed rate.
6 properties 4 required
ObservabilityPipelineData
object
Contains the pipeline’s ID, type, and configuration attributes.
3 properties 3 required
ServiceDefinitionV2Dot1Version
string
Schema version being used.
HTTPIntegration
object
The definition of HTTPIntegration object.
3 properties 3 required
CustomDestinationCreateRequestAttributes
object
The attributes associated with the custom destination.
7 properties 2 required
RuleType
string
The JSON:API type for scorecard rules.
AnnotationDisplay
object
The definition of AnnotationDisplay object.
1 property
CreatePageResponse
object
The full response object after creating a new On-Call Page.
1 property
AWSCredentials
The definition of AWSCredentials object.
AuthNMappingRelationshipToRole
object
Relationship of AuthN Mapping to a Role.
1 property 1 required
CustomDestinationForwardDestinationElasticsearchType
string
Type of the Elasticsearch destination.
BillConfig
object
Bill config.
4 properties 4 required
ObservabilityPipelineDedupeProcessor
object
The dedupe processor removes duplicate fields in log events.
6 properties 6 required
SensitiveDataScannerRuleCreateRequest
object
Create rule request.
2 properties 2 required
MSTeamsIntegrationMetadata
object
Incident integration metadata for the Microsoft Teams integration.
1 property 1 required
SensitiveDataScannerGroupCreate
object
Data related to the creation of a group.
3 properties 2 required
MicrosoftTeamsCreateTenantBasedHandleRequest
object
Create tenant-based handle request.
1 property 1 required
RelationshipToRuleData
object
Relationship data for a rule.
1 property
RoleCreateResponse
object
Response containing information about a created role.
1 property
LogsArchiveDestinationAzureType
string
Type of the Azure archive destination.
RuleTypes
array
Security rule types used as filters in security rules.
LogsArchiveIntegrationS3
object
The S3 Archive's integration destination.
2 properties 2 required
CloudWorkloadSecurityAgentRuleCreatorAttributes
object
The attributes of the user who created the Agent rule
2 properties
ObservabilityPipelineGeneratedMetricIncrementByOne
object
Strategy that increments a generated metric by one for each matching event.
1 property 1 required
OutcomesBatchAttributes
object
The JSON:API attributes for a batched set of scorecard outcomes.
1 property
SecurityMonitoringSignalRuleResponseQuery
object
Query for matching rule on signals.
9 properties
EntityV3APIKind
string
The definition of Entity V3 API Kind object.
ObservabilityPipelineEnrichmentTableFileEncoding
object
File encoding format.
3 properties 3 required
ApplicationSecurityWafExclusionFilterCreateRequest
object
Request object for creating a single WAF exclusion filter.
1 property 1 required
UserResponse
object
Response containing information about a single user.
2 properties
EntityV3APIDatadog
object
Datadog product integrations for the API entity.
5 properties
ScorecardType
string
The JSON:API type for scorecard.
EscalationPolicyDataRelationships
object
Represents the relationships for an escalation policy, including references to steps and teams.
2 properties 1 required
ExternalUserNameType
object
The components of user's real name
1 property
MonitorNotificationRuleCreateRequest
object
Request for creating a monitor notification rule.
1 property 1 required
NullableUserRelationshipData
object
Relationship to user object.
2 properties 2 required
SlackIntegrationMetadataChannelItem
object
Item in the Slack integration metadata channel array.
4 properties 3 required
AWSIntegrationType
string
The definition of AWSIntegrationType object.
EntityV3DatadogCodeLocationItem
object
Code location item.
2 properties
ComponentPropertiesIsVisible
Whether the UI component is visible. If this is a string, it must be a valid JavaScript expression that evaluates to a boolean.
ServiceDefinitionV1Info
object
Basic information about a service.
4 properties 1 required
OutcomeType
string
The JSON:API type for an outcome.
CustomFrameworkData
object
Contains type and attributes for custom frameworks.
2 properties 2 required
APIKeyCreateAttributes
object
Attributes used to create an API Key.
3 properties 1 required
SecurityFilter
object
The security filter's properties.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactOptions
object
Configuration for fully redacting sensitive data.
1 property 1 required
WorkflowUserRelationship
object
The definition of WorkflowUserRelationship object.
1 property
SecurityFilterCreateData
object
Object for a single security filter.
2 properties 2 required
RuleAttributes
object
Details of a rule.
9 properties
IncidentTypeType
string
Incident type resource type.
LogsMetricFilter
object
The log-based metric filter. Logs matching this filter will be aggregated in this metric.
1 property
ServiceDefinitionV2MSTeams
object
Service owner's Microsoft Teams.
3 properties 2 required
EscalationPolicyDataRelationshipsSteps
object
Defines the relationship to a collection of steps within an escalation policy. Contains an array of step data references.
1 property
UserCreateData
object
Object to create a user.
3 properties 2 required
Spec
object
The spec defines what the workflow does.
7 properties
AWSAuthConfigRole
object
AWS Authentication config to integrate your account using an IAM role.
2 properties 1 required
SecurityMonitoringRuleTypeRead
string
The rule type.
CloudWorkloadSecurityAgentPolicyCreateRequest
object
Request object that includes the Agent policy to create
1 property 1 required
CloudWorkloadSecurityAgentRuleActionSet
object
The set action applied on the scope matching the rule
7 properties
MonitorNotificationRuleRelationships
object
All relationships associated with monitor notification rule.
1 property
ObservabilityPipelineHttpServerSourceAuthStrategy
string
HTTP authentication method.
ObservabilityPipelineFluentdSource
object
The fluentd source ingests logs from a Fluentd-compatible service.
3 properties 2 required
SecurityMonitoringRuleMaxSignalDuration
integer
A signal will "close" regardless of the query being matched once the time exceeds the maximum duration. This time is calculated from the first seen timestamp.
EntityRaw
string
Entity definition in raw JSON or YAML representation.
StateVariableType
string
The state variable type.
ObservabilityPipelineFluentBitSource
object
The fluentbit source ingests logs from Fluent Bit.
3 properties 2 required
IncidentIntegrationRelationships
object
The incident's integration relationships from a response.
2 properties
ServiceDefinitionV2Dot1LinkType
string
Link type.
MetricCustomAggregation
object
A time and space aggregation combination for use in query.
2 properties 2 required
ScheduleDataAttributes
object
Provides core properties of a schedule object such as its name and time zone.
2 properties
SecurityMonitoringRuleResponse
Create a new rule.
CreateWorkflowResponse
object
The response object after creating a new workflow.
1 property 1 required
OpsgenieServiceCreateData
object
Opsgenie service data for a create request.
2 properties 2 required
AppTriggerWrapper
object
Schema for an App-based trigger.
2 properties 1 required
MonitorConfigPolicyTagPolicy
object
Tag attributes of a monitor configuration policy.
3 properties
IncidentAttachmentType
string
The incident attachment resource type.
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
BudgetAttributes
object
The attributes of a budget.
11 properties
FullApplicationKey
object
Datadog application key.
4 properties
WorkflowTriggerWrapper
object
Schema for a Workflow-based trigger.
2 properties 1 required
LayerAttributes
object
Describes key properties of a Layer, including rotation details, name, start/end times, and any restrictions.
6 properties
TeamCreate
object
Team create
3 properties 2 required
ObservabilityPipelineKafkaSourceSasl
object
Specifies the SASL mechanism for authenticating with a Kafka cluster.
1 property
ObservabilityPipelineSplunkHecDestination
object
The splunkhec destination forwards logs to Splunk using the HTTP Event Collector (HEC).
7 properties 3 required
StepDisplay
object
The definition of StepDisplay object.
1 property
RelationshipToUserData
object
Relationship to user object.
2 properties 2 required
SecurityMonitoringStandardDataSource
string
Source of events, either logs, audit trail, or Datadog events.
ServiceDefinitionV1Version
string
Schema version being used.
DataRelationshipsTeamsDataItemsType
string
Teams resource type.
Query
A data query used by an app. This can take the form of an external action, a data transformation, or a state variable.
ActionQuerySpec
The definition of the action query.
ConnectionEnvEnv
string
The definition of ConnectionEnvEnv object.
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties 2 required
IncidentUserData
object
User object returned by the API.
3 properties
ObservabilityPipelineQuotaProcessorOverride
object
Defines a custom quota limit that applies to specific log events based on matching field values.
2 properties 2 required
ApplicationKeyCreateData
object
Object used to create an application key.
2 properties 2 required
AWSAssumeRoleType
string
The definition of AWSAssumeRoleType object.
AppBuilderEventName
string
The triggering action for the event.
EntityV3DatadogPerformance
object
Performance stats association.
1 property
AzureUCConfig
object
Azure config.
15 properties 9 required
SpansFilter
object
The spans filter used to index spans.
1 property
TeamReferenceAttributes
object
Encapsulates the basic attributes of a Team reference, such as name, handle, and an optional avatar or description.
4 properties
CustomDestinationResponseHttpDestinationAuthCustomHeaderType
string
Type of the custom header access authentication.
MonitorNotificationRuleData
object
Monitor notification rule data.
4 properties
ApplicationKeysType
string
Application Keys resource type.
ObservabilityPipelineAmazonS3Source
object
The amazons3 source ingests logs from an Amazon S3 bucket. It supports AWS authentication and TLS encryption.
5 properties 3 required
SecurityFilterExclusionFilter
object
Exclusion filter for the security filter.
2 properties 2 required
RumMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when aggregationtype is distribution.
RelationshipToUserTeamPermissionData
object
Related user team permission data
2 properties 2 required
ObservabilityPipelineAmazonS3Destination
object
The amazons3 destination sends your logs in Datadog-rehydratable format to an Amazon S3 bucket for archiving.
9 properties 6 required
ServiceDefinitionV2Dot2Type
string
The type of service.
TimeAggregation
integer
Time aggregation period (in seconds) is used to aggregate the results of the notification rule evaluation. Results are aggregated over a selected time frame us…
AWSNamespaceFiltersExcludeOnly
object
Exclude only these namespaces from metrics collection. Defaults to ["AWS/SQS", "AWS/ElasticMapReduce"]. AWS/SQS and AWS/ElasticMapReduce are excluded by defaul…
1 property 1 required
ObservabilityPipelineFieldValue
object
Represents a static key-value pair used in various processors.
2 properties 2 required
CaseResponse
object
Case response
1 property
ObservabilityPipelineDataAttributes
object
Defines the pipeline’s name and its components (sources, processors, and destinations).
2 properties 2 required
Date
integer
Date as Unix timestamp in milliseconds.
EntityV3Service
object
Schema for service entities.
7 properties 3 required
EntityResponseIncludedSchemaType
string
Schema type.
SpansMetricResponseGroupBy
object
A group by rule.
2 properties
ObservabilityPipelineDatadogAgentSourceType
string
The source type. The value should always be datadogagent.
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
ObservabilityPipelineFluentBitSourceType
string
The source type. The value should always be fluentbit.
WorkflowDataType
string
The definition of WorkflowDataType object.
RoleCloneRequest
object
Request to create a role by cloning an existing role.
1 property 1 required
MonitorConfigPolicyResourceType
string
Monitor configuration policy resource type.
RelationshipToTeamLinkData
object
Relationship between a link and a team
2 properties 2 required
RumMetricResponse
object
The rum-based metric object.
1 property
ActionQuerySpecInput
object
The inputs to the action query. See the [Actions Catalog](https://docs.datadoghq.com/actions/actionscatalog/) for more detail on each action and its inputs.
RUMApplication
object
RUM application.
3 properties 3 required
ServiceDefinitionV1ResourceType
string
Link type.
CaseStatus
string
Case status
TeamLinkType
string
Team link type
ServiceDefinitionV2Dot2Contact
object
Service owner's contacts information.
3 properties 2 required
BudgetEntry
object
The entry of a budget.
3 properties
CustomDestinationHttpDestinationAuth
Authentication method of the HTTP requests.
AuthNMappingTeamAttributes
object
Team attributes.
7 properties
MicrosoftTeamsWorkflowsWebhookHandleResponse
object
Response of a Workflows webhook handle.
1 property 1 required
MonitorConfigPolicyAttributeCreateRequest
object
Policy and policy type for a monitor configuration policy.
2 properties 2 required
EntityV3ServiceKind
string
The definition of Entity V3 Service Kind object.
ObservabilityPipelineSensitiveDataScannerProcessorScopeAll
object
Applies scanning across all available fields.
1 property 1 required
SecurityMonitoringStandardRuleCreatePayload
object
Create a new rule.
13 properties 6 required
CloudWorkloadSecurityAgentRuleType
string
The type of the resource, must always be agentrule
EntityV3DatadogIntegrationPagerduty
object
A PagerDuty integration schema.
1 property 1 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeOptions
object
Fields to which the scope rule applies.
1 property 1 required
RoleCreateRequest
object
Create a role.
1 property 1 required
AWSMetricsConfig
object
AWS Metrics Collection config.
6 properties
ObservabilityPipelineSplunkHecDestinationEncoding
string
Encoding format for log events.
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property 1 required
OutcomesBatchResponseData
array
List of rule outcomes which were affected during the bulk operation.
DataTransform
object
A data transformer, which is custom JavaScript code that executes and transforms data when its inputs change.
4 properties 4 required
UserResponseIncludedItem
An object related to a user.
LayerType
string
Layers resource type.
ObservabilityPipelineRsyslogSourceType
string
The source type. The value should always be rsyslog.
ObservabilityPipelineOcsfMappingLibrary
string
Predefined library mappings for common log formats.
ScheduleCreateRequestDataAttributesLayersItems
object
Describes a schedule layer, including rotation intervals, members, restrictions, and timeline settings.
7 properties 5 required
RuleSeverity
string
Severity of a security rule.
CreateNotificationRuleParametersData
object
Data of the notification rule create request: the rule type, and the rule attributes. All fields are required.
2 properties 2 required
ActionQueryOnlyTriggerManually
Determines when this query is executed. If set to false, the query will run when the app loads and whenever any query arguments change. If set to true, the que…
IncidentTeamCreateRequest
object
Create request with an incident team payload.
1 property 1 required
CreateRuleResponseData
object
Create rule response data.
4 properties
EscalationPolicyUserAttributes
object
Provides basic user information for an escalation policy, including a name and email address.
3 properties
MicrosoftTeamsTenantBasedHandleResponse
object
Response of a tenant-based handle.
1 property 1 required
CreateCustomFrameworkResponse
object
Response object to create a custom framework.
1 property 1 required
RestrictionQueryCreatePayload
object
Create a restriction query.
1 property
ActionConnectionDataType
string
The definition of ActionConnectionDataType object.
EscalationPolicyIncluded
Represents included related resources when retrieving an escalation policy, such as teams, steps, or targets.
ServiceDefinitionV2Version
string
Schema version being used.
SecurityMonitoringSignalRuleQuery
object
Query for matching rule on signals.
6 properties 1 required
SecurityTriggerWrapper
object
Schema for a Security-based trigger.
2 properties 1 required
ScheduleDataRelationships
object
Groups the relationships for a schedule object, referencing layers and teams.
2 properties
NotificationRuleResponse
object
Response object which includes a notification rule.
1 property
RumRetentionFilterResponse
object
The RUM retention filter object.
1 property
LogsRestrictionQueriesType
string
Restriction query resource type.
EntityAttributes
object
Entity attributes.
8 properties
MonitorConfigPolicyTagPolicyCreateRequest
object
Tag attributes of a monitor configuration policy.
3 properties 3 required
ServiceDefinitionV2Dot1MSTeamsType
string
Contact type.
APIErrorResponse
object
API error response.
1 property 1 required
ObservabilityPipelineAmazonOpenSearchDestination
object
The amazonopensearch destination writes logs to Amazon OpenSearch.
5 properties 4 required
LogsMetricID
string
The name of the log-based metric.
ActionQueryRequiresConfirmation
Whether to prompt the user to confirm this query before it runs.
ObservabilityPipelineEnrichmentTableGeoIp
object
Uses a GeoIP database to enrich logs based on an IP field.
3 properties 3 required
LayerRelationshipsMembersDataItemsType
string
Members resource type.
OpenAPIFile
object
Object for API data in an OpenAPI format as a file.
1 property
RunRetentionFilterName
string
The name of a RUM retention filter.
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties 1 required
RetentionFilterType
string
The type of retention filter. The value should always be spans-sampling-processor.
BudgetWithEntries
object
The definition of the BudgetWithEntries object.
1 property
EntityV3MetadataAdditionalOwnersItems
object
The definition of Entity V3 Metadata Additional Owners Items object.
2 properties 1 required
ApplicationSecurityWafCustomRuleActionParameters
object
The definition of ApplicationSecurityWafCustomRuleActionParameters object.
2 properties
RetentionFilterCreateResponse
object
The retention filters definition.
1 property
ProjectCreate
object
Project create
2 properties 2 required
ServiceDefinitionV2Dot1MSTeams
object
Service owner's Microsoft Teams.
3 properties 2 required
SensitiveDataScannerRuleType
string
Sensitive Data Scanner rule type.
RelationshipToSAMLAssertionAttribute
object
AuthN Mapping relationship to SAML Assertion Attribute.
1 property 1 required
AWSNamespaceFilters
AWS Metrics namespace filters. Defaults to excludeonly.
ReadinessGate
object
Used to merge multiple branches into a single branch.
1 property 1 required
AuthNMappingCreateRequest
object
Request for creating an AuthN Mapping.
1 property 1 required
EntityV3DatadogPipelines
object
CI Pipelines association.
1 property
EntityV3System
object
Schema for system entities.
7 properties 3 required
EscalationPolicyData
object
Represents the data for a single escalation policy, including its attributes, ID, relationships, and resource type.
4 properties 1 required
EntityV3MetadataLinksItems
object
The definition of Entity V3 Metadata Links Items object.
4 properties 3 required
RelationshipToOrganizations
object
Relationship to organizations.
1 property 1 required
LeakedKeyType
string
The definition of LeakedKeyType object.
WorkflowData
object
Data related to the workflow.
4 properties 2 required
EscalationPolicyCreateRequestDataAttributesStepsItems
object
Defines a single escalation step within an escalation policy creation request. Contains assignment strategy, escalation timeout, and a list of targets.
3 properties 1 required
RUMApplicationCreate
object
RUM application creation.
2 properties 2 required
SecurityFilterType
string
The type of the resource. The value should always be securityfilters.
WorkflowUserRelationshipData
object
The definition of WorkflowUserRelationshipData object.
2 properties 2 required
NullableRelationshipToUser
object
Relationship to user.
1 property 1 required
IncidentTriggerWrapper
object
Schema for an Incident-based trigger.
2 properties 1 required
SecurityMonitoringRuleNewValueOptions
object
Options on new value detection method.
4 properties
SensitiveDataScannerRule
object
Rule item included in the group.
2 properties
ServiceDefinitionV1
object
Deprecated - Service definition V1 for providing additional service metadata and integrations.
8 properties 2 required
HTTPToken
object
The definition of HTTPToken object.
3 properties 3 required
ObservabilityPipelineSumoLogicDestinationEncoding
string
The output encoding format.
LogsArchiveCreateRequestAttributes
object
The attributes associated with the archive.
6 properties 3 required
AWSAccountConfigID
string
Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/ap…
ExternalUserGroupMeta
object
Metadata associated with a group.
4 properties
CustomDestinationForwardDestinationHttp
object
The HTTP destination.
3 properties 3 required
Project
object
A Project
4 properties 3 required
DataTransformType
string
The data transform type.
ExternalUserGroupMembersItems
object
The definition of a member belonging to a group.
4 properties
IncidentAttachmentRelatedObject
string
The object related to an incident attachment.
JSONAPIErrorItem
object
API error response body
5 properties
CustomDestinationResponseHttpDestinationAuthCustomHeader
object
Custom header access authentication.
2 properties 2 required
SensitiveDataScannerRuleCreate
object
Data related to the creation of a rule.
3 properties 3 required
MetricCustomAggregations
array
Deprecated. You no longer need to configure specific time and space aggregations for Metrics Without Limits.
LeakedKeyAttributes
object
The definition of LeakedKeyAttributes object.
2 properties 1 required
AuthNMappingResponse
object
AuthN Mapping response from the API.
2 properties
SecurityMonitoringStandardRuleQuery
object
Query for matching rule.
9 properties
ScheduleMemberRelationshipsUser
object
Wraps the user data reference for a schedule member.
1 property 1 required
AzureUCConfigPostData
object
Azure config Post data.
2 properties 2 required
PageUrgency
string
On-Call Page urgency level.
MetricCustomSpaceAggregation
string
A space aggregation for use in query.
EntityV3MetadataContactsItems
object
The definition of Entity V3 Metadata Contacts Items object.
3 properties 2 required
ObservabilityPipelineElasticsearchDestination
object
The elasticsearch destination writes logs to an Elasticsearch cluster.
5 properties 3 required
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternType
string
Indicates a custom regular expression is used for matching.
CreateOpenAPIResponseAttributes
object
Attributes for CreateOpenAPI.
1 property
ObservabilityPipelineGcpAuth
object
GCP credentials used to authenticate with Google Cloud Storage.
1 property 1 required
ObservabilityPipelineRenameFieldsProcessor
object
The renamefields processor changes field names.
5 properties 5 required
IncidentTeamIncludedItems
An object related to an incident team which is present in the included payload.
ProjectResponse
object
Project response
1 property
ObservabilityPipelineThrottleProcessorType
string
The processor type. The value should always be throttle.
ObservabilityPipelineSampleProcessorType
string
The processor type. The value should always be sample.
ObservabilityPipelineEnrichmentTableProcessorType
string
The processor type. The value should always be enrichmenttable.
RelationshipArray
array
Relationships.
SecurityMonitoringRuleSeverity
string
Severity of the Security Signal.
ObservabilityPipelineSyslogSourceMode
string
Protocol used by the syslog source to receive messages.
OpsgenieServiceResponseAttributes
object
The attributes from an Opsgenie service response.
3 properties
ObservabilityPipelineSplunkHecDestinationType
string
The destination type. Always splunkhec.
SensitiveDataScannerGroupData
object
A scanning group data.
1 property
IncidentCreateRelationships
object
The relationships the incident will have with other resources once created.
1 property 1 required
SpansMetricCreateRequest
object
The new span-based metric body.
1 property 1 required
RumRetentionFilterQuery
string
The query string for a RUM retention filter.
SensitiveDataScannerGroupAttributes
object
Attributes of the Sensitive Data Scanner group.
5 properties
RestrictionQueryCreateAttributes
object
Attributes of the created restriction query.
1 property
IncidentAttachmentUpdateData
object
A single incident attachment.
3 properties 1 required
ServiceDefinitionV2Dot1Email
object
Service owner's email.
3 properties 2 required
SensitiveDataScannerRuleRelationships
object
Relationships of a scanning rule.
2 properties
ApplicationKeyCreateRequest
object
Request used to create an application key.
1 property 1 required
CreateNotificationRuleParametersDataAttributes
object
Attributes of the notification rule create request.
5 properties 3 required
RoleResponseRelationships
object
Relationships of the role object returned by the API.
1 property
EntityV3ServiceSpec
object
The definition of Entity V3 Service Spec object.
6 properties
InputSchemaParameters
object
The definition of InputSchemaParameters object.
5 properties 2 required
ObservabilityPipelineAddEnvVarsProcessorVariable
object
Defines a mapping between an environment variable and a log field.
2 properties 2 required
EntityV3Queue
object
Schema for queue entities.
7 properties 3 required
SecurityFilterExclusionFilterResponse
object
A single exclusion filter.
2 properties
IncidentRespondersType
string
The incident responders type.
ApmRetentionFilterType
string
The type of the resource.
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties 2 required
ObservabilityPipelineQuotaProcessorType
string
The processor type. The value should always be quota.
JiraIssue
object
Jira issue attached to case
2 properties
ApplicationSecurityWafExclusionFilterType
string
Type of the resource. The value should always be exclusionfilter.
ObservabilityPipelineReduceProcessorType
string
The processor type. The value should always be reduce.
EscalationPolicyDataAttributes
object
Defines the main attributes of an escalation policy, such as its name and behavior on policy end.
3 properties 1 required
ObservabilityPipelineTls
object
Configuration for enabling TLS encryption between the pipeline component and external services.
3 properties 1 required
EntityRelationships
object
Entity relationships.
5 properties
ServiceDefinitionV2Dot1Contact
Service owner's contacts information.
LogsArchiveDestinationS3
object
The S3 archive destination.
6 properties 3 required
ObservabilityPipelineEnrichmentTableFileSchemaItemsType
string
Declares allowed data types for enrichment table columns.
ObservabilityPipelineRenameFieldsProcessorField
object
Defines how to rename a field in log events.
3 properties 3 required
MetricTagConfiguration
object
Object for a single metric tag configuration.
3 properties
IncidentServiceResponse
object
Response with an incident service payload.
2 properties 1 required
SecurityMonitoringRuleNewValueOptionsLearningMethod
string
The learning method used to determine when signals should be generated for values that weren't learned.
SensitiveDataScannerGroupRelationships
object
Relationships of the group.
2 properties
ServiceDefinitionV2Dot2Link
object
Service's external links.
4 properties 3 required
GCPSTSServiceAccountResponse
object
The account creation response.
1 property
ObservabilityPipelineOcsfMapperProcessor
object
The ocsfmapper processor transforms logs into the OCSF schema using a predefined mapping configuration.
5 properties 5 required
AwsCURConfigPostRequestType
string
Type of AWS CUR config Post Request.
RumRetentionFilterData
object
The RUM retention filter.
3 properties
CloudConfigurationRuleCaseCreate
object
Description of signals.
2 properties 1 required
CloudWorkloadSecurityAgentRuleCreateAttributes
object
Create a new Cloud Workload Security Agent rule.
11 properties 2 required
RelationshipToPermissions
object
Relationship to multiple permissions objects.
1 property
IncidentTeamRelationships
object
The incident team's relationships.
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationStorageClass
string
Storage class used for objects stored in GCS.
PowerpackRelationships
object
Powerpack relationship object.
1 property
ObservabilityPipelineRemoveFieldsProcessorType
string
The processor type. The value should always be removefields.
SensitiveDataScannerConfiguration
object
A Sensitive Data Scanner configuration.
2 properties
AwsCURConfigType
string
Type of AWS CUR config.
CasePriority
string
Case priority
LogsArchiveDestination
object
An archive's destination.
ActionQueryShowToastOnError
Whether to display a toast to the user when the query returns an error.
EntityV3DatadogEventItem
object
Events association item.
2 properties
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
RumMetricType
string
The type of the resource. The value should always be rummetrics.
SecurityMonitoringRuleThirdPartyOptions
object
Options on third party detection method.
4 properties
CaseAttributes
object
Case attributes
12 properties
RumMetricComputeAggregationType
string
The type of aggregation to use.
EntityV3ServiceDatadog
object
Datadog product integrations for the service entity.
5 properties
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties 2 required
ApplicationSecurityWafCustomRuleConditionOperator
string
Operator to use for the WAF Condition.
ScheduleMemberRelationships
object
Defines relationships for a schedule member, primarily referencing a single user.
1 property
UpsertCatalogEntityRequest
Create or update entity request.
CustomDestinationResponseHttpDestinationAuth
Authentication method of the HTTP requests.
IncidentServiceCreateAttributes
object
The incident service's attributes for a create request.
1 property 1 required
MonitorConfigPolicyCreateRequest
object
Request for creating a monitor configuration policy.
1 property 1 required
RelationshipToRole
object
Relationship to role.
1 property
ServiceDefinitionMeta
object
Metadata about a service definition.
7 properties
SecurityMonitoringUser
object
A user.
2 properties
EscalationPolicyDataRelationshipsStepsDataItemsType
string
Indicates that the resource is of type steps.
MetricTagConfigurationAttributes
object
Object containing the definition of a metric tag configuration attributes.
7 properties
ApplicationKeyResponse
object
Response for retrieving an application key.
2 properties
GCPSTSServiceAccountData
object
Additional metadata on your generated service account.
2 properties
ScheduleTarget
object
Represents a schedule target for an escalation policy step, including its ID and resource type.
2 properties 2 required
SensitiveDataScannerProduct
string
Datadog product onto which Sensitive Data Scanner can be activated.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExcludeTarget
string
Excludes specific fields from processing.
IncidentTodoCreateRequest
object
Create request for an incident todo.
1 property 1 required
ServiceDefinitionV2Email
object
Service owner's email.
3 properties 2 required
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
CreatePageRequestDataType
string
The type of resource used when creating an On-Call Page.
MicrosoftTeamsTenantBasedHandleRequestData
object
Tenant-based handle data from a response.
2 properties 2 required
ServiceDefinitionCreateResponse
object
Create service definitions response.
1 property
EscalationTargets
object
A list of escalation targets for a step
1 property
AuthNMappingTeam
object
Team.
3 properties
WorkflowDataRelationships
object
The definition of WorkflowDataRelationships object.
2 properties
ApplicationSecurityWafCustomRuleMetadata
object
Metadata associated with the WAF Custom Rule.
6 properties
UserResponseRelationships
object
Relationships of the user object returned by the API.
4 properties
RumMetricGroupBy
object
A group by rule.
2 properties 1 required
ScheduleCreateRequestDataAttributes
object
Describes the main attributes for creating a new schedule, including name, layers, and time zone.
3 properties 3 required
MonitorNotificationRuleFilterTags
object
Filter monitors by tags. Monitors must match all tags.
1 property 1 required
Parameter
object
The definition of Parameter object.
2 properties 2 required
ActionConnectionData
object
Data related to the connection.
3 properties 2 required
ObservabilityPipelineSyslogNgDestination
object
The syslogng destination forwards logs to an external syslog-ng server over TCP or UDP using the syslog protocol.
5 properties 3 required
ObservabilityPipelineEnrichmentTableFileKeyItems
object
Defines how to map log fields to enrichment table columns during lookups.
3 properties 3 required
EntityV3APISpecInterface
The API definition.
CustomDestinationResponseHttpDestinationAuthBasicType
string
Type of the basic access authentication.
SecurityMonitoringRuleImpossibleTravelOptionsBaselineUserLocations
boolean
If true, signals are suppressed for the first 24 hours. In that time, Datadog learns the user's regular access locations. This can be helpful to reduce noise a…
ObservabilityPipelineDatadogAgentSource
object
The datadogagent source collects logs from the Datadog Agent.
3 properties 2 required
AuthNMappingCreateRelationships
Relationship of AuthN Mapping create object to a Role or Team.
RelationshipToUsers
object
Relationship to users.
1 property 1 required
ActionConnectionIntegration
The definition of ActionConnectionIntegration object.
ChangeEventTriggerWrapper
object
Schema for a Change Event-based trigger.
2 properties 1 required
CloudWorkloadSecurityAgentRuleResponse
object
Response object that includes an Agent rule
1 property
PermissionsType
string
Permissions resource type.
LogsMetricCreateData
object
The new log-based metric properties.
3 properties 3 required
RelationshipItem
object
Relationship entry.
2 properties
IncidentTeamCreateAttributes
object
The incident team's attributes for a create request.
1 property 1 required
SloReportCreateRequest
object
The SLO report request body.
1 property 1 required
ComponentGridType
string
The grid component type.
CustomFrameworkRequirement
object
Framework Requirement.
2 properties 2 required
MetricTagConfigurationResponse
object
Response object which includes a single metric's tag configuration.
1 property
RumMetricCreateData
object
The new rum-based metric properties.
3 properties 3 required
IncidentServiceResponseData
object
Incident Service data from responses.
4 properties 2 required
StateVariable
object
A variable, which can be set and read by other components in the app.
4 properties 4 required
SpansMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
CloudConfigurationRuleType
string
The rule type.
AWSLogsConfig
object
AWS Logs Collection config.
1 property
RelationshipToSAMLAssertionAttributeData
object
Data of AuthN Mapping relationship to SAML Assertion Attribute.
2 properties 2 required
LogsMetricResponseAttributes
object
The object describing a Datadog log-based metric.
3 properties
NotificationRuleAttributes
object
Attributes of the notification rule.
10 properties 9 required
RumMetricUniqueness
object
The rule to count updatable events. Is only set if eventtype is sessions or views.
1 property 1 required
SensitiveDataScannerIncludedKeywordConfiguration
object
Object defining a set of keywords and a number of characters that help reduce noise. You can provide a list of keywords you would like to check within a define…
3 properties 2 required
EscalationTarget
Represents an escalation target, which can be a team, user, or schedule.
ApplicationSecurityWafCustomRuleCondition
object
One condition of the WAF Custom Rule.
2 properties 2 required
CreateCustomFrameworkRequest
object
Request object to create a custom framework.
1 property 1 required
ObservabilityPipelineOpenSearchDestinationType
string
The destination type. The value should always be opensearch.
AuthNMapping
object
The AuthN Mapping object returned by API.
4 properties 2 required
CreateAppResponseData
object
The data object containing the app ID.
2 properties 2 required
ObservabilityPipelineSpec
object
Input schema representing an observability pipeline configuration. Used in create and validate requests.
1 property 1 required
AppDefinitionType
string
The app definition type.
IncidentTodoAssignee
A todo assignee.
SensitiveDataScannerMetaVersionOnly
object
Meta payload containing information about the API.
1 property
IncidentTodoAssigneeArray
array
Array of todo assignees.
MicrosoftTeamsWorkflowsWebhookHandleResponseData
object
Workflows Webhook handle data from a response.
3 properties
CustomDestinationResponseHttpDestinationAuthBasic
object
Basic access authentication.
1 property 1 required
DatabaseMonitoringTriggerWrapper
object
Schema for a Database Monitoring-based trigger.
2 properties 1 required
RUMApplicationResponse
object
RUM application response.
1 property
CloudWorkloadSecurityAgentPolicyCreateData
object
Object for a single Agent rule
2 properties 2 required
ActionQueryMockedOutputsEnabled
Whether to enable the mocked outputs for testing.
ObservabilityPipelineSumoLogicDestination
object
The sumologic destination forwards logs to Sumo Logic.
8 properties 3 required
EntityResponseIncludedSchemaAttributes
object
Included schema.
1 property
RuleOutcomeRelationships
object
The JSON:API relationship to a scorecard rule.
1 property
MonitorNotificationRuleResponse
object
A monitor notification rule.
2 properties
SensitiveDataScannerConfigurationType
string
Sensitive Data Scanner configuration type.
CaseRelationships
object
Resources related to a case
4 properties
Schedule
object
Top-level container for a schedule object, including both the data payload and any related included resources (such as teams, layers, or members).
2 properties
EntityToIncidents
object
Entity to incidents relationship.
1 property
LogsArchiveCreateRequestDestination
An archive's destination.
ObservabilityPipelineRemoveFieldsProcessor
object
The removefields processor deletes specified fields from logs.
5 properties 5 required
WorkflowDataAttributes
object
The definition of WorkflowDataAttributes object.
8 properties 2 required
RUMApplicationCreateType
string
RUM application creation type.
AnnotationMarkdownTextAnnotation
object
The definition of AnnotationMarkdownTextAnnotation object.
1 property
OutputSchemaParameters
object
The definition of OutputSchemaParameters object.
6 properties 2 required
RumMetricResponseGroupBy
object
A group by rule.
2 properties
EntityV3QueueSpec
object
The definition of Entity V3 Queue Spec object.
4 properties
ServiceDefinitionV1Pagerduty
string
PagerDuty service URL for the service.
ApplicationKeyCreateAttributes
object
Attributes used to create an application Key.
2 properties 1 required
ObservabilityPipelineAddFieldsProcessor
object
The addfields processor adds static key-value fields to logs.
5 properties 5 required
ObservabilityPipelineLogstashSource
object
The logstash source ingests logs from a Logstash forwarder.
3 properties 2 required
CloudWorkloadSecurityAgentPolicyResponse
object
Response object that includes an Agent policy
1 property
CustomFrameworkControl
object
Framework Control.
2 properties 2 required
ScheduleUserType
string
Users resource type.
ObservabilityPipelineAddFieldsProcessorType
string
The processor type. The value should always be addfields.
GCPSTSDelegateAccountType
string
The type of account.
MetricTagConfigurationCreateRequest
object
Request object that includes the metric that you would like to configure tags for.
1 property 1 required
RumRetentionFilterCreateRequest
object
The RUM retention filter body to create.
1 property 1 required
IncidentIntegrationMetadataCreateData
object
Incident integration metadata data for a create request.
2 properties 2 required
ServiceDefinitionV2Doc
object
Service documents.
3 properties 2 required
MicrosoftTeamsTenantBasedHandleResponseData
object
Tenant-based handle data from a response.
3 properties
ObservabilityPipelineEnrichmentTableProcessor
object
The enrichmenttable processor enriches logs using a static CSV file or GeoIP database.
7 properties 5 required
SpansMetricID
string
The name of the span-based metric.
ServiceDefinitionV2Repo
object
Service code repositories.
3 properties 2 required
ServiceDefinitionV1Resource
object
Service's external links.
3 properties 3 required
IncidentImpactsType
string
The incident impacts type.
RelationshipToRoleData
object
Relationship to role object.
2 properties
SecurityFilterCreateRequest
object
Request object that includes the security filter that you would like to create.
1 property 1 required
EntityV3SystemDatadog
object
Datadog product integrations for the service entity.
4 properties
ExternalUser
object
Definition of a user.
8 properties
OutcomesBatchResponse
object
Scorecard outcomes batch response.
2 properties 2 required
ObservabilityPipelineAmazonOpenSearchDestinationAuth
object
Authentication settings for the Amazon OpenSearch destination. The strategy field determines whether basic or AWS-based authentication is used.
5 properties 1 required
SpansMetricResponseData
object
The span-based metric properties.
3 properties
AWSTracesConfig
object
AWS Traces Collection config.
1 property
CloudWorkloadSecurityAgentPolicyUpdaterAttributes
object
The attributes of the user who last updated the policy
2 properties
CloudWorkloadSecurityAgentRuleCreateData
object
Object for a single Agent rule
2 properties 2 required
AWSRegionsIncludeOnly
object
Include only these regions.
1 property 1 required
SensitiveDataScannerRuleData
object
Rules included in the group.
1 property
CustomDestinationResponseForwardDestinationSplunk
object
The Splunk HTTP Event Collector (HEC) destination.
2 properties 2 required
TokenName
string
Name for tokens.
ID
string
The ID of a notification rule.
SensitiveDataScannerGroupType
string
Sensitive Data Scanner group type.
SensitiveDataScannerGroupResponse
object
Response data related to the creation of a group.
4 properties
MicrosoftTeamsWorkflowsWebhookHandleRequestData
object
Workflows Webhook handle data from a response.
2 properties 2 required
PowerpackResponse
object
Response object which includes a single powerpack configuration.
2 properties
ServiceDefinitionRaw
string
Service Definition in raw JSON/YAML representation.
ServiceDefinitionV2Dot1Opsgenie
object
Opsgenie integration for the service.
2 properties 1 required
ActionQueryProperties
object
The properties of the action query.
9 properties 1 required
SecurityMonitoringStandardRuleResponse
object
Rule.
24 properties
CloudConfigurationRuleOptions
object
Options on cloud configuration rules.
1 property 1 required
PowerpackInnerWidgets
object
Powerpack group widget definition of individual widgets.
2 properties 1 required
UserTargetType
string
Indicates that the resource is of type users.
SecurityMonitoringRuleDetectionMethod
string
The detection method.
ObservabilityPipelineQuotaProcessor
object
The Quota Processor measures logging traffic for logs that match a specified filter. When the configured daily quota is met, the processor can drop or alert.
11 properties 7 required
Annotation
object
A list of annotations used in the workflow. These are like sticky notes for your workflow!
3 properties 3 required
SecurityMonitoringRuleNewValueOptionsLearningThreshold
integer
A number of occurrences after which signals will be generated for values that weren't learned.
EntityV3
Entity schema v3.
ComponentType
string
The UI component type.
GithubWebhookTrigger
object
Trigger a workflow from a GitHub webhook. To trigger a workflow from GitHub, you must set a webhookSecret. In your GitHub Webhook Settings, set the Payload URL…
1 property
APIKeyResponse
object
Response for retrieving an API key.
2 properties
IncidentIntegrationMetadataType
string
Integration metadata resource type.
TeamLink
object
Team link
3 properties 3 required
FullAPIKey
object
Datadog API key.
4 properties
ObservabilityPipelineSensitiveDataScannerProcessorRule
object
Defines a rule for detecting sensitive data, including matching pattern, scope, and the action to take.
6 properties 5 required
UserAttributesStatus
string
The user's status.
WidgetLiveSpan
string
The available timeframes depend on the widget you are using.
EscalationPolicyStepAttributesAssignment
string
Specifies how this escalation step will assign targets (example default or round-robin).
LogsMetricCreateRequest
object
The new log-based metric body.
1 property 1 required
SecurityMonitoringRuleDecreaseCriticalityBasedOnEnv
boolean
If true, signals in non-production environments have a lower severity than what is defined by the rule case, which can reduce signal noise. The severity is dec…
JiraIntegrationMetadataIssuesItem
object
Item in the Jira integration metadata issue array.
5 properties 2 required
ApplicationSecurityWafCustomRuleConditionInputAddress
string
Input from the request on which the condition should apply.
EscalationPolicyUserType
string
Users resource type.
RelationshipToUser
object
Relationship to user.
1 property 1 required
RelationshipToTeamData
object
Relationship to Team object.
2 properties
AuthNMappingCreateData
object
Data for creating an AuthN Mapping.
3 properties 1 required
AWSAccountID
string
AWS Account ID.
ObservabilityPipelineGeneratedMetricIncrementByFieldStrategy
string
Uses a numeric field in the log event as the metric increment.
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
SensitiveDataScannerStandardPatternData
object
A standard pattern.
1 property
ComponentGridProperties
object
Properties of a grid component.
3 properties
TriggerRateLimit
object
Defines a rate limit for a trigger.
2 properties
ObservabilityPipelineAmazonDataFirehoseSource
object
The amazondatafirehose source ingests logs from AWS Data Firehose.
4 properties 2 required
SpansMetricResponseCompute
object
The compute rule to compute the span-based metric.
3 properties
ObservabilityPipelineRsyslogDestination
object
The rsyslog destination forwards logs to an external rsyslog server over TCP or UDP using the syslog protocol.
5 properties 3 required
Targets
array
List of recipients to notify when a notification rule is triggered. Many different target types are supported, such as email addresses, Slack channels, and Pag…
ObservabilityPipelineSensitiveDataScannerProcessorActionHash
object
Configuration for hashing matched sensitive values.
2 properties 1 required
ServiceDefinitionV2Dot2Version
string
Schema version being used.
EscalationPolicy
object
Represents a complete escalation policy response, including policy data and optionally included related resources.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorKeywordOptions
object
Configuration for keywords used to reinforce sensitive data pattern detection.
2 properties 2 required
ObservabilityPipelineSumoLogicSourceType
string
The source type. The value should always be sumologic.
RetentionFilterCreateRequest
object
The body of the retention filter to be created.
1 property 1 required
SpansMetricResponseFilter
object
The span-based metric filter. Spans matching this filter will be aggregated in this metric.
1 property
SensitiveDataScannerRuleResponse
object
Response data related to the creation of a rule.
4 properties
AuthNMappingCreateAttributes
object
Key/Value pair of attributes used for create request.
2 properties
ApplicationSecurityWafCustomRuleConditionInput
object
Input from the request on which the condition should apply.
2 properties 1 required
ObservabilityPipelineSentinelOneDestinationType
string
The destination type. The value should always be sentinelone.
ApplicationSecurityWafCustomRuleScope
object
The scope of the WAF custom rule.
2 properties 2 required
ActionQuerySpecConnectionGroup
object
The connection group to use for an action query.
2 properties
AWSAuthConfigKeys
object
AWS Authentication config to integrate your account using an access key pair.
2 properties 1 required
XRayServicesList
AWS X-Ray services to collect traces from. Defaults to includeonly.
MonitorNotificationRuleResponseIncludedItem
An object related to a monitor notification rule.
SecurityMonitoringThirdPartyRuleCase
object
Case when signal is generated by a third party rule.
4 properties
OpsgenieServiceType
string
Opsgenie service resource type.
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
IncidentTypeCreateData
object
Incident type data for a create request.
2 properties 2 required
APITriggerWrapper
object
Schema for an API-based trigger.
2 properties 1 required
CaseCreateAttributes
object
Case creation attributes
4 properties 2 required
ObservabilityPipelineSumoLogicDestinationHeaderCustomFieldsItem
object
Single key-value pair used as a custom log header for Sumo Logic.
2 properties 2 required
RuleId
string
The unique ID for a scorecard rule.
HTTPTokenAuthType
string
The definition of HTTPTokenAuthType object.
TeamRelationshipsLinks
object
Links attributes.
1 property
AWSResourcesConfig
object
AWS Resources Collection config.
2 properties
AWSAccountResponseAttributes
object
AWS Account response attributes.
11 properties 1 required
CreatePageRequestDataAttributesTarget
object
Information about the target to notify (such as a team or user).
2 properties
IncidentTypeCreateRequest
object
Create request for an incident type.
1 property 1 required
CreateNotificationRuleParameters
object
Body of the notification rule create request.
1 property
CompletionGate
object
Used to create conditions before running subsequent actions.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeAllTarget
string
Applies the rule to all fields.
ApplicationSecurityWafCustomRuleType
string
The type of the resource. The value should always be customrule.
LogsMetricResponseFilter
object
The log-based metric filter. Logs matching this filter will be aggregated in this metric.
1 property
PowerpackTemplateVariable
object
Powerpack template variables.
4 properties 1 required
RestrictionQueryWithoutRelationships
object
Restriction query object returned by the API.
3 properties
ObservabilityPipelineRsyslogSource
object
The rsyslog source listens for logs over TCP or UDP from an rsyslog server using the syslog protocol.
4 properties 3 required
APITrigger
object
Trigger a workflow from an API request. The workflow must be published.
1 property
IncidentAttachmentAttributes
The attributes object for an attachment.
AuthNMappingIncluded
Included data in the AuthN Mapping response.
RUMApplicationCreateRequest
object
RUM application creation request attributes.
1 property 1 required
RuleTypesItems
string
Security rule type which can be used in security rules. Signal-based notification rules can filter signals based on rule types applicationsecurity, logdetectio…
ServiceDefinitionSchema
Service definition schema.
SensitiveDataScannerRuleAttributes
object
Attributes of the Sensitive Data Scanner rule.
10 properties
ActionQuerySpecInputs
The inputs to the action query. These are the values that are passed to the action when it is triggered.
MonitorNotificationRuleId
string
The ID of the monitor notification rule.
StepDisplayBounds
object
The definition of StepDisplayBounds object.
2 properties
MetricTagConfigurationType
string
The metric tag configuration resource type.
IncidentTodoAnonymousAssigneeSource
string
The source of the anonymous assignee.
ApiID
string
API identifier.
ObservabilityPipelineEnrichmentTableFileKeyItemsComparison
string
Defines how to compare key fields for enrichment table lookups.
SecurityMonitoringSignalRuleResponse
object
Rule.
18 properties
EntityV3APISpecInterfaceDefinition
object
The definition of EntityV3APISpecInterfaceDefinition object.
1 property
ObservabilityPipelineParseGrokProcessorRuleMatchRule
object
Defines a Grok parsing rule, which extracts structured fields from log content using named Grok patterns. Each rule must have a unique name and a valid Datadog…
2 properties 2 required
AWSLambdaForwarderConfig
object
Log Autosubscription configuration for Datadog Forwarder Lambda functions. Automatically set up triggers for existing and new logs for some services, ensuring…
2 properties
ObservabilityPipelineParseJSONProcessor
object
The parsejson processor extracts JSON from a specified field and flattens it into the event. This is useful when logs contain embedded JSON as a string.
5 properties 5 required
APIKeysType
string
API Keys resource type.
RelationshipToOrganization
object
Relationship to an organization.
1 property 1 required
SpansMetricCreateAttributes
object
The object describing the Datadog span-based metric to create.
3 properties 1 required
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
ComponentGridPropertiesIsVisible
Whether the grid component and its children are visible. If a string, it must be a valid JavaScript expression that evaluates to a boolean.
IncidentTodoRelationships
object
The incident's relationships from a response.
2 properties
ObservabilityPipelineReduceProcessorMergeStrategy
object
Defines how a specific field should be merged across grouped events.
2 properties 2 required
ServiceDefinitionV2Integrations
object
Third party integrations that Datadog supports.
2 properties
GCPSTSDelegateAccount
object
Datadog principal service account info.
3 properties
ObservabilityPipelineAmazonDataFirehoseSourceType
string
The source type. The value should always be amazondatafirehose.
MetricTagConfigurationCreateAttributes
object
Object containing the definition of a metric tag configuration to be created.
5 properties 2 required
SensitiveDataScannerGroupCreateRequest
object
Create group request.
2 properties
EntityResponseData
array
List of entity data.
MonitorConfigPolicyCreateData
object
A monitor configuration policy data.
2 properties 2 required
ReadinessGateThresholdType
string
The definition of ReadinessGateThresholdType object.
SecurityMonitoringRuleKeepAlive
integer
Once a signal is generated, the signal will remain "open" if a case is matched at least once within this keep alive window. For third party detection method, t…
CaseResourceType
string
Case resource type
ObservabilityPipelineDedupeProcessorType
string
The processor type. The value should always be dedupe.
ServiceDefinitionV2Dot2Pagerduty
object
PagerDuty integration for the service.
1 property
ObservabilityPipelineSentinelOneDestinationRegion
string
The SentinelOne region to send logs to.
SloReportCreateRequestAttributes
object
The attributes portion of the SLO report request.
5 properties 3 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptions
object
Controls how partial redaction is applied, including character count and direction.
2 properties 2 required
ObservabilityPipelineGeneratedMetricIncrementByField
object
Strategy that increments a generated metric based on the value of a log field.
2 properties 2 required
FullAPIKeyAttributes
object
Attributes of a full API key.
7 properties
Weekday
string
A day of the week.
DataTransformProperties
object
The properties of the data transformer.
1 property
EscalationPolicyStepRelationships
object
Represents the relationship of an escalation policy step to its targets.
1 property
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
LogsMetricGroupBy
object
A group by rule.
2 properties 1 required
ObservabilityPipelineGeneratedMetricMetricType
string
Type of metric to create.
CustomDestinationResponseForwardDestination
A custom destination's location to forward logs.
RelationshipToRule
object
Scorecard create rule response relationship.
1 property
SecurityMonitoringRuleImpossibleTravelOptions
object
Options on impossible travel detection method.
1 property
AzureUCConfigPairType
string
Type of Azure config pair.
CustomDestinationForwardDestination
A custom destination's location to forward logs.
Case3rdPartyTicketStatus
string
Case status
TeamAttributes
object
Team attributes
12 properties 2 required
Role
object
Role object returned by the API.
4 properties 1 required
CloudConfigurationComplianceRuleOptions
object
Options for cloudconfiguration rules. Fields resourceType and regoRule are mandatory when managing custom cloudconfiguration rules.
3 properties
CustomDestinationResponseElasticsearchDestinationAuth
object
Basic access authentication.
AuthNMappingsType
string
AuthN Mappings resource type.
ServiceDefinitionV2Dot1Pagerduty
object
PagerDuty integration for the service.
1 property
RumMetricCompute
object
The compute rule to compute the rum-based metric.
3 properties 1 required
OutboundEdge
object
The definition of OutboundEdge object.
2 properties 2 required
IncidentServiceIncludedItems
An object related to an incident service which is present in the included payload.
ScheduleRequestDataAttributesLayersItemsMembersItems
object
Defines a single member within a schedule layer, including the reference to the underlying user.
1 property
MonitorNotificationRuleRecipients
array
A list of recipients to notify. Uses the same format as the monitor message field. Must not start with an '@'.
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternOptions
object
Options for defining a custom regex pattern.
1 property 1 required
OutcomesBatchType
string
The JSON:API type for scorecard outcomes.
ObservabilityPipelineAwsAuth
object
AWS authentication credentials used for accessing AWS services such as S3. If omitted, the system’s default credentials are used (for example, the IAM role and…
3 properties
ObservabilityPipelineConfigProcessorItem
A processor for the pipeline.
OutcomesBatchRequestData
object
Scorecard outcomes batch request data.
2 properties
IncidentAttachmentUpdateAttributes
Incident attachment attributes.
CustomDestinationResponseDefinition
object
The definition of a custom destination.
3 properties
ServiceDefinitionV2LinkType
string
Link type.
ObservabilityPipelineReduceProcessor
object
The reduce processor aggregates and merges logs based on matching keys and merge strategies.
6 properties 6 required
RumMetricResponseFilter
object
The rum-based metric filter. RUM events matching this filter will be aggregated in this metric.
1 property
IncidentAttachmentsResponseIncludedItem
An object related to an attachment that is included in the response.
SecurityMonitoringFilter
object
The rule's suppression filter.
2 properties
AuthNMappingAttributes
object
Attributes of AuthN Mapping.
5 properties
EscalationPolicyCreateRequestDataAttributes
object
Defines the attributes for creating an escalation policy, including its description, name, resolution behavior, retries, and steps.
4 properties 2 required
JiraIssueResult
object
Jira issue information
4 properties
LogsArchiveDestinationGCSType
string
Type of the GCS archive destination.
ScheduleRequestDataAttributesLayersItemsMembersItemsUser
object
Identifies the user participating in this layer as a single object with an id.
1 property
TeamLinkAttributes
object
Team link attributes
4 properties 2 required
ActionQuery
object
An action query. This query type is used to trigger an action, such as sending a HTTP request.
5 properties 4 required
CaseCreate
object
Case creation data
3 properties 2 required
AwsCURConfigResponse
object
Response of AWS CUR config.
1 property
PermissionAttributes
object
Attributes of a permission.
7 properties
RelationshipToOutcome
object
The JSON:API relationship to a scorecard outcome.
1 property
NotificationRule
object
Notification rules allow full control over notifications generated by the various Datadog security products. They allow users to define the conditions under wh…
3 properties 3 required
ActionQueryPollingIntervalInMs
If specified, the app will poll the query at the specified interval in milliseconds. The minimum polling interval is 15 seconds. The query will only poll when…
LogsMetricResponse
object
The log-based metric object.
1 property
ApplicationSecurityWafExclusionFilterResponse
object
Response object for a single WAF exclusion filter.
1 property
SlackIntegrationMetadata
object
Incident integration metadata for the Slack integration.
1 property 1 required
IncidentTodoResponseData
object
Incident todo response data.
4 properties 2 required
IncidentIntegrationMetadataCreateRequest
object
Create request for an incident integration metadata.
1 property 1 required
SensitiveDataScannerTextReplacement
object
Object describing how the scanned event will be replaced.
3 properties
EscalationPolicyCreateRequest
object
Represents a request to create a new escalation policy, including the policy data.
1 property 1 required
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties 2 required
CloudWorkloadSecurityAgentRuleData
object
Object for a single Agent rule
3 properties
AWSAccountResponseData
object
AWS Account response data.
3 properties 2 required
RelationshipToTeam
object
Relationship to team.
1 property
SecurityMonitoringRuleCreatePayload
Create a new rule.
MonitorNotificationRuleRelationshipsCreatedBy
object
The user who created the monitor notification rule.
1 property
LayerRelationshipsMembers
object
Holds an array of references to the members of a Layer, each containing member IDs.
1 property
ProjectAttributes
object
Project attributes
2 properties
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeInclude
object
Includes only specific fields for sensitive data scanning.
2 properties 2 required
EntityV3Datastore
object
Schema for datastore entities.
7 properties 3 required
IncidentServiceType
string
Incident service resource type.
OutcomesBatchRequestItem
object
Scorecard outcome for a specific rule, for a given service within a batched update.
4 properties 3 required
MonitorConfigPolicyPolicyCreateRequest
Configuration for the policy.
ApplicationSecurityWafCustomRuleCreateAttributes
object
Create a new WAF custom rule.
8 properties 5 required
SecurityMonitoringSuppressionCreateRequest
object
Request object that includes the suppression rule that you would like to create.
1 property 1 required
EntityResponseMeta
object
Entity metadata.
2 properties
MonitorConfigPolicyAttributeResponse
object
Policy and policy type for a monitor configuration policy.
2 properties
LogsArchiveCreateRequestDefinition
object
The definition of an archive.
2 properties 1 required
SecurityTrigger
object
Trigger a workflow from a Security Signal or Finding. For automatic triggering a handle must be configured and the workflow must be published.
1 property
AwsCURConfigAttributes
object
Attributes for An AWS CUR config.
12 properties 6 required
ServiceDefinitionV2Dot1EmailType
string
Contact type.
IncidentTodoResponse
object
Response with an incident todo.
2 properties 1 required
SensitiveDataScannerCreateGroupResponse
object
Create group response.
2 properties
ObservabilityPipelineEnrichmentTableFileSchemaItems
object
Describes a single column and its type in an enrichment table schema.
2 properties 2 required
ObservabilityPipelineNewRelicDestinationType
string
The destination type. The value should always be newrelic.
HTTPCredentials
The definition of HTTPCredentials object.
ConnectionEnv
object
A list of connections or connection groups used in the workflow.
3 properties 1 required
RumMetricResponseCompute
object
The compute rule to compute the rum-based metric.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactAction
string
Action type that redacts part of the sensitive data while preserving a configurable number of characters, typically used for masking purposes (e.g., show last…
ExternalUserMeta
object
Metadata associated with a user.
4 properties
IncidentTimelineCellMarkdownCreateAttributesContent
object
The Markdown timeline cell contents.
1 property
CustomFrameworkDataAttributes
object
Framework Data Attributes.
6 properties 4 required
ExternalUserGroup
object
Definition of a group.
6 properties
CustomDestinationResponseForwardDestinationHttpType
string
Type of the HTTP destination.
LogsMetricResponseComputeAggregationType
string
The type of aggregation to use.
EntityToSchema
object
Entity to detail schema relationship.
1 property
SecurityMonitoringSignalRuleType
string
The rule type.
ServiceAccountCreateAttributes
object
Attributes of the created user.
4 properties 2 required
IncidentTodoAnonymousAssignee
object
Anonymous assignee entity.
4 properties 4 required
RetentionFilter
object
The definition of the retention filter.
3 properties 3 required
SensitiveDataScannerCreateRuleResponse
object
Create rule response.
2 properties
UserResourceType
string
User resource type.
CustomDestinationType
string
The type of the resource. The value should always be customdestination.
PowerpackInnerWidgetLayout
object
Powerpack inner widget layout.
4 properties 4 required
EntityV3APISpec
object
The definition of Entity V3 API Spec object.
5 properties
RetryStrategy
object
The definition of RetryStrategy object.
2 properties 1 required
IncidentAttachmentData
object
A single incident attachment.
4 properties 4 required
CaseType
string
Case type
RetryStrategyKind
string
The definition of RetryStrategyKind object.
CreatePageRequestDataAttributes
object
Details about the On-Call Page you want to create.
5 properties 3 required
MonitorNotificationRuleRelationshipsCreatedByData
object
Data for the user who created the monitor notification rule.
2 properties
SecurityFilterResponse
object
Response object which includes a single security filter.
2 properties
AWSAccountTags
array
Tags to apply to all hosts and metrics reporting for this account. Defaults to [].
IncidentTimelineCellMarkdownContentType
string
Type of the Markdown timeline cell.
ObservabilityPipelineGoogleCloudStorageDestination
object
The googlecloudstorage destination stores logs in a Google Cloud Storage (GCS) bucket. It requires a bucket name, GCP authentication, and metadata fields.
9 properties 7 required
IncidentServiceCreateRequest
object
Create request with an incident service payload.
1 property 1 required
CreateWorkflowRequest
object
A request object for creating a new workflow.
1 property 1 required
ServiceDefinitionV1Integrations
object
Third party integrations that Datadog supports.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorCustomPattern
object
Defines a custom regex-based pattern for identifying sensitive data in logs.
2 properties 2 required
CloudWorkloadSecurityAgentRuleKill
object
Kill system call applied on the container matching the rule
1 property
UserAttributes
object
Attributes of user object returned by the API.
12 properties
ApplicationSecurityWafCustomRuleConditionParameters
object
The scope of the WAF custom rule.
6 properties 1 required
SensitiveDataScannerTextReplacementType
string
Type of the replacement text. None means no replacement. hash means the data will be stubbed. replacementstring means that one can chose a text to replace the…
IncidentType
string
Incident resource type.
Component
object
[Definition of a UI component in the app](https://docs.datadoghq.com/servicemanagement/appbuilder/components/)
5 properties 3 required
SpansMetricFilter
object
The span-based metric filter. Spans matching this filter will be aggregated in this metric.
1 property
EntityV3DatadogIntegrationOpsgenie
object
An Opsgenie integration schema.
2 properties 1 required
InputSchema
object
A list of input parameters for the workflow. These can be used as dynamic runtime values in your workflow.
1 property
IncidentIntegrationMetadataResponseData
object
Incident integration metadata from a response.
4 properties 2 required
UserTarget
object
Represents a user target for an escalation policy step, including the user's ID and resource type.
2 properties 2 required
SecurityMonitoringSuppressionResponse
object
Response object containing a single suppression rule.
1 property
SecurityFilterMeta
object
Optional metadata associated to the response.
1 property
RoleAttributes
object
Attributes of the role.
4 properties
LogsArchiveIntegrationAzure
object
The Azure archive's integration destination.
2 properties 2 required
OutcomesBatchResponseMeta
object
Metadata pertaining to the bulk operation.
2 properties
User
object
User object returned by the API.
4 properties
EntityV3DatastoreKind
string
The definition of Entity V3 Datastore Kind object.
ObservabilityPipelineSensitiveDataScannerProcessor
object
The sensitivedatascanner processor detects and optionally redacts sensitive data in log events.
5 properties 5 required
ObservabilityPipelineDatadogLogsDestinationType
string
The destination type. The value should always be datadoglogs.
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property 1 required
ActionQueryMockedOutputs
The mocked outputs of the action query. This is useful for testing the app without actually running the action.
EntityV3Integrations
object
A base schema for defining third-party integrations.
2 properties
Powerpack
object
Powerpacks are templated groups of dashboard widgets you can save from an existing dashboard and turn into reusable packs in the widget tray.
1 property
CloudWorkloadSecurityAgentPolicyCreateAttributes
object
Create a new Cloud Workload Security Agent policy
5 properties 1 required
HTTPIntegrationType
string
The definition of HTTPIntegrationType object.
EmailTypeType
string
The type of email.
ObservabilityPipelineGenerateMetricsProcessor
object
The generatedatadogmetrics processor creates custom metrics from logs and sends them to Datadog. Metrics can be counters, gauges, or distributions and optional…
5 properties 5 required
EntityMeta
object
Entity metadata.
4 properties
CustomDestinationCreateRequestDefinition
object
The definition of a custom destination.
2 properties 2 required
TeamCreateAttributes
object
Team creation attributes
7 properties 2 required
ScheduleTriggerWrapper
object
Schema for a Schedule-based trigger.
2 properties 1 required
IncidentResponseData
object
Incident data from a response.
4 properties 2 required
FullApplicationKeyAttributes
object
Attributes of a full application key.
5 properties
PowerpackData
object
Powerpack data object.
4 properties
IncidentCreateData
object
Incident data for a create request.
3 properties 2 required
IncidentUserDefinedFieldType
string
The incident user defined fields type.
MonitorNotificationRuleResourceType
string
Monitor notification rule resource type.
AzureUCConfigPostRequestAttributes
object
Attributes for Azure config Post Request.
6 properties 5 required
OrganizationsType
string
Organizations resource type.
ServiceDefinitionV2OpsgenieRegion
string
Opsgenie instance region.
ApplicationSecurityWafCustomRuleConditionOptions
object
Options for the operator of this condition.
2 properties
CaseTriggerWrapper
object
Schema for a Case-based trigger.
2 properties 1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptionsDirection
string
Indicates whether to redact characters from the first or last part of the matched value.
EntityResponseIncludedSchema
object
Included detail entity schema.
3 properties
MonitorConfigPolicyType
string
The monitor configuration policy type.
AWSAccountCreateRequestAttributes
object
The AWS Account Integration Config to be created.
9 properties 3 required
UsersRelationship
object
Relationship to users.
1 property 1 required
RumMetricResponseUniqueness
object
The rule to count updatable events. Is only set if eventtype is session or view.
1 property
ObservabilityPipelineElasticsearchDestinationApiVersion
string
The Elasticsearch API version to use. Set to auto to auto-detect.
WorkflowUserRelationshipType
string
The definition of WorkflowUserRelationshipType object.
ServiceDefinitionV2Contact
Service owner's contacts information.
ObservabilityPipelinePipelineKafkaSourceSaslMechanism
string
SASL mechanism used for Kafka authentication.
SecurityMonitoringSuppressionCreateData
object
Object for a single suppression rule.
2 properties 2 required
LogsMetricCompute
object
The compute rule to compute the log-based metric.
3 properties 1 required
RelationshipToOrganizationData
object
Relationship to organization object.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPattern
object
Specifies a pattern from Datadog’s sensitive data detection library to match known sensitive data types.
2 properties 2 required
ObservabilityPipelineSpecData
object
Contains the the pipeline configuration.
2 properties 2 required
DashboardTriggerWrapper
object
Schema for a Dashboard-based trigger.
2 properties 1 required
XRayServicesIncludeOnly
object
Include only these services. Defaults to [].
1 property 1 required
PowerpackGroupWidget
object
Powerpack group widget definition object.
3 properties 1 required
CustomDestinationResponseAttributes
object
The attributes associated with the custom destination.
7 properties
SecurityFilterFilteredDataType
string
The filtered data type.
OpsgenieServiceRegionType
string
The region for the Opsgenie service.
CustomDestinationResponseForwardDestinationSplunkType
string
Type of the Splunk HTTP Event Collector (HEC) destination.
ProjectResourceType
string
Project resource type
IncidentTeamCreateData
object
Incident Team data for a create request.
3 properties 1 required
RUMApplicationAttributes
object
RUM application attributes.
11 properties 9 required
ObservabilityPipelineGooglePubSubSource
object
The googlepubsub source ingests logs from a Google Cloud Pub/Sub subscription.
7 properties 6 required
PowerpackGroupWidgetLayout
object
Powerpack group widget layout.
4 properties 4 required
RumRetentionFilterCreateData
object
The new RUM retention filter properties to create.
2 properties 2 required
ObservabilityPipelineOcsfMapperProcessorType
string
The processor type. The value should always be ocsfmapper.
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties 2 required
ObservabilityPipelineKafkaSourceLibrdkafkaOption
object
Represents a key-value pair used to configure low-level librdkafka client options for Kafka sources, such as timeouts, buffer sizes, and security settings.
2 properties 2 required
LayerRelationships
object
Holds references to objects related to the Layer entity, such as its members.
1 property
CreateOpenAPIResponse
object
Response for CreateOpenAPI operation.
1 property
SpansMetricResponse
object
The span-based metric object.
1 property
ExternalUserEmailType
object
Email address for the user.
3 properties
TagFilter
object
Tag filter for the budget's entries.
2 properties
UpsertCatalogEntityResponse
object
Upsert entity response.
3 properties
SecurityMonitoringRuleEvaluationWindow
integer
A time window is specified to match when at least one of the cases matches true. This is a sliding window and evaluates in real time. For third party detection…
RuleName
string
Name of the notification rule.
ObservabilityPipelineRenameFieldsProcessorType
string
The processor type. The value should always be renamefields.
OnCallPageTargetType
string
The kind of target, teamid | teamhandle | userid.
ObservabilityPipelineHttpClientSourceType
string
The source type. The value should always be httpclient.
SecurityMonitoringFilterAction
string
The type of filtering action.
JSONAPIErrorResponse
object
API error response.
1 property 1 required
CaseTrigger
object
Trigger a workflow from a Case. For automatic triggering a handle must be configured and the workflow must be published.
1 property
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
CustomDestinationForwardDestinationHttpType
string
Type of the HTTP destination.
UserRelationships
object
Relationships of the user object.
1 property
ActionQueryType
string
The action query type.
ScheduleDataRelationshipsLayersDataItems
object
Relates a layer to this schedule, identified by id and type (must be layers).
2 properties 2 required
CreatePageRequestData
object
The main request body, including attributes and resource type.
2 properties 1 required
ApplicationSecurityWafExclusionFilterOnMatch
string
The action taken when the exclusion filter matches. When set to monitor, security traces are emitted but the requests are not blocked. By default, security tra…
ServiceDefinitionV2Link
object
Service's external links.
3 properties 3 required
ScheduleDataRelationshipsLayersDataItemsType
string
Layers resource type.
RelationshipToPermissionData
object
Relationship to permission object.
2 properties
RestrictionQueryCreateData
object
Data related to the creation of a restriction query.
2 properties
AwsCURConfig
object
AWS CUR config.
3 properties 2 required
SpansFilterCreate
object
The spans filter. Spans matching this filter will be indexed and stored.
1 property 1 required
SecurityMonitoringRuleTypeCreate
string
The rule type.
CloudWorkloadSecurityAgentRuleAction
object
The action the rule can perform if triggered
4 properties
AppBuilderEventType
string
The response to the event.
SecurityMonitoringRuleCaseActionOptions
object
Options for the rule action
2 properties
TeamLinkCreate
object
Team link create
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeIncludeTarget
string
Applies the rule only to included fields.
IncidentCreateRequest
object
Create request for an incident.
1 property 1 required
RoleRelationships
object
Relationships of the role object.
1 property
ObservabilityPipelineFilterProcessor
object
The filter processor allows conditional processing of logs based on a Datadog search query. Logs that match the include query are passed through; others are di…
4 properties 4 required
JiraIntegrationMetadata
object
Incident integration metadata for the Jira integration.
1 property 1 required
TeamCreateRequest
object
Request to create a team
1 property 1 required
Enabled
boolean
Field used to enable or disable the rule.
ApplicationSecurityWafCustomRuleCreateRequest
object
Request object that includes the custom rule to create.
1 property 1 required
OpsgenieServiceCreateRequest
object
Create request for an Opsgenie service.
1 property 1 required
EscalationPolicyStepTarget
object
Defines a single escalation target within a step for an escalation policy creation request. Contains id and type.
2 properties
IncidentTypeAttributes
object
Incident type's attributes.
8 properties 1 required
ObservabilityPipelineParseGrokProcessor
object
The parsegrok processor extracts structured fields from unstructured log messages using Grok patterns.
6 properties 5 required
ObservabilityPipelineSumoLogicDestinationType
string
The destination type. The value should always be sumologic.
SecurityMonitoringReferenceTable
object
Reference tables used in the queries.
5 properties
ServiceDefinitionDataAttributes
object
Service definition attributes.
2 properties
ProjectRelationshipData
object
Relationship to project object
2 properties 2 required
IncidentResponse
object
Response with an incident.
2 properties 1 required
RUMApplicationType
string
RUM application response type.
ObservabilityPipelineElasticsearchDestinationType
string
The destination type. The value should always be elasticsearch.
RumRetentionFilterType
string
The type of the resource. The value should always be retentionfilters.
ObservabilityPipelineSplunkHecSource
object
The splunkhec source implements the Splunk HTTP Event Collector (HEC) API.
3 properties 2 required
MicrosoftTeamsCreateWorkflowsWebhookHandleRequest
object
Create Workflows webhook handle request.
1 property 1 required
TeamCreateRelationships
object
Relationships formed with the team on creation
1 property
ObservabilityPipelineAmazonS3SourceType
string
The source type. Always amazons3.
RoleCreateData
object
Data related to the creation of a role.
3 properties 1 required
IncidentTodoAttributes
object
Incident todo's attributes.
7 properties 2 required
RumMetricEventType
string
The type of RUM events to filter on.
TeamResponse
object
Response with a team
1 property
CreateAppRequestData
object
The data object containing the app definition.
2 properties 1 required
CloudConfigurationRuleComplianceSignalOptions
object
How to generate compliance signals. Useful for cloudconfiguration rules only.
4 properties
CustomDestinationForwardDestinationSplunkType
string
Type of the Splunk HTTP Event Collector (HEC) destination.
AwsCURConfigPostRequestAttributes
object
Attributes for AWS CUR config Post Request.
8 properties 4 required
StateVariableProperties
object
The properties of the state variable.
1 property
LogsMetricComputeAggregationType
string
The type of aggregation to use.
MonitorConfigPolicyPolicy
Configuration for the policy.
LogsArchiveDestinationGCS
object
The GCS archive destination.
4 properties 3 required
ObservabilityPipelineThrottleProcessor
object
The throttle processor limits the number of events that pass through over a given time window.
7 properties 6 required
RumRetentionFilterEnabled
boolean
Whether the retention filter is enabled.
GCPSTSDelegateAccountResponse
object
Your delegate service account response data.
1 property
IncidentTodoType
string
Todo resource type.
NullableUserRelationship
object
Relationship to user.
1 property 1 required
RoleCloneAttributes
object
Attributes required to create a new role by cloning an existing one.
1 property 1 required
LogsMetricResponseData
object
The log-based metric properties.
3 properties
UpsertCatalogEntityResponseIncludedItem
Upsert entity response included item.
EscalationPolicyCreateRequestData
object
Represents the data for creating an escalation policy, including its attributes, relationships, and resource type.
3 properties 2 required
ObservabilityPipelineQuotaProcessorOverflowAction
string
The action to take when the quota is exceeded. Options: - drop: Drop the event. - noaction: Let the event pass through. - overflowrouting: Route to an overflow…
CloudWorkloadSecurityAgentPolicyAttributes
object
A Cloud Workload Security Agent policy returned by the API
15 properties
ObservabilityPipelineSplunkHecSourceType
string
The source type. Always splunkhec.
LogsMetricType
string
The type of the resource. The value should always be logsmetrics.
EntityV3Metadata
object
The definition of Entity V3 Metadata object.
12 properties 1 required
RumMetricCreateRequest
object
The new rum-based metric body.
1 property 1 required
Step
object
A Step is a sub-component of a workflow. Each Step performs an action.
9 properties 2 required
ProjectRelationships
object
Project relationships
2 properties
NotificationRuleQuery
string
The query is composed of one or several key:value pairs, which can be used to filter security issues on tags and attributes.
ScheduleTrigger
object
Trigger a workflow from a Schedule. The workflow must be published.
1 property 1 required
SecurityMonitoringRuleNewValueOptionsForgetAfter
integer
The duration in days after which a learned value is forgotten.
ObservabilityPipelineLogstashSourceType
string
The source type. The value should always be logstash.
APIKeyRelationships
object
Resources related to the API key.
2 properties
RelationshipToUserTeamPermission
object
Relationship between a user team permission and a team
2 properties
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
CustomDestinationAttributeTagsRestrictionListType
string
How forwardtagsrestrictionlist parameter should be interpreted. If ALLOWLIST, then only tags whose keys on the forwarded logs match the ones on the restriction…
ServiceDefinitionV2EmailType
string
Contact type.
EscalationPolicyStepType
string
Indicates that the resource is of type steps.
AWSAccountResponse
object
AWS Account response body.
1 property 1 required
EntityV3APISpecInterfaceFileRef
object
The definition of EntityV3APISpecInterfaceFileRef object.
1 property
LogsArchiveCreateRequest
object
The logs archive.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternType
string
Indicates that a predefined library pattern is used.
Trigger
One of the triggers that can start the execution of a workflow.
AwsCURConfigPostRequest
object
AWS CUR config Post Request.
1 property 1 required
ServiceDefinitionV2SlackType
string
Contact type.
ScheduleDataRelationshipsLayers
object
Associates layers with this schedule in a data structure.
1 property
ObservabilityPipelineHttpClientSource
object
The httpclient source scrapes logs from HTTP endpoints at regular intervals.
7 properties 3 required
ApplicationKeyResponseIncludedItem
An object related to an application key.
CreatePageResponseDataType
string
The type of resource used when creating an On-Call Page.
EscalationPolicyDataType
string
Indicates that the resource is of type policies.
RetentionFilterCreateData
object
The body of the retention filter to be created.
2 properties 2 required
ServiceDefinitionV2Dot2Integrations
object
Third party integrations that Datadog supports.
2 properties
ServiceDefinitionMetaWarnings
object
Schema validation warnings.
3 properties
AWSIntegration
object
The definition of AWSIntegration object.
2 properties 2 required
SecurityMonitoringRuleOptions
object
Options.
10 properties
CreateRuleRequestData
object
Scorecard create rule request data.
2 properties
LogsArchiveDestinationS3Type
string
Type of the S3 archive destination.
ConnectionGroup
object
The definition of ConnectionGroup object.
3 properties 3 required
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties 2 required
RoleResponse
object
Response containing information about a single role.
1 property
ComponentGrid
object
A grid component. The grid component is the root canvas for an app and contains all other components.
5 properties 3 required
ScheduleMember
object
Represents a single member entry in a schedule, referencing a specific user.
3 properties 1 required
ApplicationKeyRelationships
object
Resources related to the application key.
1 property
LeakedKey
object
The definition of LeakedKey object.
3 properties 3 required
CreateRuleRequest
object
Scorecard create rule request.
1 property
MonitorConfigPolicyResponse
object
Response for retrieving a monitor configuration policy.
1 property
ObservabilityPipelineAddEnvVarsProcessorType
string
The processor type. The value should always be addenvvars.
ApplicationSecurityWafExclusionFilterResource
object
A JSON:API resource for an WAF exclusion filter.
3 properties
ObservabilityPipelineGeneratedMetricIncrementByOneStrategy
string
Increments the metric by 1 for each matching event.
AzureUCConfigPairAttributes
object
Attributes for Azure config pair.
2 properties 1 required
SecurityMonitoringSuppressionType
string
The type of the resource. The value should always be suppressions.
ObservabilityPipelineSyslogNgSource
object
The syslogng source listens for logs over TCP or UDP from a syslog-ng server using the syslog protocol.
4 properties 3 required
ServiceAccountCreateData
object
Object to create a service account User.
3 properties 2 required
SecurityMonitoringSuppressionAttributes
object
The attributes of the suppression rule.
14 properties
RetryStrategyLinear
object
The definition of RetryStrategyLinear object.
2 properties 2 required
CloudWorkloadSecurityAgentPolicyData
object
Object for a single Agent policy
3 properties
EscalationPolicyCreateRequestDataRelationships
object
Represents relationships in an escalation policy creation request, including references to teams.
1 property
RumMetricResponseAttributes
object
The object describing a Datadog rum-based metric.
5 properties
RumRetentionFilterSampleRate
integer
The sample rate for a RUM retention filter, between 0 and 100.
CompletionCondition
object
The definition of CompletionCondition object.
3 properties 2 required
CreateActionConnectionRequest
object
Request used to create an action connection.
1 property 1 required
SpansMetricCreateData
object
The new span-based metric properties.
3 properties 3 required
ServiceDefinitionV2Dot1OpsgenieRegion
string
Opsgenie instance region.
ProjectRelationship
object
Relationship to project
1 property 1 required
IncidentTeamResponse
object
Response with an incident team payload.
2 properties 1 required
RumRetentionFilterID
string
ID of retention filter in UUID.
ObservabilityPipelineSensitiveDataScannerProcessorScope
Determines which parts of the log the pattern-matching rule should be applied to.
UrlParam
object
The definition of UrlParam object.
2 properties 2 required
APIKeyCreateData
object
Object used to create an API key.
2 properties 2 required
OpsgenieServiceResponseData
object
Opsgenie service data from a response.
3 properties 3 required
SLOReportPostResponse
object
The SLO report response.
1 property
ApplicationSecurityWafCustomRuleAttributes
object
A WAF custom rule.
9 properties 5 required
ObservabilityPipelineParseJSONProcessorType
string
The processor type. The value should always be parsejson.
CreateOpenAPIResponseData
object
Data envelope for CreateOpenAPIResponse.
2 properties
MetricName
string
The metric name for this resource.
RuleUser
object
User creating or modifying a rule.
2 properties
SAMLAssertionAttributesType
string
SAML assertion attributes resource type.
OutcomesResponseDataItem
object
A single rule outcome.
4 properties
ServiceDefinitionV2Dot2Opsgenie
object
Opsgenie integration for the service.
2 properties 1 required
RelationshipToRoles
object
Relationship to roles.
1 property
NotebookTriggerWrapper
object
Schema for a Notebook-based trigger.
2 properties 1 required
EntityV3SystemKind
string
The definition of Entity V3 System Kind object.
ObservabilityPipelineSyslogNgSourceType
string
The source type. The value should always be syslogng.
SecurityMonitoringRuleCaseAction
object
Action to perform when a signal is triggered. Only available for Application Security rule type.
2 properties
CreateActionConnectionResponse
object
The response for a created connection
1 property
ObservabilityPipelineGenerateMetricsProcessorType
string
The processor type. Always generatedatadogmetrics.
AwsCURConfigPostData
object
AWS CUR config Post data.
2 properties 2 required
ScheduleMemberType
string
Schedule Members resource type.
GCPSTSServiceAccount
object
Info on your service account.
4 properties
ProjectCreateAttributes
object
Project creation attributes
2 properties 2 required
ObservabilityPipelineParseGrokProcessorRuleSupportRule
object
The Grok helper rule referenced in the parsing rules.
2 properties 2 required
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
SecurityMonitoringRuleCase
object
Case when signal is generated.
5 properties
EntityV3QueueKind
string
The definition of Entity V3 Queue Kind object.
ObservabilityPipelineSplunkTcpSourceType
string
The source type. Always splunktcp.
EscalationPolicyDataRelationshipsStepsDataItems
object
Defines a relationship to a single step within an escalation policy. Contains the step's id and type.
2 properties 2 required
LogsArchiveEncryptionS3Type
string
Type of S3 encryption for a destination.
SpansMetricType
string
The type of resource. The value should always be spansmetrics.
RolesType
string
Roles type.
MetricCustomTimeAggregation
string
A time aggregation for use in query.
ObservabilityPipelineKafkaSourceType
string
The source type. The value should always be kafka.
CustomDestinationForwardDestinationElasticsearch
object
The Elasticsearch destination.
5 properties 4 required
RumRetentionFilterCreateAttributes
object
The object describing attributes of a RUM retention filter to create.
5 properties 3 required
ObservabilityPipelineConfig
object
Specifies the pipeline's configuration, including its sources, processors, and destinations.
3 properties 2 required
UsersType
string
Users resource type.
ServiceDefinitionV1Org
object
Org related information about the service.
2 properties
StartStepNames
array
A list of steps that run first after a trigger fires.
EntityToRawSchema
object
Entity to raw schema relationship.
1 property
IncidentServiceCreateData
object
Incident Service payload for create requests.
3 properties 1 required
CustomDestinationElasticsearchDestinationAuth
object
Basic access authentication.
2 properties 2 required
UserRelationshipData
object
Relationship to user object.
2 properties 2 required
SpansMetricResponseAttributes
object
The object describing a Datadog span-based metric.
3 properties
RoleClone
object
Data for the clone role request.
2 properties 2 required
RumRetentionFilterAttributes
object
The object describing attributes of a RUM retention filter.
5 properties
IncidentIntegrationMetadataResponseIncludedItem
An object related to an incident integration metadata that is included in the response.
GithubWebhookTriggerWrapper
object
Schema for a GitHub webhook-based trigger.
2 properties 1 required
MetricTagConfigurationMetricTypes
string
The metric's type.
TeamLinkResponse
object
Team link response
1 property
GCPSTSServiceAccountCreateRequest
object
Data on your newly generated service account.
1 property
CustomDestinationHttpDestinationAuthCustomHeaderType
string
Type of the custom header access authentication.
EntityV3API
object
Schema for API entities.
7 properties 3 required
OpsgenieServiceCreateAttributes
object
The Opsgenie service attributes for a create request.
4 properties 3 required
TimeRestriction
object
Defines a single time restriction rule with start and end times and the applicable weekdays.
4 properties
ApplicationSecurityWafCustomRuleActionAction
string
Override the default action to take when the WAF custom rule would block.
ProjectCreateRequest
object
Project create request
1 property 1 required
EntityV3SystemSpec
object
The definition of Entity V3 System Spec object.
3 properties
ScheduleDataIncludedItem
Any additional resources related to this schedule, such as teams and layers.
ObservabilityPipelineGoogleCloudStorageDestinationAcl
string
Access control list setting for objects written to the bucket.
LogsArchiveAttributes
object
The attributes associated with the archive.
7 properties 3 required
ObservabilityPipelineGoogleChronicleDestinationType
string
The destination type. The value should always be googlechronicle.
ObservabilityPipelineAmazonS3DestinationType
string
The destination type. Always amazons3.
ObservabilityPipelineGoogleChronicleDestinationEncoding
string
The encoding format for the logs sent to Chronicle.
NotificationRulesType
string
The rule type associated to notification rules.
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties 2 required
AWSAccountCreateRequest
object
AWS Account Create Request body.
1 property 1 required
ObservabilityPipelineFilterProcessorType
string
The processor type. The value should always be filter.
SecurityMonitoringThirdPartyRuleCaseCreate
object
Case when a signal is generated by a third party rule.
4 properties 1 required
MicrosoftTeamsTenantBasedHandleAttributes
object
Tenant-based handle attributes.
4 properties
ApplicationSecurityWafExclusionFilterRulesTargetTags
object
Target multiple WAF rules based on their tags.
2 properties
ObservabilityPipelineParseGrokProcessorRule
object
A Grok parsing rule used in the parsegrok processor. Each rule defines how to extract structured fields from a specific log field using Grok patterns.
3 properties 3 required
CustomDestinationResponse
object
The custom destination.
1 property
ServiceNowTicketResult
object
ServiceNow ticket information
1 property
SensitiveDataScannerFilter
object
Filter for the Scanning Group.
1 property
MonitorNotificationRuleName
string
The name of the monitor notification rule.
CreatePageResponseData
object
The information returned after successfully creating a page.
2 properties 1 required
ObservabilityPipelineNewRelicDestinationRegion
string
The New Relic region.
SLOReportInterval
string
The frequency at which report data is to be generated.
GCPServiceAccountType
string
The type of account.
IncidentIntegrationMetadataMetadata
Incident integration metadata's metadata attribute.
ScheduleTargetType
string
Indicates that the resource is of type schedules.
ActionQuerySpecObject
object
The action query spec object.
4 properties 1 required
GCPServiceAccountMeta
object
Additional information related to your service account.
1 property
ServiceDefinitionV2Dot2OpsgenieRegion
string
Opsgenie instance region.
UpsertCatalogEntityResponseIncluded
array
Upsert entity response included.
AuthNMappingRelationshipToTeam
object
Relationship of AuthN Mapping to a Team.
1 property 1 required
HTTPTokenAuth
object
The definition of HTTPTokenAuth object.
5 properties 1 required
CustomFrameworkDataHandleAndVersion
object
Framework Handle and Version.
2 properties
CustomDestinationHttpDestinationAuthBasicType
string
Type of the basic access authentication.
ServiceDefinitionV2Slack
object
Service owner's Slack channel.
3 properties 2 required
UserCreateRequest
object
Create a user.
1 property 1 required
SecurityMonitoringRuleCaseCreate
object
Case when signal is generated.
5 properties 1 required
ApplicationSecurityWafExclusionFilterAttributes
object
Attributes describing a WAF exclusion filter.
11 properties
RumMetricUniquenessWhen
string
When to count updatable events. match when the event is first seen, or end when the event is complete.
LogsMetricResponseCompute
object
The compute rule to compute the log-based metric.
3 properties
RumMetricCreateAttributes
object
The object describing the Datadog rum-based metric to create.
5 properties 2 required
InputSchemaParametersType
string
The definition of InputSchemaParametersType object.
ApplicationSecurityWafExclusionFilterMetadata
object
Extra information about the exclusion filter.
6 properties
ScheduleData
object
Represents the primary data object for a schedule, linking attributes and relationships.
4 properties 1 required
Organization
object
Organization object.
3 properties 1 required
RumMetricResponseData
object
The rum-based metric properties.
3 properties
IncidentAttachmentUpdateResponse
object
The response object containing the created or updated incident attachments.
2 properties 1 required
ObservabilityPipelineHttpServerSourceType
string
The source type. The value should always be httpserver.
CloudWorkloadSecurityAgentRuleAttributes
object
A Cloud Workload Security Agent rule returned by the API
21 properties
RestrictionQueryWithoutRelationshipsResponse
object
Response containing information about a single restriction query.
1 property
NullableRelationshipToUserData
object
Relationship to user object.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternOptions
object
Options for selecting a predefined library pattern and enabling keyword support.
2 properties 1 required
ObservabilityPipelineAmazonS3DestinationStorageClass
string
S3 storage class.
ObservabilityPipelineDecoding
string
The decoding format used to interpret incoming logs.
EntityV3DatadogCodeLocations
array
Schema for mapping source code locations to an entity.
ScheduleCreateRequestData
object
The core data wrapper for creating a schedule, encompassing attributes, relationships, and the resource type.
3 properties 2 required
ServiceDefinitionV1Contact
object
Contact information about the service.
2 properties
CloudWorkloadSecurityAgentPolicyType
string
The type of the resource, must always be policy
ServiceDefinitionV2Dot1Link
object
Service's external links.
4 properties 3 required
RoleCreateResponseData
object
Role object returned by the API.
4 properties 1 required
RumMetricFilter
object
The rum-based metric filter. Events matching this filter will be aggregated in this metric.
1 property 1 required
SLOReportPostResponseData
object
The data portion of the SLO report response.
2 properties
MicrosoftTeamsWorkflowsWebhookResponseAttributes
object
Workflows Webhook handle attributes.
1 property
ObservabilityPipeline
object
Top-level schema representing a pipeline.
1 property 1 required
IncidentIntegrationMetadataAttributes
object
Incident integration metadata's attributes for a create request.
6 properties 2 required
ObservabilityPipelineConfigDestinationItem
A destination for the pipeline.
CustomDestinationCreateRequest
object
The custom destination.
1 property
SensitiveDataScannerGroup
object
A scanning group.
2 properties
EntityV3DatastoreSpec
object
The definition of Entity V3 Datastore Spec object.
4 properties
ObservabilityPipelineConfigSourceItem
A data source for the pipeline.
IncidentTeamType
string
Incident Team resource type.
ObservabilityPipelineSensitiveDataScannerProcessorAction
Defines what action to take when sensitive data is matched.
SoftwareCatalogTriggerWrapper
object
Schema for a Software Catalog-based trigger.
2 properties 1 required
ObservabilityPipelineNewRelicDestination
object
The newrelic destination sends logs to the New Relic platform.
4 properties 4 required
ApplicationSecurityWafCustomRuleAction
object
The definition of ApplicationSecurityWafCustomRuleAction object.
2 properties
ApplicationSecurityWafCustomRuleResponse
object
Response object that includes a single WAF custom rule.
1 property
ScheduleMemberRelationshipsUserData
object
Points to the user data associated with this schedule member, including an ID and type.
2 properties 2 required
EntityV3DatadogLogItem
object
Log association item.
2 properties
SecurityMonitoringRuleQueryAggregation
string
The aggregation type.
AzureStorageDestination
object
The azurestorage destination forwards logs to an Azure Blob Storage container.
5 properties 4 required
MonitorNotificationRuleResponseAttributes
object
Attributes of the monitor notification rule.
5 properties
HTTPBody
object
The definition of HTTPBody object.
2 properties
ObservabilityPipelineHttpServerSource
object
The httpserver source collects logs over HTTP POST from external services.
5 properties 4 required
EscalationPolicyStep
object
Represents a single step in an escalation policy, including its attributes, relationships, and resource type.
4 properties 1 required
ServiceDefinitionData
object
Service definition data.
3 properties
ScheduleCreateRequestDataRelationships
object
Gathers relationship objects for the schedule creation request, including the teams to associate.
1 property
RUMApplicationCreateAttributes
object
RUM application creation attributes.
2 properties 1 required
ObservabilityPipelineSensitiveDataScannerProcessorType
string
The processor type. The value should always be sensitivedatascanner.
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
IncidentServiceRelationships
object
The incident service's relationships.
2 properties
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property 1 required
SecurityMonitoringRuleHardcodedEvaluatorType
string
Hardcoded evaluator type.
SecurityMonitoringSignalRuleCreatePayload
object
Create a new signal correlation rule.
10 properties 6 required
AzureUCConfigPostRequestType
string
Type of Azure config Post Request.
ObservabilityPipelineGooglePubSubSourceType
string
The source type. The value should always be googlepubsub.
GCPMetricNamespaceConfig
object
Configuration for a GCP metric namespace.
2 properties
TeamTargetType
string
Indicates that the resource is of type teams.
CloudWorkloadSecurityAgentRuleActions
array
The array of actions the rule can perform if triggered
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedact
object
Configuration for partially redacting matched sensitive data.
2 properties 2 required
ObservabilityPipelineMetricValue
Specifies how the value of the generated metric is computed.
CloudWorkloadSecurityAgentRuleCreateRequest
object
Request object that includes the Agent rule to create
1 property 1 required
ScheduleUser
object
Represents a user object in the context of a schedule, including their id, type, and basic attributes.
3 properties 1 required
SAMLAssertionAttribute
object
SAML assertion attribute.
3 properties 2 required
EscalationPolicyCreateRequestDataType
string
Indicates that the resource is of type policies.
MonitorConfigPolicyResponseData
object
A monitor configuration policy data.
3 properties
ApplicationSecurityWafExclusionFilterCreateAttributes
object
Attributes for creating a WAF exclusion filter.
8 properties 2 required
CreatePageRequest
object
Full request to trigger an On-Call Page.
1 property
CaseCreateRequest
object
Case create request
1 property 1 required
SecurityFilterID
string
The ID of the security filter.
IncidentTrigger
object
Trigger a workflow from an Incident. For automatic triggering a handle must be configured and the workflow must be published.
1 property
LogsArchive
object
The logs archive.
1 property
SecurityMonitoringSuppressionCreateAttributes
object
Object containing the attributes of the suppression rule to be created.
8 properties 3 required
RumMetricID
string
The name of the rum-based metric.
SelfServiceTriggerWrapper
object
Schema for a Self Service-based trigger.
2 properties 1 required
IncidentTimelineCellMarkdownCreateAttributes
object
Timeline cell data for Markdown timeline cells for a create request.
3 properties 2 required
MonitorTrigger
object
Trigger a workflow from a Monitor. For automatic triggering a handle must be configured and the workflow must be published.
1 property
AWSNamespaceFiltersIncludeOnly
object
Include only these namespaces.
1 property 1 required
EntityV3DatadogLogs
array
Logs association.
SecurityMonitoringSuppression
object
The suppression rule's properties.
3 properties
ServiceDefinitionV2Dot1
object
Service definition v2.1 for providing service metadata and integrations.
12 properties 2 required
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property 1 required
ObservabilityPipelineEnrichmentTableFile
object
Defines a static enrichment table loaded from a CSV file.
4 properties 4 required
CloudWorkloadSecurityAgentRuleActionMetadata
object
The metadata action applied on the scope matching the rule
3 properties
Layer
object
Encapsulates a layer resource, holding attributes like rotation details, plus relationships to the members covering that layer.
4 properties 1 required
RumRetentionFilterEventType
string
The type of RUM events to filter on.
ApplicationSecurityWafCustomRuleTags
object
Tags associated with the WAF Custom Rule. The concatenation of category and type will form the security activity field associated with the traces.
2 properties 2 required
HTTPHeader
object
The definition of HTTPHeader object.
2 properties 2 required
OutputSchema
object
A list of output parameters for the workflow.
1 property
AWSAccountCreateRequestData
object
AWS Account Create Request data.
2 properties 2 required
LogsArchiveDefinition
object
The definition of an archive.
3 properties 1 required
AWSAssumeRole
object
The definition of AWSAssumeRole object.
5 properties 3 required
IncidentServiceResponseAttributes
object
The incident service's attributes from a response.
3 properties
ServiceDefinitionV2Dot1Slack
object
Service owner's Slack channel.
3 properties 2 required
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties 2 required
CustomDestinationResponseForwardDestinationElasticsearch
object
The Elasticsearch destination.
5 properties 4 required
CustomDestinationResponseForwardDestinationElasticsearchType
string
Type of the Elasticsearch destination.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactAction
string
Action type that completely replaces the matched sensitive data with a fixed replacement string to remove all visibility.
AWSAccountType
string
AWS Account resource type.
LayerRelationshipsMembersDataItems
object
Represents a single member object in a layer's members array, referencing a unique Datadog user ID.
2 properties 2 required
ObservabilityPipelineReduceProcessorMergeStrategyStrategy
string
The merge strategy to apply.
SensitiveDataScannerStandardPatternType
string
Sensitive Data Scanner standard pattern type.
SecurityMonitoringThirdPartyRootQuery
object
A query to be combined with the third party case query.
2 properties
ScheduleCreateRequestDataType
string
Schedules resource type.
CustomDestinationResponseForwardDestinationHttp
object
The HTTP destination.
3 properties 3 required
SecurityFilterCreateAttributes
object
Object containing the attributes of the security filter to be created.
5 properties 5 required
IncidentSeverity
string
The incident severity.
EscalationPolicyStepAttributes
object
Defines attributes for an escalation policy step, such as assignment strategy and escalation timeout.
2 properties
ApplicationSecurityWafExclusionFilterID
string
The identifier of the WAF exclusion filter.
ObservabilityPipelineOpenSearchDestination
object
The opensearch destination writes logs to an OpenSearch cluster.
4 properties 3 required
AWSAuthConfig
AWS Authentication config.
SecurityFilterAttributes
object
The object describing a security filter.
7 properties
CreateAppRequestDataAttributes
object
App definition attributes such as name, description, and components.
6 properties
SpansMetricComputeAggregationType
string
The type of aggregation to use.
TeamReferenceType
string
Teams resource type.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

datadog-create-api-openapi.yml Raw ↑

Other APIs Datadog publishes across the network.

Datadog Dashboards API
Datadog Synthetics API
Datadog Service Level Objectives API
Datadog Security Monitoring API
Datadog Service Definition API
Datadog Software Catalog API
Datadog Users API
Datadog Roles API
Datadog Key Management API
Datadog Organizations API
Datadog Downtimes API
Datadog RUM API
Where this information came from

This is an independent, third-party profile of Datadog Create API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.