The identity and technical contract details declared by the specification.
LogsMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExclude
object
Excludes specific fields from sensitive data scanning.
2 properties
2 required
ObservabilityPipelineTls
object
Configuration for enabling TLS encryption between the pipeline component and external services.
3 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactAction
string
Action type that redacts part of the sensitive data while preserving a configurable number of characters, typically used for masking purposes (e.g., show last…
DataRelationshipsTeamsDataItems
object
Relates a team to this schedule, identified by id and type (must be teams).
2 properties
2 required
SendTeamsMessageAction
object
Sends a message to a Microsoft Teams channel.
4 properties
4 required
MetricCustomSpaceAggregation
string
A space aggregation for use in query.
IncidentServiceRelationships
object
The incident service's relationships.
2 properties
IncidentTodoAssigneeHandle
string
Assignee's @-handle.
SpecVersion
string
The version of the CycloneDX specification a BOM conforms to.
UserTeamAttributes
object
Team membership attributes
3 properties
RoutingRuleRelationships
object
Specifies relationships for a routing rule, linking to associated policy resources.
1 property
SLOReportStatusGetResponse
object
The SLO report status response.
1 property
ObservabilityPipelineParseGrokProcessorRuleMatchRule
object
Defines a Grok parsing rule, which extracts structured fields from log content using named Grok patterns. Each rule must have a unique name and a valid Datadog…
2 properties
2 required
SecurityMonitoringSuppressionAttributes
object
The attributes of the suppression rule.
14 properties
Version
integer
Version of the notification rule. It is updated when the rule is modified.
ScheduleMemberType
string
Schedule Members resource type.
OpsgenieServiceType
string
Opsgenie service resource type.
ObservabilityPipelineGoogleCloudStorageDestinationType
string
The destination type. Always googlecloudstorage.
RoutingRule
object
Represents a routing rule, including its attributes, relationships, and unique identifier.
4 properties
1 required
LogsStorageTier
string
Specifies storage type as indexes, online-archives or flex
SBOM
object
A single SBOM
3 properties
ObservabilityPipelineDedupeProcessorType
string
The processor type. The value should always be dedupe.
SecurityMonitoringSignalListRequestPage
object
The paging attributes for listing security signals.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPattern
object
Specifies a pattern from Datadog’s sensitive data detection library to match known sensitive data types.
2 properties
2 required
ObservabilityPipelineAmazonS3DestinationStorageClass
string
S3 storage class.
ObservabilityPipelineNewRelicDestination
object
The newrelic destination sends logs to the New Relic platform.
4 properties
4 required
RelationshipToUserData
object
Relationship to user object.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternType
string
Indicates a custom regular expression is used for matching.
EscalationPolicyUserType
string
Users resource type.
ScheduleMemberRelationshipsUser
object
Wraps the user data reference for a schedule member.
1 property
1 required
TeamOnCallRespondersDataRelationshipsEscalationsDataItems
object
Represents a link to a specific escalation policy step associated with the on-call team.
2 properties
2 required
IncidentResponseMeta
object
The metadata object containing pagination metadata.
1 property
MicrosoftSentinelDestination
object
The microsoftsentinel destination forwards logs to Microsoft Sentinel.
7 properties
7 required
IncidentServiceResponse
object
Response with an incident service payload.
2 properties
1 required
RumMetricUniquenessWhen
string
When to count updatable events. match when the event is first seen, or end when the event is complete.
RoleResponseRelationships
object
Relationships of the role object returned by the API.
1 property
TeamLinkResponse
object
Team link response
1 property
AwsScanOptionsAttributes
object
Attributes for the AWS scan options.
4 properties
ScheduleData
object
Represents the primary data object for a schedule, linking attributes and relationships.
4 properties
1 required
DataRelationshipsTeamsDataItemsType
string
Teams resource type.
ProjectAttributes
object
Project attributes
2 properties
RelationshipToOrganizationData
object
Relationship to organization object.
2 properties
2 required
ObservabilityPipelineSplunkTcpSourceType
string
The source type. Always splunktcp.
Span
object
Object description of a spans after being processed and stored by Datadog.
3 properties
ObservabilityPipelineElasticsearchDestinationApiVersion
string
The Elasticsearch API version to use. Set to auto to auto-detect.
Project
object
A Project
4 properties
3 required
LeakedKeyType
string
The definition of LeakedKeyType object.
TeamPermissionSettingSerializerAction
string
The identifier for the action
ObservabilityPipelineRenameFieldsProcessor
object
The renamefields processor changes field names.
5 properties
5 required
EscalationPolicyIncluded
Represents included related resources when retrieving an escalation policy, such as teams, steps, or targets.
IncidentUserDefinedFieldType
string
The incident user defined fields type.
ObservabilityPipelineGeneratedMetricMetricType
string
Type of metric to create.
UserResponseIncludedItem
An object related to a user.
UserTeamRelationships
object
Relationship between membership and a user
2 properties
IPAllowlistEntryData
object
Data of the IP allowlist entry object.
3 properties
1 required
TeamRoutingRulesDataRelationshipsRulesDataItemsType
string
Indicates that the resource is of type 'teamroutingrules'.
PowerpackInnerWidgetLayout
object
Powerpack inner widget layout.
4 properties
4 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedact
object
Configuration for partially redacting matched sensitive data.
2 properties
2 required
AuthNMappingTeamAttributes
object
Team attributes.
7 properties
SecurityMonitoringSignalsSort
string
The sort parameters used for querying security signals.
RumMetricResponseGroupBy
object
A group by rule.
2 properties
EscalationTarget
Represents an escalation target, which can be a team, user, or schedule.
LogsMetricID
string
The name of the log-based metric.
ObservabilityPipelineSumoLogicSourceType
string
The source type. The value should always be sumologic.
ObservabilityPipelineAddEnvVarsProcessorVariable
object
Defines a mapping between an environment variable and a log field.
2 properties
2 required
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties
2 required
EscalationPolicyData
object
Represents the data for a single escalation policy, including its attributes, ID, relationships, and resource type.
4 properties
1 required
ObservabilityPipelineOcsfMapperProcessorMapping
object
Defines how specific events are transformed to OCSF using a mapping configuration.
2 properties
2 required
MonitorNotificationRuleFilter
Filter used to associate the notification rule with monitors.
SecurityMonitoringSuppression
object
The suppression rule's properties.
3 properties
AwsScanOptionsListResponse
object
Response object that includes a list of AWS scan options.
1 property
ObservabilityPipelineKafkaSource
object
The kafka source ingests data from Apache Kafka topics.
7 properties
4 required
ScheduleUser
object
Represents a user object in the context of a schedule, including their id, type, and basic attributes.
3 properties
1 required
AWSLogsServicesResponseData
object
AWS Logs Services response body
3 properties
2 required
TeamReference
object
Provides a reference to a team, including ID, type, and basic attributes/relationships.
3 properties
1 required
UsageTimeSeriesType
string
Type of usage data.
SpansListResponseLinks
object
Links attributes.
1 property
ShiftDataRelationships
object
The definition of ShiftDataRelationships object.
1 property
IncidentIntegrationMetadataResponseIncludedItem
An object related to an incident integration metadata that is included in the response.
SecurityMonitoringRuleNewValueOptionsLearningMethod
string
The learning method used to determine when signals should be generated for values that weren't learned.
IncidentTeamResponseAttributes
object
The incident team's attributes from a response.
3 properties
SecurityMonitoringRuleCaseActionOptions
object
Options for the rule action
2 properties
RestrictionQueryWithRelationships
object
Restriction query object returned by the API.
4 properties
IncidentTodoAnonymousAssignee
object
Anonymous assignee entity.
4 properties
4 required
TeamPermissionSettingsResponse
object
Team permission settings response
1 property
JSONAPIErrorItem
object
API error response body
5 properties
SlackIntegrationMetadata
object
Incident integration metadata for the Slack integration.
1 property
1 required
DowntimeMonitorIdentifierId
object
Object of the monitor identifier.
1 property
1 required
LeakedKey
object
The definition of LeakedKey object.
3 properties
3 required
Shift
object
The definition of Shift object.
2 properties
UsageTimeSeriesObject
object
Usage timeseries data.
2 properties
LogType
string
Type of the event.
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property
1 required
SpansMetricType
string
The type of resource. The value should always be spansmetrics.
ObservabilityPipelineAmazonS3DestinationType
string
The destination type. Always amazons3.
EmailTypeType
string
The type of email.
AzureStorageDestination
object
The azurestorage destination forwards logs to an Azure Blob Storage container.
5 properties
4 required
SecurityMonitoringUser
object
A user.
2 properties
IncidentTodoAttributes
object
Incident todo's attributes.
7 properties
2 required
ObservabilityPipelineHttpClientSourceType
string
The source type. The value should always be httpclient.
ScheduleTargetType
string
Indicates that the resource is of type schedules.
ShiftDataAttributes
object
The definition of ShiftDataAttributes object.
2 properties
ShiftData
object
The definition of ShiftData object.
4 properties
1 required
ObservabilityPipelineParseGrokProcessorRuleSupportRule
object
The Grok helper rule referenced in the parsing rules.
2 properties
2 required
PowerpackTemplateVariable
object
Powerpack template variables.
4 properties
1 required
SecurityMonitoringSuppressionType
string
The type of the resource. The value should always be suppressions.
TeamRoutingRulesIncluded
Represents additional included resources for team routing rules, such as associated routing rules.
ObservabilityPipelineFieldValue
object
Represents a static key-value pair used in various processors.
2 properties
2 required
EscalationPolicyUserAttributes
object
Provides basic user information for an escalation policy, including a name and email address.
3 properties
AWSAccountPartition
string
AWS partition your AWS account is scoped to. Defaults to aws. See [Partitions](https://docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/pa…
NullableRelationshipToUser
objectnull
Relationship to user.
1 property
1 required
SecurityMonitoringRuleEvaluationWindow
integer
A time window is specified to match when at least one of the cases matches true. This is a sliding window and evaluates in real time. For third party detection…
ExternalUserGroup
object
Definition of a group.
6 properties
SecurityMonitoringRuleHardcodedEvaluatorType
string
Hardcoded evaluator type.
GetRuleVersionHistoryResponse
object
Response for getting the rule version history.
1 property
ID
string
The ID of a notification rule.
SBOMType
string
The JSON:API type.
ObservabilityPipelineAmazonS3Source
object
The amazons3 source ingests logs from an Amazon S3 bucket. It supports AWS authentication and TLS encryption.
5 properties
3 required
ProjectRelationships
object
Project relationships
2 properties
OrganizationAttributes
object
Attributes of the organization.
8 properties
ScheduleDataRelationships
object
Groups the relationships for a schedule object, referencing layers and teams.
2 properties
SecurityMonitoringSignalsListResponse
object
The response object with all security signals matching the request and pagination information.
3 properties
SpansMetricResponseData
object
The span-based metric properties.
3 properties
ScheduleMemberRelationships
object
Defines relationships for a schedule member, primarily referencing a single user.
1 property
SpansMetricID
string
The name of the span-based metric.
MetricPaginationMeta
object
Response metadata object.
1 property
ObservabilityPipelineEnrichmentTableFileKeyItems
object
Defines how to map log fields to enrichment table columns during lookups.
3 properties
3 required
UsageDataObject
object
Usage data.
3 properties
LogsListResponse
object
Response object with all logs matching the request and pagination information.
3 properties
RelationshipToRoleData
object
Relationship to role object.
2 properties
XRayServicesIncludeOnly
objectnull
Include only these services. Defaults to [].
1 property
1 required
MonitorNotificationRuleRelationshipsCreatedBy
object
The user who created the monitor notification rule.
1 property
SpansListResponseMetadata
object
The metadata associated with a request.
5 properties
ObservabilityPipelineRenameFieldsProcessorField
object
Defines how to rename a field in log events.
3 properties
3 required
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
RoutingRuleType
string
Team routing rules resource type.
WorklflowGetInstanceResponseDataAttributes
object
The attributes of the instance response data.
1 property
FullAPIKeyAttributes
object
Attributes of a full API key.
7 properties
ObservabilityPipelineQuotaProcessor
object
The Quota Processor measures logging traffic for logs that match a specified filter. When the configured daily quota is met, the processor can drop or alert.
11 properties
7 required
LogsRestrictionQueriesType
string
Restriction query resource type.
MonitorNotificationRuleResponseIncludedItem
An object related to a monitor notification rule.
ObservabilityPipelineReduceProcessorMergeStrategy
object
Defines how a specific field should be merged across grouped events.
2 properties
2 required
WorklflowGetInstanceResponseData
object
The data of the instance response.
1 property
UsageAttributesObject
object
Usage attributes data.
6 properties
IncidentTypeAttributes
object
Incident type's attributes.
8 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternOptions
object
Options for selecting a predefined library pattern and enabling keyword support.
2 properties
1 required
ObservabilityPipelineSumoLogicDestinationHeaderCustomFieldsItem
object
Single key-value pair used as a custom log header for Sumo Logic.
2 properties
2 required
ObservabilityPipelineAddEnvVarsProcessor
object
The addenvvars processor adds environment variable values to log events.
5 properties
5 required
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties
2 required
LogsMetricResponse
object
The log-based metric object.
1 property
UsersRelationship
object
Relationship to users.
1 property
1 required
JobDefinition
object
Definition of a historical job.
14 properties
7 required
MetricCustomAggregations
array
Deprecated. You no longer need to configure specific time and space aggregations for Metrics Without Limits.
IncidentTeamIncludedItems
An object related to an incident team which is present in the included payload.
IncidentNonDatadogCreator
objectnull
Incident's non Datadog creator.
2 properties
AuthNMappingIncluded
Included data in the AuthN Mapping response.
AwsScanOptionsType
string
The type of the resource. The value should always be awsscanoptions.
LayerRelationshipsMembers
object
Holds an array of references to the members of a Layer, each containing member IDs.
1 property
SecurityMonitoringSignal
object
Object description of a security signal.
3 properties
RestrictionQueryResponseIncludedItem
An object related to a restriction query.
MSTeamsIntegrationMetadata
object
Incident integration metadata for the Microsoft Teams integration.
1 property
1 required
ObservabilityPipelineGooglePubSubSourceType
string
The source type. The value should always be googlepubsub.
DowntimeResponseAttributes
object
Downtime details.
12 properties
DowntimeMuteFirstRecoveryNotification
boolean
If the first recovery notification during a downtime should be muted.
AWSAuthConfig
AWS Authentication config.
AuthNMappingsType
string
AuthN Mappings resource type.
TeamRoutingRulesDataRelationshipsRulesDataItems
object
Defines a relationship item to link a routing rule by its ID and type.
2 properties
2 required
MetricMetaPageType
string
Type of metric pagination.
LayerAttributes
object
Describes key properties of a Layer, including rotation details, name, start/end times, and any restrictions.
6 properties
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties
2 required
ObservabilityPipelineRsyslogDestinationType
string
The destination type. The value should always be rsyslog.
RelationshipToRoles
object
Relationship to roles.
1 property
UserTeamType
string
Team membership type
ObservabilityPipelineOcsfMapperProcessorMappingMapping
Defines a single mapping rule for transforming logs into the OCSF schema.
ObservabilityPipelineGeneratedMetricIncrementByOneStrategy
string
Increments the metric by 1 for each matching event.
OpsgenieServiceResponseAttributes
object
The attributes from an Opsgenie service response.
3 properties
ObservabilityPipelineAmazonOpenSearchDestinationAuthStrategy
string
The authentication strategy to use.
RelationshipToTeamLinkData
object
Relationship between a link and a team
2 properties
2 required
ObservabilityPipelineEnrichmentTableGeoIp
object
Uses a GeoIP database to enrich logs based on an IP field.
3 properties
3 required
TeamOnCallRespondersDataRelationships
object
Relationship objects linked to a team's on-call responder configuration, including escalations and responders.
2 properties
RelationshipToTeamData
object
Relationship to Team object.
2 properties
SecurityMonitoringSuppressionID
string
The ID of the suppression rule.
ObservabilityPipelineAmazonOpenSearchDestinationAuth
object
Authentication settings for the Amazon OpenSearch destination. The strategy field determines whether basic or AWS-based authentication is used.
5 properties
1 required
Team
object
A team
4 properties
3 required
SecurityMonitoringStandardRuleQuery
object
Query for matching rule.
9 properties
MetricCustomTimeAggregation
string
A time aggregation for use in query.
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties
2 required
CloudWorkloadSecurityAgentPolicyAttributes
object
A Cloud Workload Security Agent policy returned by the API
15 properties
UserTeamPermissionType
string
User team permission type
ObservabilityPipelineSensitiveDataScannerProcessor
object
The sensitivedatascanner processor detects and optionally redacts sensitive data in log events.
5 properties
5 required
ObservabilityPipelineConfigSourceItem
A data source for the pipeline.
ExternalUserGroupMeta
object
Metadata associated with a group.
4 properties
SecurityMonitoringSignalType
string
The type of event.
RestrictionQueryWithRelationshipsResponse
object
Response containing information about a single restriction query.
2 properties
IncidentTodoAnonymousAssigneeSource
string
The source of the anonymous assignee.
EscalationRelationships
object
Contains the relationships of an escalation object, including its responders.
1 property
ObservabilityPipelineReduceProcessorType
string
The processor type. The value should always be reduce.
RelationshipToUserTeamUserData
object
A user's relationship with a team
2 properties
2 required
EscalationTargets
object
A list of escalation targets for a step
1 property
TeamPermissionSetting
object
Team permission setting
3 properties
2 required
IncidentIntegrationMetadataAttributes
object
Incident integration metadata's attributes for a create request.
6 properties
2 required
ObservabilityPipelineFilterProcessorType
string
The processor type. The value should always be filter.
RelationshipToUser
object
Relationship to user.
1 property
1 required
ObservabilityPipelineGoogleCloudStorageDestination
object
The googlecloudstorage destination stores logs in a Google Cloud Storage (GCS) bucket. It requires a bucket name, GCP authentication, and metadata fields.
9 properties
7 required
RuleVersionUpdateType
string
The type of change.
SpansResponseMetadataPage
object
Paging attributes.
1 property
AWSAccountTags
arraynull
Tags to apply to all hosts and metrics reporting for this account. Defaults to [].
SecurityMonitoringRuleNewValueOptionsLearningDuration
integer
The duration in days during which values are learned, and after which signals will be generated for values that weren't learned. If set to 0, a signal will be…
ObservabilityPipelineReduceProcessorMergeStrategyStrategy
string
The merge strategy to apply.
TeamRoutingRulesDataRelationships
object
Specifies relationships for team routing rules, including rule references.
1 property
EscalationRelationshipsResponders
object
Lists the users involved in a specific step of the escalation policy.
1 property
RelationshipToTeam
object
Relationship to team.
1 property
ObservabilityPipelineSplunkHecSource
object
The splunkhec source implements the Splunk HTTP Event Collector (HEC) API.
3 properties
2 required
TeamType
string
Team type
RoutingRuleRelationshipsPolicy
object
Defines the relationship that links a routing rule to a policy.
1 property
ScheduleUserType
string
Users resource type.
RumMetricComputeAggregationType
string
The type of aggregation to use.
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property
1 required
NotificationRuleAttributes
object
Attributes of the notification rule.
10 properties
9 required
ObservabilityPipelineConfig
object
Specifies the pipeline's configuration, including its sources, processors, and destinations.
3 properties
2 required
ObservabilityPipelineGeneratedMetricIncrementByFieldStrategy
string
Uses a numeric field in the log event as the metric increment.
SecurityMonitoringSignalResponse
object
Security Signal response data object.
1 property
AWSMetricsConfig
object
AWS Metrics Collection config.
6 properties
DowntimeMonitorIdentifierTags
object
Object of the monitor tags.
1 property
1 required
ObservabilityPipelinePipelineKafkaSourceSaslMechanism
string
SASL mechanism used for Kafka authentication.
MicrosoftSentinelDestinationType
string
The destination type. The value should always be microsoftsentinel.
XRayServicesList
AWS X-Ray services to collect traces from. Defaults to includeonly.
TeamReferenceType
string
Teams resource type.
SpansMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
IncidentTodoRelationships
object
The incident's relationships from a response.
2 properties
LogsMetricResponseFilter
object
The log-based metric filter. Logs matching this filter will be aggregated in this metric.
1 property
Urgency
string
Specifies the level of urgency for a routing rule (low, high, or dynamic).
ObservabilityPipeline
object
Top-level schema representing a pipeline.
1 property
1 required
ObservabilityPipelineGeneratedMetric
object
Defines a log-based custom metric, including its name, type, filter, value computation strategy, and optional grouping fields.
5 properties
4 required
SBOMComponentType
string
The SBOM component type
Permission
object
Permission object.
3 properties
1 required
LayerType
string
Layers resource type.
Organization
object
Organization object.
3 properties
1 required
ObservabilityPipelineOpenSearchDestination
object
The opensearch destination writes logs to an OpenSearch cluster.
4 properties
3 required
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
SecurityMonitoringThirdPartyRuleCase
object
Case when signal is generated by a third party rule.
4 properties
ObservabilityPipelineGooglePubSubSource
object
The googlepubsub source ingests logs from a Google Cloud Pub/Sub subscription.
7 properties
6 required
ObservabilityPipelineSyslogNgSourceType
string
The source type. The value should always be syslogng.
SecurityMonitoringRuleCaseActionType
string
The action type.
TeamRoutingRulesDataRelationshipsRules
object
Holds references to a set of routing rules in a relationship.
1 property
MonitorNotificationRuleResourceType
string
Monitor notification rule resource type.
IncidentIntegrationMetadataResponse
object
Response with an incident integration metadata.
2 properties
1 required
IncidentTodoType
string
Todo resource type.
ApiID
string
API identifier.
SpansWarning
object
A warning message indicating something that went wrong with the query.
3 properties
EscalationPolicyUser
object
Represents a user object in the context of an escalation policy, including their id, type, and basic attributes.
3 properties
1 required
SpansMetricComputeAggregationType
string
The type of aggregation to use.
RestrictionPolicyAttributes
object
Restriction policy attributes.
1 property
1 required
TeamReferenceAttributes
object
Encapsulates the basic attributes of a Team reference, such as name, handle, and an optional avatar or description.
4 properties
ObservabilityPipelineSumoLogicDestination
object
The sumologic destination forwards logs to Sumo Logic.
8 properties
3 required
ObservabilityPipelineEnrichmentTableFileKeyItemsComparison
string
Defines how to compare key fields for enrichment table lookups.
RelationshipToRole
object
Relationship to role.
1 property
SecurityMonitoringReferenceTable
object
Reference tables used in the queries.
5 properties
LogsAggregateResponseStatus
string
The status of the response
ObservabilityPipelineHttpClientSourceAuthStrategy
string
Optional authentication strategy for HTTP requests.
ObservabilityPipelineSplunkTcpSource
object
The splunktcp source receives logs from a Splunk Universal Forwarder over TCP. TLS is supported for secure transmission.
3 properties
2 required
SLOReportStatusGetResponseData
object
The data portion of the SLO report status response.
3 properties
LogsWarning
object
A warning message indicating something that went wrong with the query
3 properties
LogsMetricResponseComputeAggregationType
string
The type of aggregation to use.
MetricMetaPage
object
Paging attributes. Only present if pagination query parameters were provided.
4 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeInclude
object
Includes only specific fields for sensitive data scanning.
2 properties
2 required
RelationshipToSAMLAssertionAttribute
object
AuthN Mapping relationship to SAML Assertion Attribute.
1 property
1 required
SecurityMonitoringSignalRuleResponseQuery
object
Query for matching rule on signals.
9 properties
DowntimeResourceType
string
Downtime resource type.
ObservabilityPipelineAmazonDataFirehoseSource
object
The amazondatafirehose source ingests logs from AWS Data Firehose.
4 properties
2 required
LogsMetricResponseData
object
The log-based metric properties.
3 properties
ObservabilityPipelineDatadogLogsDestination
object
The datadoglogs destination forwards logs to Datadog Log Management.
3 properties
3 required
IncidentServiceType
string
Incident service resource type.
ObservabilityPipelineFluentBitSourceType
string
The source type. The value should always be fluentbit.
ObservabilityPipelineRsyslogSource
object
The rsyslog source listens for logs over TCP or UDP from an rsyslog server using the syslog protocol.
4 properties
3 required
TeamLinksResponse
object
Team links response
1 property
SecurityMonitoringRuleCaseActionOptionsUserBehaviorName
string
Used with the case action of type 'userbehavior'. The value specified in this field is applied as a risk tag to all users affected by the rule.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedact
object
Configuration for completely redacting matched sensitive data.
2 properties
2 required
RestrictionPolicyType
string
Restriction policy type.
ObservabilityPipelineParseGrokProcessor
object
The parsegrok processor extracts structured fields from unstructured log messages using Grok patterns.
6 properties
5 required
OrgConfigType
string
Data type of an Org Config.
TeamsResponseLinks
object
Teams response links.
5 properties
CloudConfigurationRuleComplianceSignalOptions
object
How to generate compliance signals. Useful for cloudconfiguration rules only.
4 properties
MonitorNotificationRuleName
string
The name of the monitor notification rule.
IncidentAttachmentAttributes
The attributes object for an attachment.
DowntimeIncludedMonitorType
string
Monitor resource type.
IncidentTeamResponse
object
Response with an incident team payload.
2 properties
1 required
MetricType
string
The metric resource type.
SecurityMonitoringRuleThirdPartyOptions
object
Options on third party detection method.
4 properties
ObservabilityPipelineQuotaProcessorOverride
object
Defines a custom quota limit that applies to specific log events based on matching field values.
2 properties
2 required
Log
object
Object description of a log after being processed and stored by Datadog.
3 properties
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
APIKeyResponse
object
Response for retrieving an API key.
2 properties
SecurityMonitoringRuleSeverity
string
Severity of the Security Signal.
IncidentIntegrationMetadataResponseData
object
Incident integration metadata from a response.
4 properties
2 required
ObservabilityPipelineConfigDestinationItem
A destination for the pipeline.
SecurityMonitoringRuleDetectionMethod
string
The detection method.
ScheduleDataRelationshipsLayersDataItems
object
Relates a layer to this schedule, identified by id and type (must be layers).
2 properties
2 required
ObservabilityPipelineHttpServerSourceType
string
The source type. The value should always be httpserver.
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties
2 required
Escalation
object
Represents an escalation policy step.
3 properties
1 required
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property
1 required
APIKeyRelationships
object
Resources related to the API key.
2 properties
RestrictionPolicyResponse
object
Response containing information about a single restriction policy.
1 property
1 required
MetricCustomAggregation
object
A time and space aggregation combination for use in query.
2 properties
2 required
LogsResponseMetadataPage
object
Paging attributes.
1 property
DowntimeStatus
string
The current status of the downtime.
OrgConfigReadAttributes
object
Readable attributes of an Org Config.
5 properties
4 required
AuthNMappingResponse
object
AuthN Mapping response from the API.
2 properties
ObservabilityPipelineData
object
Contains the pipeline’s ID, type, and configuration attributes.
3 properties
3 required
MonitorNotificationRuleResponse
object
A monitor notification rule.
2 properties
ObservabilityPipelineQuotaProcessorOverflowAction
string
The action to take when the quota is exceeded. Options: - drop: Drop the event. - noaction: Let the event pass through. - overflowrouting: Route to an overflow…
ObservabilityPipelineSumoLogicDestinationType
string
The destination type. The value should always be sumologic.
ObservabilityPipelineSampleProcessor
object
The sample processor allows probabilistic sampling of logs at a fixed rate.
6 properties
4 required
NotificationRuleQuery
string
The query is composed of one or several key:value pairs, which can be used to filter security issues on tags and attributes.
MicrosoftTeamsWorkflowsWebhookHandleType
string
Specifies the Workflows webhook handle resource type.
SecurityMonitoringRuleCaseCreate
object
Case when signal is generated.
5 properties
1 required
ObservabilityPipelineFluentdSource
object
The fluentd source ingests logs from a Fluentd-compatible service.
3 properties
2 required
ObservabilityPipelineHttpServerSource
object
The httpserver source collects logs over HTTP POST from external services.
5 properties
4 required
TeamTargetType
string
Indicates that the resource is of type teams.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactOptions
object
Configuration for fully redacting sensitive data.
1 property
1 required
ObservabilityPipelineOcsfMappingLibrary
string
Predefined library mappings for common log formats.
RuleTypes
array
Security rule types used as filters in security rules.
DowntimeRelationshipsMonitor
object
The monitor identified by the downtime.
1 property
RoutingRuleAttributes
object
Defines the configurable attributes of a routing rule, such as actions, query, time restriction, and urgency.
4 properties
SpansMetricResponse
object
The span-based metric object.
1 property
AWSNamespaceFiltersIncludeOnly
object
Include only these namespaces.
1 property
1 required
ObservabilityPipelineSumoLogicSource
object
The sumologic source receives logs from Sumo Logic collectors.
2 properties
2 required
UsageObservabilityPipelinesResponse
object
Observability Pipelines usage response.
1 property
MicrosoftTeamsWorkflowsWebhookResponseAttributes
object
Workflows Webhook handle attributes.
1 property
AWSAccountResponseData
object
AWS Account response data.
3 properties
2 required
EscalationPolicy
object
Represents a complete escalation policy response, including policy data and optionally included related resources.
2 properties
TeamOnCallRespondersDataRelationshipsResponders
object
Defines the list of users assigned as on-call responders for the team.
1 property
SecurityMonitoringRuleNewValueOptionsLearningThreshold
integer
A number of occurrences after which signals will be generated for values that weren't learned.
ObservabilityPipelineSplunkHecDestination
object
The splunkhec destination forwards logs to Splunk using the HTTP Event Collector (HEC).
7 properties
3 required
IncidentServiceResponseData
object
Incident Service data from responses.
4 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeAll
object
Applies scanning across all available fields.
1 property
1 required
PowerpackRelationships
object
Powerpack relationship object.
1 property
Targets
array
List of recipients to notify when a notification rule is triggered. Many different target types are supported, such as email addresses, Slack channels, and Pag…
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
WidgetLiveSpan
string
The available timeframes depend on the widget you are using.
ScheduleTarget
object
Represents a schedule target for an escalation policy step, including its ID and resource type.
2 properties
2 required
DowntimeResponseIncludedItem
An object related to a downtime.
APIKeysType
string
API Keys resource type.
AWSAuthConfigKeys
object
AWS Authentication config to integrate your account using an access key pair.
2 properties
1 required
SBOMComponent
object
Software or hardware component.
5 properties
3 required
EscalationPolicyDataRelationships
object
Represents the relationships for an escalation policy, including references to steps and teams.
2 properties
1 required
SecurityMonitoringRuleImpossibleTravelOptions
object
Options on impossible travel detection method.
1 property
UserResponse
object
Response containing information about a single user.
2 properties
CloudWorkloadSecurityAgentPolicyType
string
The type of the resource, must always be policy
HistoricalJobOptions
object
Job options.
7 properties
TeamRoutingRules
object
Represents a complete set of team routing rules, including data and optionally included related resources.
2 properties
AuthNMappingTeam
object
Team.
3 properties
DowntimeRelationships
object
All relationships associated with downtime.
2 properties
SecurityMonitoringSuppressionResponse
object
Response object containing a single suppression rule.
1 property
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
RumMetricResponseData
object
The rum-based metric properties.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptionsDirection
string
Indicates whether to redact characters from the first or last part of the matched value.
TeamOnCallResponders
object
Root object representing a team's on-call responder configuration.
2 properties
FastlyServiceType
string
The JSON:API type for this API. Should always be fastly-services.
SecurityMonitoringRuleImpossibleTravelOptionsBaselineUserLocations
boolean
If true, signals are suppressed for the first 24 hours. In that time, Datadog learns the user's regular access locations. This can be helpful to reduce noise a…
AWSLogsServicesResponse
object
AWS Logs Services response body
1 property
1 required
MonitorNotificationRuleRelationshipsCreatedByData
objectnull
Data for the user who created the monitor notification rule.
2 properties
SpansMetricResponseGroupBy
object
A group by rule.
2 properties
ObservabilityPipelineSplunkHecSourceType
string
The source type. Always splunkhec.
NotificationRulesType
string
The rule type associated to notification rules.
TeamsResponseMeta
object
Teams response metadata.
1 property
TimeRestrictions
object
Holds time zone information and a list of time restrictions for a routing rule.
2 properties
2 required
IncidentIntegrationMetadataType
string
Integration metadata resource type.
HourlyUsageType
string
Usage type that is being measured.
GetRuleVersionHistoryDataType
string
Type of data.
RelationshipToUserTeamTeam
object
Relationship between team membership and team
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorScope
Determines which parts of the log the pattern-matching rule should be applied to.
TeamPermissionSettingType
string
Team permission setting type
LogsMetricResponseCompute
object
The compute rule to compute the log-based metric.
3 properties
RelationshipToUsers
object
Relationship to users.
1 property
1 required
SecurityMonitoringSignalsListResponseMeta
object
Meta attributes.
1 property
ObservabilityPipelineSyslogSourceMode
string
Protocol used by the syslog source to receive messages.
TeamAttributes
object
Team attributes
12 properties
2 required
IncidentTeamType
string
Incident Team resource type.
UserInvitationResponseData
object
Object of a user invitation returned by the API.
4 properties
IncidentType
string
Incident resource type.
IncidentRespondersType
string
The incident responders type.
ObservabilityPipelineHttpClientSource
object
The httpclient source scrapes logs from HTTP endpoints at regular intervals.
7 properties
3 required
RumMetricType
string
The type of the resource. The value should always be rummetrics.
SecurityMonitoringSignalsListResponseMetaPage
object
Paging attributes.
1 property
SecurityMonitoringRuleResponse
Create a new rule.
UserRelationshipData
object
Relationship to user object.
2 properties
2 required
ObservabilityPipelineMetricValue
Specifies how the value of the generated metric is computed.
AWSAccountResponseAttributes
object
AWS Account response attributes.
11 properties
1 required
ScheduleMemberRelationshipsUserDataType
string
Users resource type.
ObservabilityPipelineElasticsearchDestinationType
string
The destination type. The value should always be elasticsearch.
ObservabilityPipelineDedupeProcessorMode
string
The deduplication mode to apply to the fields.
SBOMMetadata
object
Provides additional information about a BOM.
1 property
TeamRoutingRulesDataType
string
Team routing rules resource type.
AWSRegionsIncludeAll
object
Include all regions. Defaults to true.
1 property
1 required
AWSLambdaForwarderConfig
object
Log Autosubscription configuration for Datadog Forwarder Lambda functions. Automatically set up triggers for existing and new logs for some services, ensuring…
2 properties
TeamsResponseMetaPagination
object
Teams response metadata.
8 properties
TriggerSource
string
The type of security issues on which the rule applies. Notification rules based on security signals need to use the trigger source "securitysignals", while not…
SecurityMonitoringSignalListRequestFilter
object
Search filters for listing security signals.
3 properties
ObservabilityPipelineSentinelOneDestinationRegion
string
The SentinelOne region to send logs to.
RestrictionQueryRelationships
object
Relationships of the restriction query object.
1 property
EscalationPolicyStepType
string
Indicates that the resource is of type steps.
ScheduleDataAttributes
object
Provides core properties of a schedule object such as its name and time zone.
2 properties
Weekday
string
A day of the week.
ObservabilityPipelineSentinelOneDestination
object
The sentinelone destination sends logs to SentinelOne.
4 properties
4 required
ObservabilityPipelineQuotaProcessorLimit
object
The maximum amount of data or number of events allowed before the quota is enforced. Can be specified in bytes or events.
2 properties
2 required
APIErrorResponse
object
API error response.
1 property
1 required
SecurityMonitoringSignalRuleResponse
object
Rule.
18 properties
UsageLambdaTracedInvocationsResponse
object
Lambda Traced Invocations usage response.
1 property
DowntimeNotifyEndTypes
array
Actions that will trigger a monitor notification if the downtime is in the notifyendtypes state.
ObservabilityPipelineDatadogAgentSource
object
The datadogagent source collects logs from the Datadog Agent.
3 properties
2 required
SecurityMonitoringRuleTypeRead
string
The rule type.
MetricsListResponseLinks
object
Pagination links. Only present if pagination query parameters were provided.
5 properties
ScheduleDataRelationshipsLayers
object
Associates layers with this schedule in a data structure.
1 property
UserTeamIncluded
Included resources related to the team membership
ObservabilityPipelineSentinelOneDestinationType
string
The destination type. The value should always be sentinelone.
WorklflowGetInstanceResponse
object
The state of the given workflow instance.
1 property
ExternalUserNameType
object
The components of user's real name
1 property
ObservabilityPipelineAmazonDataFirehoseSourceType
string
The source type. The value should always be amazondatafirehose.
HistoricalJobResponse
object
Historical job response.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternType
string
Indicates that a predefined library pattern is used.
PowerpackGroupWidgetLayout
object
Powerpack group widget layout.
4 properties
4 required
DowntimeScheduleRecurrenceRrule
string
The RRULE standard for defining recurring events. For example, to have a recurring event on the first day of each month, set the type to rrule and set the FREQ…
IncidentTodoAssignee
A todo assignee.
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties
1 required
Enabled
boolean
Field used to enable or disable the rule.
RumMetricID
string
The name of the rum-based metric.
LeakedKeyAttributes
object
The definition of LeakedKeyAttributes object.
2 properties
1 required
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
ObservabilityPipelineEnrichmentTableFile
object
Defines a static enrichment table loaded from a CSV file.
4 properties
4 required
DowntimeScheduleRecurrenceResponse
object
An RRULE-based recurring downtime.
3 properties
ObservabilityPipelineSyslogNgDestinationType
string
The destination type. The value should always be syslogng.
ObservabilityPipelineLogstashSourceType
string
The source type. The value should always be logstash.
TeamLinkAttributes
object
Team link attributes
4 properties
2 required
RelationshipToPermissions
object
Relationship to multiple permissions objects.
1 property
Selectors
object
Selectors are used to filter security issues for which notifications should be generated. Users can specify rule severities, rule types, a query to filter secu…
4 properties
1 required
SecurityMonitoringSignalListRequest
object
The request for a security signal list.
3 properties
IncidentIntegrationMetadataListResponse
object
Response with a list of incident integration metadata.
3 properties
1 required
DowntimeRelationshipsCreatedBy
object
The user who created the downtime.
1 property
RuleVersionUpdate
object
A change in a rule version.
3 properties
DowntimeScheduleRecurrenceDuration
string
The length of the downtime. Must begin with an integer and end with one of 'm', 'h', d', or 'w'.
RuleName
string
Name of the notification rule.
TeamPermissionSettingValues
array
Possible values for action
SecurityMonitoringRuleCase
object
Case when signal is generated.
5 properties
ObservabilityPipelineThrottleProcessorType
string
The processor type. The value should always be throttle.
IncidentTodoResponseData
object
Incident todo response data.
4 properties
2 required
IncidentTypeType
string
Incident type resource type.
MetricTagConfigurationMetricTypes
string
The metric's type.
EscalationPolicyDataType
string
Indicates that the resource is of type policies.
AwsScanOptionsData
object
Single AWS Scan Options entry.
3 properties
EscalationRelationshipsRespondersDataItems
object
Represents a user assigned to an escalation step.
2 properties
2 required
DowntimeResponse
object
Downtiming gives you greater control over monitor notifications by allowing you to globally exclude scopes from alerting. Downtime settings, which can be sched…
2 properties
ObservabilityPipelineFluentdSourceType
string
The source type. The value should always be fluentd.
ObservabilityPipelineGoogleChronicleDestination
object
The googlechronicle destination sends logs to Google Chronicle.
7 properties
5 required
RoleResponse
object
Response containing information about a single role.
1 property
DowntimeNotifyEndStates
array
States that will trigger a monitor notification when the notifyendtypes action occurs.
FullAPIKey
object
Datadog API key.
4 properties
SecurityMonitoringStandardRuleResponse
object
Rule.
24 properties
AssetType
string
The asset type
ObservabilityPipelineGoogleChronicleDestinationType
string
The destination type. The value should always be googlechronicle.
SecurityMonitoringRuleQueryAggregation
string
The aggregation type.
TeamOnCallRespondersIncluded
Represents an union of related resources included in the response, such as users and escalation steps.
AWSResourcesConfig
object
AWS Resources Collection config.
2 properties
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties
2 required
DowntimeDisplayTimezone
stringnull
The timezone in which to display the downtime's start and end times in Datadog applications. This is not used as an offset for scheduling.
ObservabilityPipelineGenerateMetricsProcessor
object
The generatedatadogmetrics processor creates custom metrics from logs and sends them to Datadog. Metrics can be counters, gauges, or distributions and optional…
5 properties
5 required
SLOReportStatusGetResponseAttributes
object
The attributes portion of the SLO report status response.
1 property
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties
2 required
SecurityMonitoringRuleDecreaseCriticalityBasedOnEnv
boolean
If true, signals in non-production environments have a lower severity than what is defined by the rule case, which can reduce signal noise. The severity is dec…
IncidentTodoResponseIncludedItem
An object related to an incident todo that is included in the response.
ExternalUserGroupMembersItems
object
The definition of a member belonging to a group.
4 properties
JiraIntegrationMetadata
object
Incident integration metadata for the Jira integration.
1 property
1 required
IncidentAttachmentType
string
The incident attachment resource type.
SecurityMonitoringFilter
object
The rule's suppression filter.
2 properties
SendSlackMessageActionType
string
Indicates that the action is a send Slack message action.
ObservabilityPipelineKafkaSourceLibrdkafkaOption
object
Represents a key-value pair used to configure low-level librdkafka client options for Kafka sources, such as timeouts, buffer sizes, and security settings.
2 properties
2 required
UserTeamUserType
string
User team user type
LayerRelationshipsMembersDataItems
object
Represents a single member object in a layer's members array, referencing a unique Datadog user ID.
2 properties
2 required
EscalationPolicyStepAttributes
object
Defines attributes for an escalation policy step, such as assignment strategy and escalation timeout.
2 properties
TeamOnCallRespondersDataRelationshipsEscalationsDataItemsType
string
Identifies the resource type for escalation policy steps linked to a team's on-call configuration.
LogsMetricResponseGroupBy
object
A group by rule.
2 properties
LogsListResponseLinks
object
Links attributes.
1 property
IPAllowlistResponse
object
Response containing information about the IP allowlist.
1 property
SpansMetricResponseCompute
object
The compute rule to compute the span-based metric.
3 properties
ShiftDataRelationshipsUserData
object
Represents a reference to the user assigned to this shift, containing the user's ID and resource type.
2 properties
2 required
IncidentTeamResponseData
object
Incident Team data from a response.
4 properties
ObservabilityPipelineDedupeProcessor
object
The dedupe processor removes duplicate fields in log events.
6 properties
6 required
IPAllowlistData
object
IP allowlist data.
3 properties
1 required
UserInvitationDataAttributes
object
Attributes of a user invitation.
4 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeAllTarget
string
Applies the rule to all fields.
ObservabilityPipelineGoogleCloudStorageDestinationStorageClass
string
Storage class used for objects stored in GCS.
OrganizationsType
string
Organizations resource type.
TeamOnCallRespondersData
object
Defines the main on-call responder object for a team, including relationships and metadata.
3 properties
1 required
SecurityMonitoringFilterAction
string
The type of filtering action.
UserResponseRelationships
object
Relationships of the user object returned by the API.
4 properties
SlackIntegrationMetadataChannelItem
object
Item in the Slack integration metadata channel array.
4 properties
3 required
ObservabilityPipelineOcsfMapperProcessorType
string
The processor type. The value should always be ocsfmapper.
ObservabilityPipelineSensitiveDataScannerProcessorScopeIncludeTarget
string
Applies the rule only to included fields.
SecurityMonitoringStandardDataSource
string
Source of events, either logs, audit trail, or Datadog events.
TeamPermissionSettingAttributes
object
Team permission setting attributes
5 properties
RestrictionQueryWithoutRelationships
object
Restriction query object returned by the API.
3 properties
ObservabilityPipelineAmazonOpenSearchDestination
object
The amazonopensearch destination writes logs to Amazon OpenSearch.
5 properties
4 required
ObservabilityPipelineGeneratedMetricIncrementByOne
object
Strategy that increments a generated metric by one for each matching event.
1 property
1 required
ScheduleMemberRelationshipsUserData
object
Points to the user data associated with this schedule member, including an ID and type.
2 properties
2 required
RelationshipToOrganization
object
Relationship to an organization.
1 property
1 required
ObservabilityPipelineParseGrokProcessorType
string
The processor type. The value should always be parsegrok.
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
SpansAggregateResponseStatus
string
The status of the response.
IncidentIntegrationRelationships
object
The incident's integration relationships from a response.
2 properties
IncidentTodoAssigneeArray
array
Array of todo assignees.
RumMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when aggregationtype is distribution.
SBOMAttributes
object
The JSON:API attributes of the SBOM.
6 properties
6 required
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
AWSAccountID
string
AWS Account ID.
ShiftDataRelationshipsUser
object
Defines the relationship between a shift and the user who is working that shift.
1 property
1 required
SecurityMonitoringThirdPartyRootQuery
object
A query to be combined with the third party case query.
2 properties
ScheduleDataRelationshipsLayersDataItemsType
string
Layers resource type.
ObservabilityPipelineSplunkHecDestinationType
string
The destination type. Always splunkhec.
ObservabilityPipelineGoogleChronicleDestinationEncoding
string
The encoding format for the logs sent to Chronicle.
DataRelationshipsTeams
object
Associates teams with this schedule in a data structure.
1 property
AWSNamespaceFilters
AWS Metrics namespace filters. Defaults to excludeonly.
RelationshipToOrganizations
object
Relationship to organizations.
1 property
1 required
AuthNMappingAttributes
object
Attributes of AuthN Mapping.
5 properties
MetricTagConfiguration
object
Object for a single metric tag configuration.
3 properties
ObservabilityPipelineParseJSONProcessor
object
The parsejson processor extracts JSON from a specified field and flattens it into the event. This is useful when logs contain embedded JSON as a string.
5 properties
5 required
ObservabilityPipelineLogstashSource
object
The logstash source ingests logs from a Logstash forwarder.
3 properties
2 required
DowntimeScheduleRecurrencesResponse
object
A recurring downtime schedule definition.
3 properties
1 required
TeamRelationships
object
Resources related to a team
2 properties
AWSAccountResponse
object
AWS Account response body.
1 property
1 required
ObservabilityPipelineEnrichmentTableProcessor
object
The enrichmenttable processor enriches logs using a static CSV file or GeoIP database.
7 properties
5 required
UserInvitationRelationships
object
Relationships data for user invitation.
1 property
1 required
SAMLAssertionAttributeAttributes
object
Key/Value pair of attributes used in SAML assertion attributes.
2 properties
AWSLogsConfig
object
AWS Logs Collection config.
1 property
ObservabilityPipelineSplunkHecDestinationEncoding
string
Encoding format for log events.
LogsMetricType
string
The type of the resource. The value should always be logsmetrics.
RuleTypesItems
string
Security rule type which can be used in security rules. Signal-based notification rules can filter signals based on rule types applicationsecurity, logdetectio…
TeamRelationshipsLinks
object
Links attributes.
1 property
UserAttributes
object
Attributes of user object returned by the API.
12 properties
RelationshipToUserTeamPermission
object
Relationship between a user team permission and a team
2 properties
PermissionsType
string
Permissions resource type.
GetTeamMembershipsSort
string
Specifies the order of returned team memberships
AWSNamespaceTagFilter
object
AWS Metrics Collection tag filters list. Defaults to []. The array of custom AWS resource tags (in the form key:value) defines a filter that Datadog uses when…
2 properties
RelationshipToSAMLAssertionAttributeData
object
Data of AuthN Mapping relationship to SAML Assertion Attribute.
2 properties
2 required
AzureStorageDestinationType
string
The destination type. The value should always be azurestorage.
ShiftDataType
string
Indicates that the resource is of type 'shifts'.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExcludeTarget
string
Excludes specific fields from processing.
HistoricalJobResponseData
object
Historical job response data.
3 properties
DowntimeScheduleCurrentDowntimeResponse
object
The most recent actual start and end dates for a recurring downtime. For a canceled downtime, this is the previously occurring downtime. For active downtimes,…
2 properties
RumMetricEventType
string
The type of RUM events to filter on.
PowerpackResponse
object
Response object which includes a single powerpack configuration.
2 properties
ObservabilityPipelineEnrichmentTableFileEncodingType
string
Specifies the encoding format (e.g., CSV) used for enrichment tables.
RoutingRuleAction
Defines an action that is executed when a routing rule matches certain criteria.
SendSlackMessageAction
object
Sends a message to a Slack channel.
3 properties
3 required
UserResourceType
string
User resource type.
RestrictionQueryAttributes
object
Attributes of the restriction query.
3 properties
ObservabilityPipelineGenerateMetricsProcessorType
string
The processor type. Always generatedatadogmetrics.
LayerRelationships
object
Holds references to objects related to the Layer entity, such as its members.
1 property
RumMetricResponseFilter
object
The rum-based metric filter. RUM events matching this filter will be aggregated in this metric.
1 property
NotificationRule
object
Notification rules allow full control over notifications generated by the various Datadog security products. They allow users to define the conditions under wh…
3 properties
3 required
CloudWorkloadSecurityAgentPolicyResponse
object
Response object that includes an Agent policy
1 property
SpansMetricResponseAttributes
object
The object describing a Datadog span-based metric.
3 properties
MicrosoftTeamsTenantBasedHandleType
string
Specifies the tenant-based handle resource type.
NullableRelationshipToUserData
objectnull
Relationship to user object.
2 properties
2 required
MonitorNotificationRuleId
string
The ID of the monitor notification rule.
ObservabilityPipelineQuotaProcessorLimitEnforceType
string
Unit for quota enforcement in bytes for data size or events for count.
DowntimeRelationshipsMonitorData
objectnull
Data for the monitor.
2 properties
ScheduleDataIncludedItem
Any additional resources related to this schedule, such as teams and layers.
AWSRegionsIncludeOnly
object
Include only these regions.
1 property
1 required
SecurityMonitoringRuleCaseAction
object
Action to perform when a signal is triggered. Only available for Application Security rule type.
2 properties
ExternalUser
object
Definition of a user.
8 properties
SAMLAssertionAttribute
object
SAML assertion attribute.
3 properties
2 required
SecurityMonitoringRuleOptions
object
Options.
10 properties
RelationshipToTeamLinks
object
Relationship between a team and a team link
2 properties
AWSNamespaceFiltersExcludeOnly
object
Exclude only these namespaces from metrics collection. Defaults to ["AWS/SQS", "AWS/ElasticMapReduce"]. AWS/SQS and AWS/ElasticMapReduce are excluded by defaul…
1 property
1 required
ObservabilityPipelineEnrichmentTableProcessorType
string
The processor type. The value should always be enrichmenttable.
UserTargetType
string
Indicates that the resource is of type users.
DowntimeMonitorIdentifier
Monitor identifier for the downtime.
SpansType
string
Type of the span.
RelationshipToUserTeamPermissionData
object
Related user team permission data
2 properties
2 required
TeamOnCallRespondersDataType
string
Represents the resource type for a group of users assigned to handle on-call duties within a team.
IncidentTypeObject
object
Incident type response data.
3 properties
2 required
PowerpackAttributes
object
Powerpack attribute object.
5 properties
2 required
IPAllowlistEntryAttributes
object
Attributes of the IP allowlist entry.
4 properties
TimeAggregation
integer
Time aggregation period (in seconds) is used to aggregate the results of the notification rule evaluation. Results are aggregated over a selected time frame us…
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternOptions
object
Options for defining a custom regex pattern.
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactAction
string
Action type that completely replaces the matched sensitive data with a fixed replacement string to remove all visibility.
AWSLogsServicesResponseAttributes
object
AWS Logs Services response body
1 property
1 required
ObservabilityPipelineDataAttributes
object
Defines the pipeline’s name and its components (sources, processors, and destinations).
2 properties
2 required
SAMLAssertionAttributesType
string
SAML assertion attributes resource type.
OrgConfigRead
object
A single Org Config.
3 properties
3 required
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
CloudWorkloadSecurityAgentPolicyData
object
Object for a single Agent policy
3 properties
MicrosoftTeamsTenantBasedHandleResponse
object
Response of a tenant-based handle.
1 property
1 required
OpsgenieServiceResponseData
object
Opsgenie service data from a response.
3 properties
3 required
RoleAttributes
object
Attributes of the role.
4 properties
MetricTagConfigurationAttributes
object
Object containing the definition of a metric tag configuration attributes.
7 properties
ScheduleMember
object
Represents a single member entry in a schedule, referencing a specific user.
3 properties
1 required
SecurityMonitoringThirdPartyRuleCaseCreate
object
Case when a signal is generated by a third party rule.
4 properties
1 required
TeamRoutingRulesData
object
Represents the top-level data object for team routing rules, containing the ID, relationships, and resource type.
3 properties
1 required
LogAttributes
object
JSON object containing all log attributes and their associated values.
7 properties
LayerRelationshipsMembersDataItemsType
string
Members resource type.
IncidentAttachmentData
object
A single incident attachment.
4 properties
4 required
NotificationRuleResponse
object
Response object which includes a notification rule.
1 property
TeamResponse
object
Response with a team
1 property
CloudConfigurationComplianceRuleOptions
object
Options for cloudconfiguration rules. Fields resourceType and regoRule are mandatory when managing custom cloudconfiguration rules.
3 properties
UserTeamTeamType
string
User team team type
DowntimeMessage
stringnull
A message to include with notifications for this downtime. Email notifications can be sent to specific users by using the same @username notation as events.
RumMetricResponse
object
The rum-based metric object.
1 property
SLOReportStatus
string
The status of the SLO report job.
TeamLink
object
Team link
3 properties
3 required
UserTarget
object
Represents a user target for an escalation policy step, including the user's ID and resource type.
2 properties
2 required
ObservabilityPipelineEnrichmentTableFileSchemaItemsType
string
Declares allowed data types for enrichment table columns.
MonitorNotificationRuleData
object
Monitor notification rule data.
4 properties
ObservabilityPipelineSensitiveDataScannerProcessorType
string
The processor type. The value should always be sensitivedatascanner.
SpansListResponse
object
Response object with all spans matching the request and pagination information.
3 properties
RumMetricResponseAttributes
object
The object describing a Datadog rum-based metric.
5 properties
EscalationPolicyStepAttributesAssignment
string
Specifies how this escalation step will assign targets (example default or round-robin).
SecurityMonitoringRuleMaxSignalDuration
integer
A signal will "close" regardless of the query being matched once the time exceeds the maximum duration. This time is calculated from the first seen timestamp.
EscalationRelationshipsRespondersDataItemsType
string
Represents the resource type for users assigned as responders in an escalation step.
ExternalUserMeta
object
Metadata associated with a user.
4 properties
UserTeamsResponse
object
Team memberships response
4 properties
MonitorNotificationRuleRelationships
object
All relationships associated with monitor notification rule.
1 property
SecurityMonitoringSignalRuleType
string
The rule type.
RelationshipToPermissionData
object
Relationship to permission object.
2 properties
EscalationPolicyDataAttributes
object
Defines the main attributes of an escalation policy, such as its name and behavior on policy end.
3 properties
1 required
PowerpackGroupWidget
object
Powerpack group widget definition object.
3 properties
1 required
AWSTracesConfig
object
AWS Traces Collection config.
1 property
MicrosoftTeamsWorkflowsWebhookHandleResponseData
object
Workflows Webhook handle data from a response.
3 properties
ObservabilityPipelineSyslogNgDestination
object
The syslogng destination forwards logs to an external syslog-ng server over TCP or UDP using the syslog protocol.
5 properties
3 required
EscalationPolicyDataRelationshipsSteps
object
Defines the relationship to a collection of steps within an escalation policy. Contains an array of step data references.
1 property
ObservabilityPipelineThrottleProcessor
object
The throttle processor limits the number of events that pass through over a given time window.
7 properties
6 required
XRayServicesIncludeAll
object
Include all services.
1 property
1 required
CloudConfigurationRegoRule
object
Rule details.
2 properties
2 required
RumMetricResponseUniqueness
object
The rule to count updatable events. Is only set if eventtype is session or view.
1 property
AuthNMappingRelationships
object
All relationships associated with AuthN Mapping.
3 properties
DowntimeMonitorIncludedItem
object
Information about the monitor identified by the downtime.
3 properties
RestrictionQueryRoleAttribute
object
Attributes of the role for a restriction query.
1 property
MonitorNotificationRuleFilterTags
object
Filter monitors by tags. Monitors must match all tags.
1 property
1 required
RestrictionPolicy
object
Restriction policy object.
3 properties
3 required
IncidentServiceIncludedItems
An object related to an incident service which is present in the included payload.
IncidentRelatedObject
string
Object related to an incident.
SpansSort
string
Sort parameters when querying spans.
SpansAttributes
object
JSON object containing all span attributes and their associated values.
17 properties
OpsgenieServiceRegionType
string
The region for the Opsgenie service.
HistoricalJobDataType
string
Type of payload.
AWSAccountType
string
AWS Account resource type.
Schedule
object
Top-level container for a schedule object, including both the data payload and any related included resources (such as teams, layers, or members).
2 properties
RelationshipToUserTeamUser
object
Relationship between team membership and user
1 property
1 required
PermissionAttributes
object
Attributes of a permission.
7 properties
UserAttributesStatus
string
The user's status.
APIKeyResponseIncludedItem
An object related to an API key.
FastlyServiceResponse
object
The expected response schema when getting a Fastly service.
1 property
MonitorNotificationRuleResponseAttributes
object
Attributes of the monitor notification rule.
5 properties
Layer
object
Encapsulates a layer resource, holding attributes like rotation details, plus relationships to the members covering that layer.
4 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionHashAction
string
Action type that replaces the matched sensitive data with a hashed representation, preserving structure while securing content.
TeamPermissionSettingValue
string
What type of user is allowed to perform the specified action
SecurityMonitoringRuleKeepAlive
integer
Once a signal is generated, the signal will remain "open" if a case is matched at least once within this keep alive window. For third party detection method, t…
IPAllowlistEntry
object
IP allowlist entry object.
1 property
1 required
ObservabilityPipelineKafkaSourceType
string
The source type. The value should always be kafka.
ObservabilityPipelineAddFieldsProcessor
object
The addfields processor adds static key-value fields to logs.
5 properties
5 required
TeamLinkType
string
Team link type
ObservabilityPipelineSensitiveDataScannerProcessorKeywordOptions
object
Configuration for keywords used to reinforce sensitive data pattern detection.
2 properties
2 required
OrgConfigGetResponse
object
A response with a single Org Config.
1 property
1 required
SecurityMonitoringRuleNewValueOptionsForgetAfter
integer
The duration in days after which a learned value is forgotten.
DowntimeScheduleOneTimeResponse
object
A one-time downtime definition.
2 properties
1 required
ObservabilityPipelineMetadataEntry
object
A custom metadata entry.
2 properties
2 required
MetricName
string
The metric name for this resource.
UserInvitationResponse
object
User invitation as returned by the API.
1 property
ObservabilityPipelineQuotaProcessorType
string
The processor type. The value should always be quota.
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorRule
object
Defines a rule for detecting sensitive data, including matching pattern, scope, and the action to take.
6 properties
5 required
CalculatedField
object
Calculated field.
2 properties
2 required
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties
2 required
ObservabilityPipelineAmazonOpenSearchDestinationType
string
The destination type. The value should always be amazonopensearch.
IncidentTodoListResponse
object
Response with a list of incident todos.
3 properties
1 required
PowerpackGroupWidgetDefinition
object
Powerpack group widget object.
5 properties
3 required
ObservabilityPipelineDatadogLogsDestinationType
string
The destination type. The value should always be datadoglogs.
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
ObservabilityPipelineDatadogAgentSourceType
string
The source type. The value should always be datadogagent.
ObservabilityPipelineGoogleCloudStorageDestinationAcl
string
Access control list setting for objects written to the bucket.
ObservabilityPipelineSumoLogicDestinationEncoding
string
The output encoding format.
ScheduleUserAttributes
object
Provides basic user information for a schedule, including a name and email address.
3 properties
TeamTarget
object
Represents a team target for an escalation policy step, including the team's ID and resource type.
2 properties
2 required
RelationshipToUserTeamTeamData
object
The team associated with the membership
2 properties
2 required
ProjectResponse
object
Project response
1 property
DowntimeScheduleResponse
The schedule that defines when the monitor starts, stops, and recurs. There are two types of schedules: one-time and recurring. Recurring schedules may have up…
ObservabilityPipelineHttpServerSourceAuthStrategy
string
HTTP authentication method.
SBOMMetadataComponent
object
The component that the BOM describes.
2 properties
RuleSeverity
string
Severity of a security rule.
MicrosoftTeamsWorkflowsWebhookHandleResponse
object
Response of a Workflows webhook handle.
1 property
1 required
IPAllowlistAttributes
object
Attributes of the IP allowlist.
2 properties
CloudWorkloadSecurityAgentPolicyUpdaterAttributes
object
The attributes of the user who last updated the policy
2 properties
ObservabilityPipelineSampleProcessorType
string
The processor type. The value should always be sample.
IncidentIntegrationMetadataMetadata
Incident integration metadata's metadata attribute.
ObservabilityPipelineSyslogNgSource
object
The syslogng source listens for logs over TCP or UDP from a syslog-ng server using the syslog protocol.
4 properties
3 required
ObservabilityPipelineDecoding
string
The decoding format used to interpret incoming logs.
UserTeam
object
A user's relationship with a team
4 properties
2 required
IncidentResponseMetaPagination
object
Pagination properties.
3 properties
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
ShiftDataRelationshipsUserDataType
string
Indicates that the related resource is of type 'users'.
IPAllowlistEntryType
string
IP allowlist Entry type.
RolesType
string
Roles type.
RestrictionQueryListResponse
object
Response containing information about multiple restriction queries.
1 property
ObservabilityPipelineGcpAuth
object
GCP credentials used to authenticate with Google Cloud Storage.
1 property
1 required
ObservabilityPipelineRemoveFieldsProcessor
object
The removefields processor deletes specified fields from logs.
5 properties
5 required
Role
object
Role object returned by the API.
4 properties
1 required
LogsMetricResponseAttributes
object
The object describing a Datadog log-based metric.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorPattern
Pattern detection configuration for identifying sensitive data using either a custom regex or a library reference.
AWSAuthConfigRole
object
AWS Authentication config to integrate your account using an IAM role.
2 properties
1 required
ObservabilityPipelineOcsfMapperProcessor
object
The ocsfmapper processor transforms logs into the OCSF schema using a predefined mapping configuration.
5 properties
5 required
SpansMetricResponseFilter
object
The span-based metric filter. Spans matching this filter will be aggregated in this metric.
1 property
ObservabilityPipelineReduceProcessor
object
The reduce processor aggregates and merges logs based on matching keys and merge strategies.
6 properties
6 required
MetricTagConfigurationMetricTypeCategory
string
The metric's type category.
ObservabilityPipelineEnrichmentTableFileEncoding
object
File encoding format.
3 properties
3 required
TeamOnCallRespondersDataRelationshipsEscalations
object
Defines the escalation policy steps linked to the team's on-call configuration.
1 property
LogsSort
string
Sort parameters when querying logs.
ObservabilityPipelineParseGrokProcessorRule
object
A Grok parsing rule used in the parsegrok processor. Each rule defines how to extract structured fields from a specific log field using Grok patterns.
3 properties
3 required
RumMetricResponseCompute
object
The compute rule to compute the rum-based metric.
3 properties
ScheduleDataType
string
Schedules resource type.
IncidentResponse
object
Response with an incident.
2 properties
1 required
IPAllowlistType
string
IP allowlist type.
TimeRestriction
object
Defines a single time restriction rule with start and end times and the applicable weekdays.
4 properties
ObservabilityPipelineEnrichmentTableFileSchemaItems
object
Describes a single column and its type in an enrichment table schema.
2 properties
2 required
ObservabilityPipelineRsyslogDestination
object
The rsyslog destination forwards logs to an external rsyslog server over TCP or UDP using the syslog protocol.
5 properties
3 required
HistoricalJobResponseAttributes
object
Historical job attributes.
8 properties
ObservabilityPipelineRemoveFieldsProcessorType
string
The processor type. The value should always be removefields.
Date
integer
Date as Unix timestamp in milliseconds.
ShiftIncluded
The definition of ShiftIncluded object.
JiraIntegrationMetadataIssuesItem
object
Item in the Jira integration metadata issue array.
5 properties
2 required
ObservabilityPipelineAmazonS3SourceType
string
The source type. Always amazons3.
ObservabilityPipelineGeneratedMetricIncrementByField
object
Strategy that increments a generated metric based on the value of a log field.
2 properties
2 required
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
EscalationPolicyDataRelationshipsStepsDataItemsType
string
Indicates that the resource is of type steps.
AWSRegions
AWS Regions to collect data from. Defaults to includeall.
MicrosoftTeamsTenantBasedHandleAttributes
object
Tenant-based handle attributes.
4 properties
AuthNMapping
object
The AuthN Mapping object returned by API.
4 properties
2 required
SendTeamsMessageActionType
string
Indicates that the action is a send Microsoft Teams message action.
ProjectResourceType
string
Project resource type
UserInvitationsType
string
User invitations type.
ObservabilityPipelineParseJSONProcessorType
string
The processor type. The value should always be parsejson.
RuleUser
object
User creating or modifying a rule.
2 properties
PermissionsResponse
object
Payload with API-returned permissions.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorCustomPattern
object
Defines a custom regex-based pattern for identifying sensitive data in logs.
2 properties
2 required
ObservabilityPipelineAddEnvVarsProcessorType
string
The processor type. The value should always be addenvvars.
SecurityMonitoringSignalAttributes
object
The object containing all signal attributes and their associated values.
4 properties
DowntimeRelationshipsCreatedByData
objectnull
Data for the user who created the downtime.
2 properties
ObservabilityPipelineElasticsearchDestination
object
The elasticsearch destination writes logs to an Elasticsearch cluster.
5 properties
3 required
TeamOnCallRespondersDataRelationshipsRespondersDataItems
object
Represents a user responder associated with the on-call team.
2 properties
2 required
ExternalUserEmailType
object
Email address for the user.
3 properties
IncidentResponseData
object
Incident data from a response.
4 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptions
object
Controls how partial redaction is applied, including character count and direction.
2 properties
2 required
ObservabilityPipelineConfigProcessorItem
A processor for the pipeline.
FastlyServiceAttributes
object
Attributes object for Fastly service requests.
1 property
IncidentImpactsType
string
The incident impacts type.
IncidentTypeResponse
object
Incident type response data.
1 property
1 required
ObservabilityPipelineRenameFieldsProcessorType
string
The processor type. The value should always be renamefields.
User
object
User object returned by the API.
4 properties
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property
1 required
LogsResponseMetadata
object
The metadata associated with a request
5 properties
ObservabilityPipelineNewRelicDestinationRegion
string
The New Relic region.
GetSBOMResponse
object
The expected response schema when getting an SBOM.
1 property
1 required
FastlyServiceData
object
Data object for Fastly service requests.
3 properties
2 required
RestrictionQueryRole
object
Partial role object.
3 properties
PowerpackInnerWidgets
object
Powerpack group widget definition of individual widgets.
2 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeOptions
object
Fields to which the scope rule applies.
1 property
1 required
RestrictionPolicyBinding
object
Specifies which principals are associated with a relation.
2 properties
2 required
EscalationType
string
Represents the resource type for individual steps in an escalation policy used during incident response.
ObservabilityPipelineAddFieldsProcessorType
string
The processor type. The value should always be addfields.
MetricsAndMetricTagConfigurationsResponse
object
Response object that includes metrics and metric tag configurations.
3 properties
DowntimeScope
string
The scope to which the downtime applies. Must follow the [common search syntax](https://docs.datadoghq.com/logs/explorer/searchsyntax/).
AWSAccountConfigID
string
Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/ap…
JSONAPIErrorResponse
object
API error response.
1 property
1 required
HistoricalJobQuery
object
Query for selecting logs analyzed by the historical job.
8 properties
UsersType
string
Users resource type.
RoutingRuleRelationshipsPolicyDataType
string
Indicates that the resource is of type 'policies'.
EscalationPolicyStep
object
Represents a single step in an escalation policy, including its attributes, relationships, and resource type.
4 properties
1 required
IncidentsResponse
object
Response with a list of incidents.
3 properties
1 required
IncidentTypeListResponse
object
Response with a list of incident types.
1 property
1 required
AWSLogsServicesResponseDataType
string
The AWSLogsServicesResponseData type.
SecurityMonitoringRuleNewValueOptions
object
Options on new value detection method.
4 properties
TeamOnCallRespondersDataRelationshipsRespondersDataItemsType
string
Identifies the resource type for individual user entities associated with on-call response.
IncidentTeamRelationships
object
The incident team's relationships.
2 properties
ObservabilityPipelineKafkaSourceSasl
object
Specifies the SASL mechanism for authenticating with a Kafka cluster.
1 property
ObservabilityPipelineOpenSearchDestinationType
string
The destination type. The value should always be opensearch.
ObservabilityPipelineAwsAuth
object
AWS authentication credentials used for accessing AWS services such as S3. If omitted, the system’s default credentials are used (for example, the IAM role and…
3 properties
SecurityMonitoringSignalsListResponseLinks
object
Links attributes.
1 property
MicrosoftTeamsTenantBasedHandleResponseData
object
Tenant-based handle data from a response.
3 properties
IncidentTodoResponse
object
Response with an incident todo.
2 properties
1 required
DowntimeMonitorIncludedAttributes
object
Attributes of the monitor identified by the downtime.
1 property
DowntimeNotifyEndStateActions
string
Action that will trigger a monitor notification if the downtime is in the notifyendtypes state.
IncidentSeverity
string
The incident severity.
ObservabilityPipelineFilterProcessor
object
The filter processor allows conditional processing of logs based on a Datadog search query. Logs that match the include query are passed through; others are di…
4 properties
4 required
EscalationPolicyDataRelationshipsStepsDataItems
object
Defines a relationship to a single step within an escalation policy. Contains the step's id and type.
2 properties
2 required
Metric
object
Object for a single metric tag configuration.
2 properties
EscalationPolicyStepRelationships
object
Represents the relationship of an escalation policy step to its targets.
1 property
RuleVersions
object
A rule version with a list of updates.
2 properties
PowerpackData
object
Powerpack data object.
4 properties
UserTeamRole
stringnull
The user's role within the team
DowntimeNotifyEndStateTypes
string
State that will trigger a monitor notification when the notifyendtypes action occurs.
ObservabilityPipelineAmazonS3Destination
object
The amazons3 destination sends your logs in Datadog-rehydratable format to an Amazon S3 bucket for archiving.
9 properties
6 required
ObservabilityPipelineNewRelicDestinationType
string
The destination type. The value should always be newrelic.
MSTeamsIntegrationMetadataTeamsItem
object
Item in the Microsoft Teams integration metadata teams array.
4 properties
4 required
LayerAttributesInterval
object
Defines how often the rotation repeats, using a combination of days and optional seconds.
2 properties
RoutingRuleRelationshipsPolicyData
object
Represents the policy data reference, containing the policy's ID and resource type.
2 properties
2 required
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
MonitorNotificationRuleRecipients
array
A list of recipients to notify. Uses the same format as the monitor message field. Must not start with an '@'.
ObservabilityPipelineFluentBitSource
object
The fluentbit source ingests logs from Fluent Bit.
3 properties
2 required
DowntimeResponseData
object
Downtime data.
4 properties
MetricTagConfigurationType
string
The metric tag configuration resource type.
IncidentUserData
object
User object returned by the API.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionHash
object
Configuration for hashing matched sensitive values.
2 properties
1 required
ObservabilityPipelineRsyslogSourceType
string
The source type. The value should always be rsyslog.
GetRuleVersionHistoryData
object
Data for the rule version history.
3 properties
OpsgenieServiceResponse
object
Response of an Opsgenie service.
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorAction
Defines what action to take when sensitive data is matched.
MetricsAndMetricTagConfigurations
Object for a metrics and metric tag configurations.
IncidentServiceResponseAttributes
object
The incident service's attributes from a response.
3 properties
RuleVersionHistory
object
Response object containing the version history of a rule.
2 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Datadog publishes across the network.