The identity and technical contract details declared by the specification.
ServiceDefinitionV2
object
Service definition V2 for providing service metadata and integrations.
11 properties
2 required
ScheduleMemberRelationshipsUserDataType
string
Users resource type.
LogsArchiveDestinationAzure
object
The Azure archive destination.
6 properties
4 required
ContainerImageFlavor
object
Container Image breakdown by supported platform.
5 properties
SecurityMonitoringSignalType
string
The type of event.
ActionQueryCondition
Whether to run this query. If specified, the query will only run if this condition evaluates to true in JavaScript and all other conditions are also met.
ServiceDefinitionV2Dot1SlackType
string
Contact type.
OrganizationAttributes
object
Attributes of the organization.
8 properties
ListTagsResponse
object
List tags response.
1 property
OrgConfigReadAttributes
object
Readable attributes of an Org Config.
5 properties
4 required
CustomConnectionAttributesOnPremRunner
object
Information about the Private Action Runner used by the custom connection, if the custom connection is associated with a Private Action Runner.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionHashAction
string
Action type that replaces the matched sensitive data with a hashed representation, preserving structure while securing content.
RelationshipToTeamLinks
object
Relationship between a team and a team link
2 properties
IncidentServicesResponse
object
Response with a list of incident service payloads.
3 properties
1 required
DomainAllowlistResponse
object
Response containing information about the email domain allowlist.
1 property
LogsStorageTier
string
Specifies storage type as indexes, online-archives or flex
TeamPermissionSettingSerializerAction
string
The identifier for the action
DORAListDeploymentsRequestDataType
string
The definition of DORAListDeploymentsRequestDataType object.
FastlyServiceType
string
The JSON:API type for this API. Should always be fastly-services.
EntityToOncalls
object
Entity to oncalls relationship.
1 property
Version
integer
Version of the notification rule. It is updated when the rule is modified.
ServiceNowTicket
object
ServiceNow ticket attached to case
2 properties
TeamRelationships
object
Resources related to a team
2 properties
CustomCostGetResponseMeta
object
Meta for the response from the Get Custom Costs endpoints.
1 property
ObservabilityPipelineDedupeProcessorMode
string
The deduplication mode to apply to the fields.
IncidentResponseMetaPagination
object
Pagination properties.
3 properties
ConfluentResourceType
string
The JSON:API type for this request.
ShiftDataAttributes
object
The definition of ShiftDataAttributes object.
2 properties
Deployment
object
The version of the app that was published.
4 properties
RelationshipToUserTeamTeamData
object
The team associated with the membership
2 properties
2 required
EntityV3DatastoreDatadog
object
Datadog product integrations for the datastore entity.
3 properties
AWSLogsServicesResponseDataType
string
The AWSLogsServicesResponseData type.
EventStatusType
string
If an alert event is enabled, its status is one of the following: failure, error, warning, info, success, userupdate, recommendation, or snapshot.
IncidentResponseMeta
object
The metadata object containing pagination metadata.
1 property
MonthlyCostAttributionAttributes
object
Cost Attribution by Tag for a given organization.
7 properties
EventsSort
string
The sort parameters when querying events.
AzureStorageDestinationType
string
The destination type. The value should always be azurestorage.
CloudWorkloadSecurityAgentRuleUpdaterAttributes
object
The attributes of the user who last updated the Agent rule
2 properties
ObservabilityPipelineMetadataEntry
object
A custom metadata entry.
2 properties
2 required
ProcessSummariesMeta
object
Response metadata object.
1 property
PowerpackGroupWidgetDefinition
object
Powerpack group widget object.
5 properties
3 required
Permission
object
Permission object.
3 properties
1 required
TeamReference
object
Provides a reference to a team, including ID, type, and basic attributes/relationships.
3 properties
1 required
LogsArchiveIntegrationGCS
object
The GCS archive's integration destination.
2 properties
1 required
ServiceDefinitionV2Dot2
object
Service definition v2.2 for providing service metadata and integrations.
15 properties
2 required
ObservabilityPipelineSyslogNgDestinationType
string
The destination type. The value should always be syslogng.
PowerpackAttributes
object
Powerpack attribute object.
5 properties
2 required
ObservabilityPipelineEnrichmentTableFileEncodingType
string
Specifies the encoding format (e.g., CSV) used for enrichment tables.
AuthNMappingRelationships
object
All relationships associated with AuthN Mapping.
3 properties
ObservabilityPipelineFluentdSourceType
string
The source type. The value should always be fluentd.
RetentionFilterAll
object
The definition of the retention filter.
3 properties
3 required
IPAllowlistAttributes
object
Attributes of the IP allowlist.
2 properties
TokenType
string
The definition of TokenType object.
ObservabilityPipelineOcsfMapperProcessorMappingMapping
Defines a single mapping rule for transforming logs into the OCSF schema.
ContainerImageGroupRelationshipsLinks
object
Links attributes.
1 property
RelationResponseType
string
Relation type.
XRayServicesIncludeAll
object
Include all services.
1 property
1 required
MSTeamsIntegrationMetadataTeamsItem
object
Item in the Microsoft Teams integration metadata teams array.
4 properties
4 required
UsageApplicationSecurityMonitoringResponse
object
Application Security Monitoring usage response.
1 property
UserTeamPermissionAttributes
object
User team permission attributes
1 property
AWSLogsServicesResponse
object
AWS Logs Services response body
1 property
1 required
LogsArchiveEncryptionS3
object
The S3 encryption settings.
2 properties
1 required
AWSNamespaceTagFilter
object
AWS Metrics Collection tag filters list. Defaults to []. The array of custom AWS resource tags (in the form key:value) defines a filter that Datadog uses when…
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationType
string
The destination type. Always googlecloudstorage.
CustomCostsFileLineItem
object
Line item details from a Custom Costs file.
7 properties
DowntimeNotifyEndStateActions
string
Action that will trigger a monitor notification if the downtime is in the notifyendtypes state.
DataRelationshipsTeamsDataItems
object
Relates a team to this schedule, identified by id and type (must be teams).
2 properties
2 required
ApplicationSecurityWafExclusionFilterScope
object
Deploy on services based on their environment and/or service name.
2 properties
AnnotationDisplayBounds
object
The definition of AnnotationDisplayBounds object.
4 properties
IncidentTodoAssigneeHandle
string
Assignee's @-handle.
LogsArchiveState
string
The state of the archive.
BudgetWithEntriesData
object
A budget and all its entries.
3 properties
TeamRoutingRulesIncluded
Represents additional included resources for team routing rules, such as associated routing rules.
ContainerImagesResponseLinks
object
Pagination links.
5 properties
ObservabilityPipelineQuotaProcessorLimitEnforceType
string
Unit for quota enforcement in bytes for data size or events for count.
CIAppResponsePage
object
Paging attributes.
1 property
SecurityMonitoringRuleNewValueOptionsLearningDuration
integer
The duration in days during which values are learned, and after which signals will be generated for values that weren't learned. If set to 0, a signal will be…
SlackTriggerWrapper
object
Schema for a Slack-based trigger.
2 properties
1 required
PermissionsResponse
object
Payload with API-returned permissions.
1 property
ObservabilityPipelineRsyslogDestinationType
string
The destination type. The value should always be rsyslog.
MonitorNotificationRuleFilter
Filter used to associate the notification rule with monitors.
Selectors
object
Selectors are used to filter security issues for which notifications should be generated. Users can specify rule severities, rule types, a query to filter secu…
4 properties
1 required
ErrorHandler
object
Used to handle errors in an action.
2 properties
2 required
ObservabilityPipelineParseGrokProcessorType
string
The processor type. The value should always be parsegrok.
TeamTarget
object
Represents a team target for an escalation policy step, including the team's ID and resource type.
2 properties
2 required
RUMResponseStatus
string
The status of the response.
ObservabilityPipelineAmazonOpenSearchDestinationType
string
The destination type. The value should always be amazonopensearch.
GetDeviceAttributes
object
The device attributes
19 properties
SecurityMonitoringRuleCaseActionOptionsUserBehaviorName
string
Used with the case action of type 'userbehavior'. The value specified in this field is applied as a risk tag to all users affected by the rule.
RestrictionQueryAttributes
object
Attributes of the restriction query.
3 properties
ObservabilityPipelineGeneratedMetric
object
Defines a log-based custom metric, including its name, type, filter, value computation strategy, and optional grouping fields.
5 properties
4 required
HourlyUsageResponse
object
Hourly usage response.
2 properties
AWSRegionsIncludeAll
object
Include all regions. Defaults to true.
1 property
1 required
ObservabilityPipelineGoogleChronicleDestination
object
The googlechronicle destination sends logs to Google Chronicle.
7 properties
5 required
LogsArchiveStorageClassS3Type
string
The storage class where the archive will be stored.
MicrosoftTeamsTenantBasedHandleType
string
Specifies the tenant-based handle resource type.
LayerAttributesInterval
object
Defines how often the rotation repeats, using a combination of days and optional seconds.
2 properties
AWSRegions
AWS Regions to collect data from. Defaults to includeall.
ListTagsResponseDataAttributes
object
The definition of ListTagsResponseDataAttributes object.
1 property
AuditLogsResponseMetadata
object
The metadata associated with a request.
5 properties
ObservabilityPipelineKafkaSource
object
The kafka source ingests data from Apache Kafka topics.
7 properties
4 required
RUMResponseMetadata
object
The metadata associated with a request.
5 properties
ContainerGroupRelationshipsData
array
Links data.
CsmAgentData
object
Single Agent Data.
3 properties
ObservabilityPipelineSplunkTcpSource
object
The splunktcp source receives logs from a Splunk Universal Forwarder over TCP. TLS is supported for secure transmission.
3 properties
2 required
DowntimeMeta
object
Pagination metadata returned by the API.
1 property
ActionQueryMockedOutputsObject
object
The mocked outputs of the action query.
2 properties
1 required
TeamRoutingRulesDataType
string
Team routing rules resource type.
UserTeamPermissionType
string
User team permission type
EntityResponseIncludedRelatedEntityAttributes
object
Related entity attributes.
4 properties
LogsMetricResponseGroupBy
object
A group by rule.
2 properties
IncidentTeamResponseAttributes
object
The incident team's attributes from a response.
3 properties
IncidentTypeObject
object
Incident type response data.
3 properties
2 required
ActionQueryDebounceInMs
The minimum time in milliseconds that must pass before the query can be triggered again. This is useful for preventing accidental double-clicks from triggering…
MonitorDowntimeMatchResponseData
object
A downtime match.
3 properties
AuditLogsEventAttributes
object
JSON object containing all event attributes and their associated values.
5 properties
CsmHostsAndContainersCoverageAnalysisResponse
object
CSM Hosts and Containers Coverage Analysis response.
1 property
AppBuilderEvent
object
An event on a UI component that triggers a response or action in an app.
2 properties
ApplicationSecurityWafCustomRuleData
object
Object for a single WAF custom rule.
3 properties
TriggerSource
string
The type of security issues on which the rule applies. Notification rules based on security signals need to use the trigger source "securitysignals", while not…
LogsSort
string
Sort parameters when querying logs.
TeamType
string
Team type
SAMLAssertionAttributeAttributes
object
Key/Value pair of attributes used in SAML assertion attributes.
2 properties
EntityV3QueueDatadog
object
Datadog product integrations for the datastore entity.
3 properties
CSMAgentsMetadata
object
Metadata related to the paginated response.
3 properties
IncidentTypeResponse
object
Incident type response data.
1 property
1 required
ObservabilityPipelineSentinelOneDestination
object
The sentinelone destination sends logs to SentinelOne.
4 properties
4 required
SecurityMonitoringSignalsListResponseMetaPage
object
Paging attributes.
1 property
Case
object
A case
4 properties
3 required
UserInvitationResponseData
object
Object of a user invitation returned by the API.
4 properties
UsageTimeSeriesType
string
Type of usage data.
ScheduleDataType
string
Schedules resource type.
CsmCloudAccountsCoverageAnalysisResponse
object
CSM Cloud Accounts Coverage Analysis response.
1 property
ServiceDefinitionV2Opsgenie
object
Opsgenie integration for the service.
2 properties
1 required
LogsArchiveOrderDefinitionType
string
Type of the archive order definition.
DowntimeNotifyEndStates
array
States that will trigger a monitor notification when the notifyendtypes action occurs.
AwsOnDemandResponse
object
Response object that includes an AWS on demand task.
1 property
ObservabilityPipelineAmazonOpenSearchDestinationAuthStrategy
string
The authentication strategy to use.
CustomFrameworkType
string
The type of the resource. The value must be customframework.
MicrosoftSentinelDestination
object
The microsoftsentinel destination forwards logs to Microsoft Sentinel.
7 properties
7 required
CloudConfigurationRegoRule
object
Rule details.
2 properties
2 required
LogsListResponse
object
Response object with all logs matching the request and pagination information.
3 properties
CompletionConditionOperator
string
The definition of CompletionConditionOperator object.
MicrosoftTeamsWorkflowsWebhookHandleType
string
Specifies the Workflows webhook handle resource type.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExclude
object
Excludes specific fields from sensitive data scanning.
2 properties
2 required
CIAppResponseMetadataWithPagination
object
The metadata associated with a request.
5 properties
ListDevicesResponseMetadataPage
object
Pagination object.
1 property
ServiceDefinitionV2Pagerduty
string
PagerDuty service URL for the service.
IncidentTeamResponseData
object
Incident Team data from a response.
4 properties
Connection
object
The definition of Connection object.
2 properties
2 required
IncidentNonDatadogCreator
object
Incident's non Datadog creator.
2 properties
OpsgenieServicesResponse
object
Response with a list of Opsgenie services.
1 property
1 required
ScheduleUserAttributes
object
Provides basic user information for a schedule, including a name and email address.
3 properties
OnDemandConcurrencyCap
object
On-demand concurrency cap.
2 properties
ObservabilityPipelineDatadogLogsDestination
object
The datadoglogs destination forwards logs to Datadog Log Management.
3 properties
3 required
EntityV3DatadogEvents
array
Events associations.
SecurityFiltersResponse
object
All the available security filters objects.
2 properties
IncidentIntegrationMetadataResponse
object
Response with an incident integration metadata.
2 properties
1 required
Team
object
A team
4 properties
3 required
ObservabilityPipelineAddEnvVarsProcessor
object
The addenvvars processor adds environment variable values to log events.
5 properties
5 required
ObservabilityPipelineSensitiveDataScannerProcessorPattern
Pattern detection configuration for identifying sensitive data using either a custom regex or a library reference.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedact
object
Configuration for completely redacting matched sensitive data.
2 properties
2 required
SBOMType
string
The JSON:API type.
PartialAPIKeyAttributes
object
Attributes of a partial API key.
6 properties
UserTeamIncluded
Included resources related to the team membership
MonitorType
object
Attributes from the monitor that triggered the event.
11 properties
ApplicationSecurityWafExclusionFilterRulesTarget
object
Target WAF rules based either on an identifier or tags.
2 properties
MonitorTriggerWrapper
object
Schema for a Monitor-based trigger.
2 properties
1 required
LogsMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
CloudWorkloadSecurityAgentRulesListResponse
object
Response object that includes a list of Agent rule
1 property
DowntimeScope
string
The scope to which the downtime applies. Must follow the [common search syntax](https://docs.datadoghq.com/logs/explorer/searchsyntax/).
AWSAccountPartition
string
AWS partition your AWS account is scoped to. Defaults to aws. See [Partitions](https://docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/pa…
EntityData
object
Entity data.
5 properties
HourlyUsagePagination
object
The metadata for the current pagination.
1 property
ServiceDefinitionV2MSTeamsType
string
Contact type.
ApplicationSecurityWafCustomRuleTagsCategory
string
The category of the WAF Rule, can be either businesslogic, attackattempt or securityresponse.
SBOMComponentType
string
The SBOM component type
IncidentTodoResponseIncludedItem
An object related to an incident todo that is included in the response.
ObservabilityPipelineSumoLogicSource
object
The sumologic source receives logs from Sumo Logic collectors.
2 properties
2 required
OutputSchemaParametersType
string
The definition of OutputSchemaParametersType object.
UsageTimeSeriesObject
object
Usage timeseries data.
2 properties
ObservabilityPipelineHttpClientSourceAuthStrategy
string
Optional authentication strategy for HTTP requests.
SecurityMonitoringSuppressionID
string
The ID of the suppression rule.
EntityV3APIVersion
string
The schema version of entity type. The field is known as schema-version in the previous version.
BillingDimensionsMappingBodyItemAttributes
object
Mapping of billing dimensions to endpoint keys.
3 properties
WorklflowGetInstanceResponse
object
The state of the given workflow instance.
1 property
ObservabilityPipelineOcsfMapperProcessorMapping
object
Defines how specific events are transformed to OCSF using a mapping configuration.
2 properties
2 required
MicrosoftSentinelDestinationType
string
The destination type. The value should always be microsoftsentinel.
ObservabilityPipelineQuotaProcessorLimit
object
The maximum amount of data or number of events allowed before the quota is enforced. Can be specified in bytes or events.
2 properties
2 required
ActionConnectionAttributes
object
The definition of ActionConnectionAttributes object.
2 properties
2 required
APIKeyResponseIncludedItem
An object related to an API key.
DataRelationshipsTeams
object
Associates teams with this schedule in a data structure.
1 property
ServiceDefinitionV2Dot1Integrations
object
Third party integrations that Datadog supports.
2 properties
OpsgenieServiceResponse
object
Response of an Opsgenie service.
1 property
1 required
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property
1 required
EventsResponseMetadataPage
object
Pagination attributes.
1 property
EntityToRelatedEntities
object
Entity to related entities relationship.
1 property
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties
2 required
AuditLogsEvent
object
Object description of an Audit Logs event after it is processed and stored by Datadog.
3 properties
ComponentProperties
object
Properties of a UI component. Different component types can have their own additional unique properties. See the [components documentation](https://docs.datado…
2 properties
EscalationPolicyUser
object
Represents a user object in the context of an escalation policy, including their id, type, and basic attributes.
3 properties
1 required
SecurityMonitoringRuleCaseActionType
string
The action type.
ObservabilityPipelineSampleProcessor
object
The sample processor allows probabilistic sampling of logs at a fixed rate.
6 properties
4 required
CIAppPipelineEventsResponse
object
Response object with all pipeline events matching the request and pagination information.
3 properties
ObservabilityPipelineData
object
Contains the pipeline’s ID, type, and configuration attributes.
3 properties
3 required
MetricsListResponseLinks
object
Pagination links. Only present if pagination query parameters were provided.
5 properties
ServiceDefinitionV2Dot1Version
string
Schema version being used.
CustomConnectionAttributes
object
The custom connection attributes.
2 properties
HTTPIntegration
object
The definition of HTTPIntegration object.
3 properties
3 required
AwsOnDemandListResponse
object
Response object that includes a list of AWS on demand tasks.
1 property
CsmServerlessCoverageAnalysisAttributes
object
CSM Serverless Resources Coverage Analysis attributes.
3 properties
AnnotationDisplay
object
The definition of AnnotationDisplay object.
1 property
AWSCredentials
The definition of AWSCredentials object.
RuleVersionHistory
object
Response object containing the version history of a rule.
2 properties
LogsMetricsResponse
object
All the available log-based metric objects.
1 property
RUMEvent
object
Object description of a RUM event after being processed and stored by Datadog.
3 properties
ObservabilityPipelineDedupeProcessor
object
The dedupe processor removes duplicate fields in log events.
6 properties
6 required
DowntimeMuteFirstRecoveryNotification
boolean
If the first recovery notification during a downtime should be muted.
MSTeamsIntegrationMetadata
object
Incident integration metadata for the Microsoft Teams integration.
1 property
1 required
DowntimeMonitorIdentifier
Monitor identifier for the downtime.
LogsArchiveDestinationAzureType
string
Type of the Azure archive destination.
RuleVersions
object
A rule version with a list of updates.
2 properties
RuleTypes
array
Security rule types used as filters in security rules.
LogsArchiveIntegrationS3
object
The S3 Archive's integration destination.
2 properties
2 required
CalculatedField
object
Calculated field.
2 properties
2 required
CloudWorkloadSecurityAgentRuleCreatorAttributes
object
The attributes of the user who created the Agent rule
2 properties
ContainerImageAttributes
object
Attributes for a Container Image.
17 properties
ObservabilityPipelineGeneratedMetricIncrementByOne
object
Strategy that increments a generated metric by one for each matching event.
1 property
1 required
SecurityMonitoringSignalRuleResponseQuery
object
Query for matching rule on signals.
9 properties
ProcessSummariesResponse
object
List of process summaries.
2 properties
EntityV3APIKind
string
The definition of Entity V3 API Kind object.
ObservabilityPipelineEnrichmentTableFileEncoding
object
File encoding format.
3 properties
3 required
UserResponse
object
Response containing information about a single user.
2 properties
EntityV3APIDatadog
object
Datadog product integrations for the API entity.
5 properties
EscalationPolicyDataRelationships
object
Represents the relationships for an escalation policy, including references to steps and teams.
2 properties
1 required
BillingDimensionsMappingResponse
object
Billing dimensions mapping response.
1 property
TeamOnCallRespondersDataRelationshipsRespondersDataItemsType
string
Identifies the resource type for individual user entities associated with on-call response.
ExternalUserNameType
object
The components of user's real name
1 property
RetentionFilterResponse
object
The retention filters definition.
1 property
HistoricalJobResponseData
object
Historical job response data.
3 properties
DowntimeMonitorIncludedItem
object
Information about the monitor identified by the downtime.
3 properties
Shift
object
The definition of Shift object.
2 properties
ContainerGroupAttributes
object
Attributes for a container group.
2 properties
DowntimeMonitorIdentifierTags
object
Object of the monitor tags.
1 property
1 required
NullableUserRelationshipData
object
Relationship to user object.
2 properties
2 required
TeamOnCallRespondersData
object
Defines the main on-call responder object for a team, including relationships and metadata.
3 properties
1 required
SpansMetricsResponse
object
All the available span-based metric objects.
1 property
SBOMAttributes
object
The JSON:API attributes of the SBOM.
6 properties
6 required
AWSIntegrationType
string
The definition of AWSIntegrationType object.
SlackIntegrationMetadataChannelItem
object
Item in the Slack integration metadata channel array.
4 properties
3 required
EntityV3DatadogCodeLocationItem
object
Code location item.
2 properties
Metric
object
Object for a single metric tag configuration.
2 properties
ComponentPropertiesIsVisible
Whether the UI component is visible. If this is a string, it must be a valid JavaScript expression that evaluates to a boolean.
ServiceDefinitionV1Info
object
Basic information about a service.
4 properties
1 required
GetTeamMembershipsSort
string
Specifies the order of returned team memberships
CIAppEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
IncidentAttachmentAttachmentType
string
The type of the incident attachment attributes.
SecurityFilter
object
The security filter's properties.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactOptions
object
Configuration for fully redacting sensitive data.
1 property
1 required
WorkflowUserRelationship
object
The definition of WorkflowUserRelationship object.
1 property
RoutingRuleRelationshipsPolicy
object
Defines the relationship that links a routing rule to a policy.
1 property
DashboardListItems
object
Dashboards within a list.
2 properties
1 required
IncidentTypeType
string
Incident type resource type.
ServiceDefinitionV2MSTeams
object
Service owner's Microsoft Teams.
3 properties
2 required
EscalationPolicyDataRelationshipsSteps
object
Defines the relationship to a collection of steps within an escalation policy. Contains an array of step data references.
1 property
Spec
object
The spec defines what the workflow does.
7 properties
AWSAuthConfigRole
object
AWS Authentication config to integrate your account using an IAM role.
2 properties
1 required
SecurityMonitoringRuleTypeRead
string
The rule type.
MonitorNotificationRuleRelationships
object
All relationships associated with monitor notification rule.
1 property
CloudWorkloadSecurityAgentRuleActionSet
object
The set action applied on the scope matching the rule
7 properties
SendTeamsMessageActionType
string
Indicates that the action is a send Microsoft Teams message action.
ObservabilityPipelineHttpServerSourceAuthStrategy
string
HTTP authentication method.
ObservabilityPipelineFluentdSource
object
The fluentd source ingests logs from a Fluentd-compatible service.
3 properties
2 required
SecurityMonitoringRuleMaxSignalDuration
integer
A signal will "close" regardless of the query being matched once the time exceeds the maximum duration. This time is calculated from the first seen timestamp.
StateVariableType
string
The state variable type.
ObservabilityPipelineFluentBitSource
object
The fluentbit source ingests logs from Fluent Bit.
3 properties
2 required
IncidentIntegrationRelationships
object
The incident's integration relationships from a response.
2 properties
SLOReportStatusGetResponseAttributes
object
The attributes portion of the SLO report status response.
1 property
ServiceDefinitionV2Dot1LinkType
string
Link type.
InterfaceAttributesStatus
string
The interface status
MetricCustomAggregation
object
A time and space aggregation combination for use in query.
2 properties
2 required
ListTagsResponseData
object
The list tags response data.
3 properties
ScheduleDataAttributes
object
Provides core properties of a schedule object such as its name and time zone.
2 properties
SecurityMonitoringRuleResponse
Create a new rule.
AppTriggerWrapper
object
Schema for an App-based trigger.
2 properties
1 required
MonitorConfigPolicyTagPolicy
object
Tag attributes of a monitor configuration policy.
3 properties
IncidentAttachmentType
string
The incident attachment resource type.
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
CIAppTestEvent
object
Object description of test event after being processed and stored by Datadog.
3 properties
ContainerImageGroupType
string
Type of Container Image Group.
MonthlyCostAttributionResponse
object
Response containing the monthly cost attribution by tag(s).
2 properties
ListApplicationKeysResponse
object
Response for a list of application keys.
3 properties
BudgetAttributes
object
The attributes of a budget.
11 properties
FullApplicationKey
object
Datadog application key.
4 properties
WorkflowTriggerWrapper
object
Schema for a Workflow-based trigger.
2 properties
1 required
LayerAttributes
object
Describes key properties of a Layer, including rotation details, name, start/end times, and any restrictions.
6 properties
EscalationRelationships
object
Contains the relationships of an escalation object, including its responders.
1 property
ObservabilityPipelineKafkaSourceSasl
object
Specifies the SASL mechanism for authenticating with a Kafka cluster.
1 property
ObservabilityPipelineSplunkHecDestination
object
The splunkhec destination forwards logs to Splunk using the HTTP Event Collector (HEC).
7 properties
3 required
StepDisplay
object
The definition of StepDisplay object.
1 property
RelationshipToUserData
object
Relationship to user object.
2 properties
2 required
SecurityMonitoringStandardDataSource
string
Source of events, either logs, audit trail, or Datadog events.
ServiceDefinitionV1Version
string
Schema version being used.
DataRelationshipsTeamsDataItemsType
string
Teams resource type.
Query
A data query used by an app. This can take the form of an external action, a data transformation, or a state variable.
ListDevicesResponse
object
List devices response.
2 properties
ActionQuerySpec
The definition of the action query.
ConnectionEnvEnv
string
The definition of ConnectionEnvEnv object.
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties
2 required
AuditLogsWarning
object
Warning message indicating something that went wrong with the query.
3 properties
ContainerImageGroupImagesRelationshipsLink
object
Relationships to Container Images inside a Container Image Group.
2 properties
FindingTags
array
The tags associated with this finding.
CIAppTestEventsResponse
object
Response object with all test events matching the request and pagination information.
3 properties
ListTeamsInclude
string
Included related resources optionally requested.
IncidentUserData
object
User object returned by the API.
3 properties
ObservabilityPipelineQuotaProcessorOverride
object
Defines a custom quota limit that applies to specific log events based on matching field values.
2 properties
2 required
AWSAssumeRoleType
string
The definition of AWSAssumeRoleType object.
AppBuilderEventName
string
The triggering action for the event.
EntityV3DatadogPerformance
object
Performance stats association.
1 property
SpansFilter
object
The spans filter used to index spans.
1 property
SecurityMonitoringSignalAttributes
object
The object containing all signal attributes and their associated values.
4 properties
TeamReferenceAttributes
object
Encapsulates the basic attributes of a Team reference, such as name, handle, and an optional avatar or description.
4 properties
CustomDestinationResponseHttpDestinationAuthCustomHeaderType
string
Type of the custom header access authentication.
MonitorNotificationRuleData
object
Monitor notification rule data.
4 properties
ApplicationKeysType
string
Application Keys resource type.
ObservabilityPipelineAmazonS3Source
object
The amazons3 source ingests logs from an Amazon S3 bucket. It supports AWS authentication and TLS encryption.
5 properties
3 required
RumMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when aggregationtype is distribution.
RelationshipToUserTeamPermissionData
object
Related user team permission data
2 properties
2 required
CloudflareAccountResponse
object
The expected response schema when getting a Cloudflare account.
1 property
ContainerMetaPageType
string
Type of Container pagination.
EntityResponseIncludedIncident
object
Included incident.
3 properties
ConfluentResourceResponseAttributes
object
Model representation of a Confluent Cloud resource.
4 properties
1 required
ObservabilityPipelineAmazonS3Destination
object
The amazons3 destination sends your logs in Datadog-rehydratable format to an Amazon S3 bucket for archiving.
9 properties
6 required
CIAppPipelineLevel
string
Pipeline execution level.
ServiceDefinitionV2Dot2Type
string
The type of service.
TimeAggregation
integer
Time aggregation period (in seconds) is used to aggregate the results of the notification rule evaluation. Results are aggregated over a selected time frame us…
AWSNamespaceFiltersExcludeOnly
object
Exclude only these namespaces from metrics collection. Defaults to ["AWS/SQS", "AWS/ElasticMapReduce"]. AWS/SQS and AWS/ElasticMapReduce are excluded by defaul…
1 property
1 required
ObservabilityPipelineFieldValue
object
Represents a static key-value pair used in various processors.
2 properties
2 required
CaseResponse
object
Case response
1 property
ObservabilityPipelineDataAttributes
object
Defines the pipeline’s name and its components (sources, processors, and destinations).
2 properties
2 required
Date
integer
Date as Unix timestamp in milliseconds.
ApplicationKeyResponseMeta
object
Additional information related to the application key response.
2 properties
EntityV3Service
object
Schema for service entities.
7 properties
3 required
ObservabilityPipelineDatadogAgentSourceType
string
The source type. The value should always be datadogagent.
EntityResponseIncludedSchemaType
string
Schema type.
SpansMetricResponseGroupBy
object
A group by rule.
2 properties
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
ObservabilityPipelineFluentBitSourceType
string
The source type. The value should always be fluentbit.
WorkflowDataType
string
The definition of WorkflowDataType object.
ContainerGroup
object
Container group object.
4 properties
LogsListResponseLinks
object
Links attributes.
1 property
ContainerType
string
Type of container.
OnDemandConcurrencyCapResponse
object
On-demand concurrency cap response.
1 property
ContainerImageMetaPageType
string
Type of Container Image pagination.
MonitorConfigPolicyResourceType
string
Monitor configuration policy resource type.
RelationshipToTeamLinkData
object
Relationship between a link and a team
2 properties
2 required
RumMetricResponse
object
The rum-based metric object.
1 property
DowntimeNotifyEndTypes
array
Actions that will trigger a monitor notification if the downtime is in the notifyendtypes state.
ActionQuerySpecInput
object
The inputs to the action query. See the [Actions Catalog](https://docs.datadoghq.com/actions/actionscatalog/) for more detail on each action and its inputs.
OrderDirection
string
The sort direction for results.
IncidentIntegrationMetadataListResponse
object
Response with a list of incident integration metadata.
3 properties
1 required
AuditLogsResponseStatus
string
The status of the response.
RUMApplication
object
RUM application.
3 properties
3 required
ServiceDefinitionV1ResourceType
string
Link type.
MonthlyCostAttributionPagination
object
The metadata for the current pagination.
1 property
DowntimeResourceType
string
Downtime resource type.
CaseStatus
string
Case status
TeamLinkType
string
Team link type
DowntimeMonitorIdentifierId
object
Object of the monitor identifier.
1 property
1 required
ServiceDefinitionV2Dot2Contact
object
Service owner's contacts information.
3 properties
2 required
MicrosoftTeamsChannelInfoResponseAttributes
object
Channel attributes.
3 properties
BudgetEntry
object
The entry of a budget.
3 properties
AuthNMappingTeamAttributes
object
Team attributes.
7 properties
MicrosoftTeamsWorkflowsWebhookHandleResponse
object
Response of a Workflows webhook handle.
1 property
1 required
FastlyServiceData
object
Data object for Fastly service requests.
3 properties
2 required
ConfluentAccountResponseAttributes
object
The attributes of a Confluent account.
3 properties
1 required
EntityV3ServiceKind
string
The definition of Entity V3 Service Kind object.
ObservabilityPipelineSensitiveDataScannerProcessorScopeAll
object
Applies scanning across all available fields.
1 property
1 required
RestrictionQueryListResponse
object
Response containing information about multiple restriction queries.
1 property
RUMEventsResponse
object
Response object with all events matching the request and pagination information.
3 properties
CsmAgentsResponse
object
Response object that includes a list of CSM Agents.
2 properties
DowntimeStatus
string
The current status of the downtime.
CloudWorkloadSecurityAgentRuleType
string
The type of the resource, must always be agentrule
EntityV3DatadogIntegrationPagerduty
object
A PagerDuty integration schema.
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeOptions
object
Fields to which the scope rule applies.
1 property
1 required
ContainersResponseLinks
object
Pagination links.
5 properties
SpansType
string
Type of the span.
IncidentRelatedObject
string
Object related to an incident.
GetWorkflowResponse
object
The response object after getting a workflow.
1 property
SecurityMonitoringSignalListRequestFilter
object
Search filters for listing security signals.
3 properties
AWSMetricsConfig
object
AWS Metrics Collection config.
6 properties
ObservabilityPipelineSplunkHecDestinationEncoding
string
Encoding format for log events.
DowntimeRelationshipsMonitorData
object
Data for the monitor.
2 properties
FastlyServiceResponse
object
The expected response schema when getting a Fastly service.
1 property
FindingMute
object
Information about the mute status of this finding.
6 properties
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property
1 required
DataTransform
object
A data transformer, which is custom JavaScript code that executes and transforms data when its inputs change.
4 properties
4 required
RestrictionQueryWithRelationshipsResponse
object
Response containing information about a single restriction query.
2 properties
MonitorConfigPolicyListResponse
object
Response for retrieving all monitor configuration policies.
1 property
UserResponseIncludedItem
An object related to a user.
AuditLogsEventType
string
Type of the event.
LayerType
string
Layers resource type.
RuleVersionUpdate
object
A change in a rule version.
3 properties
MicrosoftTeamsTenantBasedHandleInfoResponseAttributes
object
Tenant-based handle attributes.
7 properties
ObservabilityPipelineRsyslogSourceType
string
The source type. The value should always be rsyslog.
ObservabilityPipelineOcsfMappingLibrary
string
Predefined library mappings for common log formats.
TeamsResponseMeta
object
Teams response metadata.
1 property
RuleSeverity
string
Severity of a security rule.
CIAppPipelineEventTypeName
string
Type of the event.
SingleAggregatedConnectionResponseData
object
Object describing an aggregated connection.
3 properties
CIAppWarning
object
A warning message indicating something that went wrong with the query.
3 properties
ActionQueryOnlyTriggerManually
Determines when this query is executed. If set to false, the query will run when the app loads and whenever any query arguments change. If set to true, the que…
RoutingRuleAttributes
object
Defines the configurable attributes of a routing rule, such as actions, query, time restriction, and urgency.
4 properties
SpansWarning
object
A warning message indicating something that went wrong with the query.
3 properties
EscalationPolicyUserAttributes
object
Provides basic user information for an escalation policy, including a name and email address.
3 properties
MicrosoftTeamsTenantBasedHandleResponse
object
Response of a tenant-based handle.
1 property
1 required
DowntimeMessage
string
A message to include with notifications for this downtime. Email notifications can be sent to specific users by using the same @username notation as events.
CostByOrgResponse
object
Chargeback Summary response.
1 property
ActionConnectionDataType
string
The definition of ActionConnectionDataType object.
HistoricalJobQuery
object
Query for selecting logs analyzed by the historical job.
8 properties
EscalationPolicyIncluded
Represents included related resources when retrieving an escalation policy, such as teams, steps, or targets.
CostAttributionAggregates
array
An array of available aggregates.
ServiceDefinitionV2Version
string
Schema version being used.
DORAListDeploymentsRequestAttributes
object
Attributes to get a list of deployments.
5 properties
FullCustomFrameworkDataAttributes
object
Full Framework Data Attributes.
5 properties
4 required
OnDemandConcurrencyCapType
string
On-demand concurrency cap type.
SecurityTriggerWrapper
object
Schema for a Security-based trigger.
2 properties
1 required
CloudWorkloadSecurityAgentPoliciesListResponse
object
Response object that includes a list of Agent policies
1 property
CloudflareAccountResponseData
object
Data object of a Cloudflare account.
3 properties
3 required
ScheduleDataRelationships
object
Groups the relationships for a schedule object, referencing layers and teams.
2 properties
RestrictionQueryWithRelationships
object
Restriction query object returned by the API.
4 properties
IPAllowlistResponse
object
Response containing information about the IP allowlist.
1 property
NotificationRuleResponse
object
Response object which includes a notification rule.
1 property
ServiceDefinitionsListResponse
object
Create service definitions response.
1 property
TeamPermissionSettingValue
string
What type of user is allowed to perform the specified action
EntityResponseIncludedRelatedIncidentAttributes
object
Incident attributes.
5 properties
RumRetentionFilterResponse
object
The RUM retention filter object.
1 property
LogsRestrictionQueriesType
string
Restriction query resource type.
EntityAttributes
object
Entity attributes.
8 properties
LogsResponseMetadata
object
The metadata associated with a request
5 properties
RelationResponseMeta
object
Relation response metadata.
2 properties
FindingEvaluationChangedAt
integer
The date on which the evaluation for this finding changed (Unix ms).
ServiceDefinitionV2Dot1MSTeamsType
string
Contact type.
Event
object
The metadata associated with a request.
4 properties
APIErrorResponse
object
API error response.
1 property
1 required
ObservabilityPipelineAmazonOpenSearchDestination
object
The amazonopensearch destination writes logs to Amazon OpenSearch.
5 properties
4 required
LogsMetricID
string
The name of the log-based metric.
EventResponse
object
The object description of an event after being processed and stored by Datadog.
3 properties
ActionQueryRequiresConfirmation
Whether to prompt the user to confirm this query before it runs.
ObservabilityPipelineEnrichmentTableGeoIp
object
Uses a GeoIP database to enrich logs based on an IP field.
3 properties
3 required
LayerRelationshipsMembersDataItemsType
string
Members resource type.
RunRetentionFilterName
string
The name of a RUM retention filter.
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties
1 required
MicrosoftTeamsChannelInfoType
string
Channel info resource type.
GetAppResponseData
object
The data object containing the app definition.
3 properties
3 required
SecurityMonitoringSuppressionsResponse
object
Response object containing the available suppression rules.
1 property
BudgetWithEntries
object
The definition of the BudgetWithEntries object.
1 property
EntityV3MetadataAdditionalOwnersItems
object
The definition of Entity V3 Metadata Additional Owners Items object.
2 properties
1 required
ContainerImageVulnerabilities
object
Vulnerability counts associated with the Container Image.
7 properties
ApplicationSecurityWafCustomRuleActionParameters
object
The definition of ApplicationSecurityWafCustomRuleActionParameters object.
2 properties
ServiceDefinitionV2Dot1MSTeams
object
Service owner's Microsoft Teams.
3 properties
2 required
ContainerGroupType
string
Type of container group.
RelationshipToSAMLAssertionAttribute
object
AuthN Mapping relationship to SAML Assertion Attribute.
1 property
1 required
AuditLogsSort
string
Sort parameters when querying events.
SpansAttributes
object
JSON object containing all span attributes and their associated values.
17 properties
AWSNamespaceFilters
AWS Metrics namespace filters. Defaults to excludeonly.
EventsResponseMetadata
object
The metadata associated with a request.
5 properties
ReadinessGate
object
Used to merge multiple branches into a single branch.
1 property
1 required
EntityV3DatadogPipelines
object
CI Pipelines association.
1 property
EntityV3System
object
Schema for system entities.
7 properties
3 required
EscalationPolicyData
object
Represents the data for a single escalation policy, including its attributes, ID, relationships, and resource type.
4 properties
1 required
EntityV3MetadataLinksItems
object
The definition of Entity V3 Metadata Links Items object.
4 properties
3 required
RelationshipToOrganizations
object
Relationship to organizations.
1 property
1 required
UserTeamUserType
string
User team user type
LeakedKeyType
string
The definition of LeakedKeyType object.
WorkflowData
object
Data related to the workflow.
4 properties
2 required
SecurityFilterType
string
The type of the resource. The value should always be securityfilters.
WorkflowUserRelationshipData
object
The definition of WorkflowUserRelationshipData object.
2 properties
2 required
NullableRelationshipToUser
object
Relationship to user.
1 property
1 required
IncidentTriggerWrapper
object
Schema for an Incident-based trigger.
2 properties
1 required
DORAListFailuresRequestData
object
The JSON:API data.
2 properties
1 required
SecurityMonitoringRuleNewValueOptions
object
Options on new value detection method.
4 properties
EventsListResponseLinks
object
Links attributes.
1 property
DowntimeScheduleOneTimeResponse
object
A one-time downtime definition.
2 properties
1 required
ServiceDefinitionV1
object
Deprecated - Service definition V1 for providing additional service metadata and integrations.
8 properties
2 required
HTTPToken
object
The definition of HTTPToken object.
3 properties
3 required
ObservabilityPipelineSumoLogicDestinationEncoding
string
The output encoding format.
AWSAccountConfigID
string
Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/ap…
FastlyServiceAttributes
object
Attributes object for Fastly service requests.
1 property
ExternalUserGroupMeta
object
Metadata associated with a group.
4 properties
Project
object
A Project
4 properties
3 required
DataTransformType
string
The data transform type.
ExternalUserGroupMembersItems
object
The definition of a member belonging to a group.
4 properties
IPAllowlistEntryAttributes
object
Attributes of the IP allowlist entry.
4 properties
IncidentAttachmentRelatedObject
string
The object related to an incident attachment.
JSONAPIErrorItem
object
API error response body
5 properties
CustomDestinationResponseHttpDestinationAuthCustomHeader
object
Custom header access authentication.
2 properties
2 required
DowntimeScheduleResponse
The schedule that defines when the monitor starts, stops, and recurs. There are two types of schedules: one-time and recurring. Recurring schedules may have up…
MetricCustomAggregations
array
Deprecated. You no longer need to configure specific time and space aggregations for Metrics Without Limits.
LeakedKeyAttributes
object
The definition of LeakedKeyAttributes object.
2 properties
1 required
EventResponseAttributes
object
The object description of an event response attribute.
4 properties
AuthNMappingResponse
object
AuthN Mapping response from the API.
2 properties
FullCustomFrameworkData
object
Contains type and attributes for custom frameworks.
3 properties
3 required
ProjectedCostType
string
Type of cost data.
SecurityMonitoringStandardRuleQuery
object
Query for matching rule.
9 properties
DowntimeIncludedMonitorType
string
Monitor resource type.
ScheduleMemberRelationshipsUser
object
Wraps the user data reference for a schedule member.
1 property
1 required
SecurityMonitoringSignalListRequestPage
object
The paging attributes for listing security signals.
2 properties
MetricCustomSpaceAggregation
string
A space aggregation for use in query.
CustomCostsFileMetadataWithContent
object
Schema of a cost file's metadata.
9 properties
DowntimeDisplayTimezone
string
The timezone in which to display the downtime's start and end times in Datadog applications. This is not used as an offset for scheduling.
EntityV3MetadataContactsItems
object
The definition of Entity V3 Metadata Contacts Items object.
3 properties
2 required
ObservabilityPipelineElasticsearchDestination
object
The elasticsearch destination writes logs to an Elasticsearch cluster.
5 properties
3 required
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternType
string
Indicates a custom regular expression is used for matching.
ObservabilityPipelineGcpAuth
object
GCP credentials used to authenticate with Google Cloud Storage.
1 property
1 required
ShiftDataType
string
Indicates that the resource is of type 'shifts'.
ObservabilityPipelineRenameFieldsProcessor
object
The renamefields processor changes field names.
5 properties
5 required
IncidentTeamIncludedItems
An object related to an incident team which is present in the included payload.
ProjectResponse
object
Project response
1 property
TimeRestrictions
object
Holds time zone information and a list of time restrictions for a routing rule.
2 properties
2 required
HistoricalJobResponseAttributes
object
Historical job attributes.
8 properties
ObservabilityPipelineThrottleProcessorType
string
The processor type. The value should always be throttle.
GetFindingResponse
object
The expected response schema when getting a finding.
1 property
1 required
ObservabilityPipelineSampleProcessorType
string
The processor type. The value should always be sample.
ObservabilityPipelineEnrichmentTableProcessorType
string
The processor type. The value should always be enrichmenttable.
SecurityMonitoringRuleSeverity
string
Severity of the Security Signal.
RelationshipArray
array
Relationships.
ObservabilityPipelineSyslogSourceMode
string
Protocol used by the syslog source to receive messages.
OpsgenieServiceResponseAttributes
object
The attributes from an Opsgenie service response.
3 properties
MicrosoftTeamsTenantBasedHandlesResponse
object
Response with a list of tenant-based handles.
1 property
1 required
ObservabilityPipelineSplunkHecDestinationType
string
The destination type. Always splunkhec.
AwsScanOptionsAttributes
object
Attributes for the AWS scan options.
4 properties
RumRetentionFilterQuery
string
The query string for a RUM retention filter.
ServiceDefinitionV2Dot1Email
object
Service owner's email.
3 properties
2 required
SecurityMonitoringSignalsListResponseLinks
object
Links attributes.
1 property
RelationToEntity
object
Relation to entity.
2 properties
RoleResponseRelationships
object
Relationships of the role object returned by the API.
1 property
EntityV3ServiceSpec
object
The definition of Entity V3 Service Spec object.
6 properties
InputSchemaParameters
object
The definition of InputSchemaParameters object.
5 properties
2 required
ObservabilityPipelineAddEnvVarsProcessorVariable
object
Defines a mapping between an environment variable and a log field.
2 properties
2 required
MonitorNotificationRuleListResponse
object
Response for retrieving all monitor notification rules.
2 properties
IncidentRespondersType
string
The incident responders type.
SecurityFilterExclusionFilterResponse
object
A single exclusion filter.
2 properties
UsageObservabilityPipelinesResponse
object
Observability Pipelines usage response.
1 property
EntityV3Queue
object
Schema for queue entities.
7 properties
3 required
ApmRetentionFilterType
string
The type of the resource.
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties
2 required
ObservabilityPipelineQuotaProcessorType
string
The processor type. The value should always be quota.
JiraIssue
object
Jira issue attached to case
2 properties
ApplicationSecurityWafExclusionFilterType
string
Type of the resource. The value should always be exclusionfilter.
ObservabilityPipelineReduceProcessorType
string
The processor type. The value should always be reduce.
DowntimeRelationshipsMonitor
object
The monitor identified by the downtime.
1 property
APIKeysResponseMetaPage
object
Additional information related to the API keys response.
1 property
EscalationPolicyDataAttributes
object
Defines the main attributes of an escalation policy, such as its name and behavior on policy end.
3 properties
1 required
ProcessSummary
object
Process summary object.
3 properties
ObservabilityPipelineTls
object
Configuration for enabling TLS encryption between the pipeline component and external services.
3 properties
1 required
EntityRelationships
object
Entity relationships.
5 properties
ServiceDefinitionV2Dot1Contact
Service owner's contacts information.
FindingResource
string
The resource name of this finding.
LogsArchiveDestinationS3
object
The S3 archive destination.
6 properties
3 required
ObservabilityPipelineEnrichmentTableFileSchemaItemsType
string
Declares allowed data types for enrichment table columns.
ObservabilityPipelineRenameFieldsProcessorField
object
Defines how to rename a field in log events.
3 properties
3 required
MetricTagConfiguration
object
Object for a single metric tag configuration.
3 properties
GetAppResponse
object
The full app definition response object.
4 properties
IncidentServiceResponse
object
Response with an incident service payload.
2 properties
1 required
SecurityMonitoringRuleNewValueOptionsLearningMethod
string
The learning method used to determine when signals should be generated for values that weren't learned.
ServiceDefinitionV2Dot2Link
object
Service's external links.
4 properties
3 required
Pagination
object
Pagination object.
2 properties
SLOReportStatus
string
The status of the SLO report job.
LogsArchiveOrder
object
A ordered list of archive IDs.
1 property
AssetType
string
The asset type
ObservabilityPipelineOcsfMapperProcessor
object
The ocsfmapper processor transforms logs into the OCSF schema using a predefined mapping configuration.
5 properties
5 required
RumRetentionFilterData
object
The RUM retention filter.
3 properties
EntityResponseIncludedRawSchemaAttributes
object
Included raw schema attributes.
1 property
ChargebackBreakdown
object
Charges breakdown.
3 properties
RelationshipToPermissions
object
Relationship to multiple permissions objects.
1 property
IncidentTeamRelationships
object
The incident team's relationships.
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationStorageClass
string
Storage class used for objects stored in GCS.
IncidentTodoListResponse
object
Response with a list of incident todos.
3 properties
1 required
PowerpackRelationships
object
Powerpack relationship object.
1 property
ObservabilityPipelineRemoveFieldsProcessorType
string
The processor type. The value should always be removefields.
LogsArchiveDestination
object
An archive's destination.
CasePriority
string
Case priority
ActionQueryShowToastOnError
Whether to display a toast to the user when the query returns an error.
EntityV3DatadogEventItem
object
Events association item.
2 properties
EventsListResponse
object
The response object with all events matching the request and pagination information.
3 properties
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
RumMetricType
string
The type of the resource. The value should always be rummetrics.
PartialApplicationKeyResponse
object
Response for retrieving a partial application key.
2 properties
SecurityMonitoringRuleThirdPartyOptions
object
Options on third party detection method.
4 properties
RestrictionPolicyAttributes
object
Restriction policy attributes.
1 property
1 required
CaseAttributes
object
Case attributes
12 properties
RumMetricComputeAggregationType
string
The type of aggregation to use.
EntityV3ServiceDatadog
object
Datadog product integrations for the service entity.
5 properties
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties
2 required
ApplicationSecurityWafCustomRuleConditionOperator
string
Operator to use for the WAF Condition.
TeamRoutingRulesData
object
Represents the top-level data object for team routing rules, containing the ID, relationships, and resource type.
3 properties
1 required
ScheduleMemberRelationships
object
Defines relationships for a schedule member, primarily referencing a single user.
1 property
AwsOnDemandType
string
The type of the on demand task. The value should always be awsresource.
ListEntityCatalogResponseIncludedItem
List entity response included item.
CustomDestinationResponseHttpDestinationAuth
Authentication method of the HTTP requests.
FastlyService
object
The schema representation of a Fastly service.
2 properties
1 required
OrgConfigType
string
Data type of an Org Config.
ServiceDefinitionMeta
object
Metadata about a service definition.
7 properties
ContainerImageGroup
object
Container Image Group object.
4 properties
SecurityMonitoringUser
object
A user.
2 properties
RelationshipToRole
object
Relationship to role.
1 property
EscalationPolicyDataRelationshipsStepsDataItemsType
string
Indicates that the resource is of type steps.
SecurityMonitoringSignalsListResponseMeta
object
Meta attributes.
1 property
OktaAccount
object
Schema for an Okta account.
3 properties
2 required
MetricTagConfigurationAttributes
object
Object containing the definition of a metric tag configuration attributes.
7 properties
ApplicationKeyResponse
object
Response for retrieving an application key.
2 properties
UserTeamType
string
Team membership type
ScheduleTarget
object
Represents a schedule target for an escalation policy step, including its ID and resource type.
2 properties
2 required
LogsArchiveOrderDefinition
object
The definition of an archive order.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeExcludeTarget
string
Excludes specific fields from processing.
ServiceDefinitionV2Email
object
Service owner's email.
3 properties
2 required
SecurityMonitoringSignal
object
Object description of a security signal.
3 properties
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
EscalationTargets
object
A list of escalation targets for a step
1 property
RumRetentionFiltersResponse
object
All RUM retention filters for a RUM application.
1 property
DowntimeMonitorIncludedAttributes
object
Attributes of the monitor identified by the downtime.
1 property
ListPowerpacksResponse
object
Response object which includes all powerpack configurations.
4 properties
AuthNMappingTeam
object
Team.
3 properties
ProcessSummaryAttributes
object
Attributes for a process summary.
8 properties
WorkflowDataRelationships
object
The definition of WorkflowDataRelationships object.
2 properties
ApplicationSecurityWafCustomRuleMetadata
object
Metadata associated with the WAF Custom Rule.
6 properties
SecurityMonitoringSignalsListResponse
object
The response object with all security signals matching the request and pagination information.
3 properties
UserResponseRelationships
object
Relationships of the user object returned by the API.
4 properties
PowerpackResponseLinks
object
Links attributes.
5 properties
SpansListResponseLinks
object
Links attributes.
1 property
ConfluentResourceResponse
object
Response schema when interacting with a Confluent resource.
1 property
MonitorDowntimeMatchResourceType
string
Monitor Downtime Match resource type.
MonitorNotificationRuleFilterTags
object
Filter monitors by tags. Monitors must match all tags.
1 property
1 required
Parameter
object
The definition of Parameter object.
2 properties
2 required
ActionConnectionData
object
Data related to the connection.
3 properties
2 required
ObservabilityPipelineSyslogNgDestination
object
The syslogng destination forwards logs to an external syslog-ng server over TCP or UDP using the syslog protocol.
5 properties
3 required
ObservabilityPipelineEnrichmentTableFileKeyItems
object
Defines how to map log fields to enrichment table columns during lookups.
3 properties
3 required
EntityV3APISpecInterface
The API definition.
TeamsResponseMetaPagination
object
Teams response metadata.
8 properties
ContainerImageGroupRelationshipsData
array
Links data.
CustomDestinationResponseHttpDestinationAuthBasicType
string
Type of the basic access authentication.
ContainerImageGroupRelationships
object
Relationships inside a Container Image Group.
1 property
SecurityMonitoringRuleImpossibleTravelOptionsBaselineUserLocations
boolean
If true, signals are suppressed for the first 24 hours. In that time, Datadog learns the user's regular access locations. This can be helpful to reduce noise a…
ObservabilityPipelineDatadogAgentSource
object
The datadogagent source collects logs from the Datadog Agent.
3 properties
2 required
RelationshipToUsers
object
Relationship to users.
1 property
1 required
ActionConnectionIntegration
The definition of ActionConnectionIntegration object.
ChangeEventTriggerWrapper
object
Schema for a Change Event-based trigger.
2 properties
1 required
CloudWorkloadSecurityAgentRuleResponse
object
Response object that includes an Agent rule
1 property
AppMeta
object
Metadata of an app.
9 properties
PermissionsType
string
Permissions resource type.
ApplicationKeyResponseMetaPage
object
Additional information related to the application key response.
1 property
RelationshipItem
object
Relationship entry.
2 properties
ComponentGridType
string
The grid component type.
CustomFrameworkRequirement
object
Framework Requirement.
2 properties
2 required
Escalation
object
Represents an escalation policy step.
3 properties
1 required
RUMWarning
object
A warning message indicating something that went wrong with the query.
3 properties
GetSBOMResponse
object
The expected response schema when getting an SBOM.
1 property
1 required
ShiftDataRelationshipsUser
object
Defines the relationship between a shift and the user who is working that shift.
1 property
1 required
IncidentServiceResponseData
object
Incident Service data from responses.
4 properties
2 required
GetRuleVersionHistoryResponse
object
Response for getting the rule version history.
1 property
APIKeysResponseMeta
object
Additional information related to api keys response.
2 properties
RoutingRule
object
Represents a routing rule, including its attributes, relationships, and unique identifier.
4 properties
1 required
StateVariable
object
A variable, which can be set and read by other components in the app.
4 properties
4 required
RestrictionQueryRole
object
Partial role object.
3 properties
SpansMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
AWSLogsConfig
object
AWS Logs Collection config.
1 property
RelationshipToSAMLAssertionAttributeData
object
Data of AuthN Mapping relationship to SAML Assertion Attribute.
2 properties
2 required
LogsMetricResponseAttributes
object
The object describing a Datadog log-based metric.
3 properties
GetCustomFrameworkResponse
object
Response object to get a custom framework.
1 property
1 required
DomainAllowlistType
string
Email domain allowlist allowlist type.
NotificationRuleAttributes
object
Attributes of the notification rule.
10 properties
9 required
EntityResponseIncludedRelatedOncallEscalations
array
Oncall escalations.
IPAllowlistType
string
IP allowlist type.
EscalationTarget
Represents an escalation target, which can be a team, user, or schedule.
MonthlyCostAttributionMeta
object
The object containing document metadata.
2 properties
SpansSort
string
Sort parameters when querying spans.
ApplicationSecurityWafCustomRuleCondition
object
One condition of the WAF Custom Rule.
2 properties
2 required
TeamOnCallRespondersDataRelationshipsRespondersDataItems
object
Represents a user responder associated with the on-call team.
2 properties
2 required
ObservabilityPipelineOpenSearchDestinationType
string
The destination type. The value should always be opensearch.
DashboardListItem
object
A dashboard within a list.
14 properties
2 required
AuthNMapping
object
The AuthN Mapping object returned by API.
4 properties
2 required
UsageLambdaTracedInvocationsResponse
object
Lambda Traced Invocations usage response.
1 property
CustomCostsUser
object
Metadata of the user that has uploaded the Custom Costs file.
3 properties
CustomConnection
object
A custom connection used by an app.
3 properties
CsmServerlessCoverageAnalysisData
object
CSM Serverless Resources Coverage Analysis data.
3 properties
AppDefinitionType
string
The app definition type.
CustomCostsFileUsageChargePeriod
object
Usage charge period of a Custom Costs file.
2 properties
IncidentTodoAssignee
A todo assignee.
IncidentTodoAssigneeArray
array
Array of todo assignees.
MicrosoftTeamsWorkflowsWebhookHandleResponseData
object
Workflows Webhook handle data from a response.
3 properties
SpansResponseMetadataPage
object
Paging attributes.
1 property
CustomDestinationResponseHttpDestinationAuthBasic
object
Basic access authentication.
1 property
1 required
DatabaseMonitoringTriggerWrapper
object
Schema for a Database Monitoring-based trigger.
2 properties
1 required
RUMApplicationResponse
object
RUM application response.
1 property
ActionQueryMockedOutputsEnabled
Whether to enable the mocked outputs for testing.
ObservabilityPipelineSumoLogicDestination
object
The sumologic destination forwards logs to Sumo Logic.
8 properties
3 required
EntityResponseIncludedSchemaAttributes
object
Included schema.
1 property
TeamOnCallRespondersDataRelationshipsEscalationsDataItemsType
string
Identifies the resource type for escalation policy steps linked to a team's on-call configuration.
TeamsField
string
Supported teams field.
MonitorNotificationRuleResponse
object
A monitor notification rule.
2 properties
CaseRelationships
object
Resources related to a case
4 properties
Schedule
object
Top-level container for a schedule object, including both the data payload and any related included resources (such as teams, layers, or members).
2 properties
EntityToIncidents
object
Entity to incidents relationship.
1 property
ObservabilityPipelineRemoveFieldsProcessor
object
The removefields processor deletes specified fields from logs.
5 properties
5 required
WorkflowDataAttributes
object
The definition of WorkflowDataAttributes object.
8 properties
2 required
DowntimeScheduleRecurrenceDuration
string
The length of the downtime. Must begin with an integer and end with one of 'm', 'h', d', or 'w'.
IncidentTeamsResponse
object
Response with a list of incident team payloads.
3 properties
1 required
AnnotationMarkdownTextAnnotation
object
The definition of AnnotationMarkdownTextAnnotation object.
1 property
BillingDimensionsMappingBody
array
Billing dimensions mapping data.
TeamOnCallResponders
object
Root object representing a team's on-call responder configuration.
2 properties
OutputSchemaParameters
object
The definition of OutputSchemaParameters object.
6 properties
2 required
RumMetricResponseGroupBy
object
A group by rule.
2 properties
EntityV3QueueSpec
object
The definition of Entity V3 Queue Spec object.
4 properties
UserTeamAttributes
object
Team membership attributes
3 properties
ServiceDefinitionV1Pagerduty
string
PagerDuty service URL for the service.
RoutingRuleAction
Defines an action that is executed when a routing rule matches certain criteria.
UserTeam
object
A user's relationship with a team
4 properties
2 required
ObservabilityPipelineAddFieldsProcessor
object
The addfields processor adds static key-value fields to logs.
5 properties
5 required
ObservabilityPipelineLogstashSource
object
The logstash source ingests logs from a Logstash forwarder.
3 properties
2 required
LogsAggregateResponseStatus
string
The status of the response
CIAppPipelineEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
CloudWorkloadSecurityAgentPolicyResponse
object
Response object that includes an Agent policy
1 property
CustomFrameworkControl
object
Framework Control.
2 properties
2 required
ScheduleUserType
string
Users resource type.
ObservabilityPipelineAddFieldsProcessorType
string
The processor type. The value should always be addfields.
TeamRoutingRulesDataRelationshipsRulesDataItems
object
Defines a relationship item to link a routing rule by its ID and type.
2 properties
2 required
SpansListResponseMetadata
object
The metadata associated with a request.
5 properties
AppRelationship
object
The app's publication relationship and custom connections.
2 properties
ServiceDefinitionV2Doc
object
Service documents.
3 properties
2 required
MicrosoftTeamsTenantBasedHandleResponseData
object
Tenant-based handle data from a response.
3 properties
DORAListFailuresRequest
object
Request to get a list of failures.
1 property
1 required
ObservabilityPipelineEnrichmentTableProcessor
object
The enrichmenttable processor enriches logs using a static CSV file or GeoIP database.
7 properties
5 required
SpansMetricID
string
The name of the span-based metric.
GetDeviceResponse
object
The GetDevice operation's response.
1 property
ServiceDefinitionV2Repo
object
Service code repositories.
3 properties
2 required
ServiceDefinitionV1Resource
object
Service's external links.
3 properties
3 required
IncidentImpactsType
string
The incident impacts type.
RelationshipToRoleData
object
Relationship to role object.
2 properties
PartialApplicationKeyAttributes
object
Attributes of a partial application key.
4 properties
EntityV3SystemDatadog
object
Datadog product integrations for the service entity.
4 properties
ConfluentAccountType
string
The JSON:API type for this API. Should always be confluent-cloud-accounts.
ExternalUser
object
Definition of a user.
8 properties
FastlyAccountType
string
The JSON:API type for this API. Should always be fastly-accounts.
ObservabilityPipelineAmazonOpenSearchDestinationAuth
object
Authentication settings for the Amazon OpenSearch destination. The strategy field determines whether basic or AWS-based authentication is used.
5 properties
1 required
SpansMetricResponseData
object
The span-based metric properties.
3 properties
EntityResponseIncludedRelatedEntityType
string
Related entity.
AWSTracesConfig
object
AWS Traces Collection config.
1 property
CloudWorkloadSecurityAgentPolicyUpdaterAttributes
object
The attributes of the user who last updated the policy
2 properties
MonitorDowntimeMatchResponse
object
Response for retrieving all downtime matches for a monitor.
2 properties
MetricPaginationMeta
object
Response metadata object.
1 property
AWSRegionsIncludeOnly
object
Include only these regions.
1 property
1 required
CIAppTestEventTypeName
string
Type of the event.
APIKeysResponse
object
Response for a list of API keys.
3 properties
EntityResponseIncludedIncidentType
string
Incident description.
CustomDestinationResponseForwardDestinationSplunk
object
The Splunk HTTP Event Collector (HEC) destination.
2 properties
2 required
TokenName
string
Name for tokens.
ID
string
The ID of a notification rule.
PowerpackResponse
object
Response object which includes a single powerpack configuration.
2 properties
LogsWarning
object
A warning message indicating something that went wrong with the query
3 properties
DowntimeResponse
object
Downtiming gives you greater control over monitor notifications by allowing you to globally exclude scopes from alerting. Downtime settings, which can be sched…
2 properties
RelationshipToUserTeamUserData
object
A user's relationship with a team
2 properties
2 required
ServiceDefinitionV2Dot1Opsgenie
object
Opsgenie integration for the service.
2 properties
1 required
ActionQueryProperties
object
The properties of the action query.
9 properties
1 required
AppDeploymentType
string
The deployment type.
SecurityMonitoringStandardRuleResponse
object
Rule.
24 properties
PowerpackInnerWidgets
object
Powerpack group widget definition of individual widgets.
2 properties
1 required
SecurityMonitoringRuleDetectionMethod
string
The detection method.
UserTargetType
string
Indicates that the resource is of type users.
ObservabilityPipelineQuotaProcessor
object
The Quota Processor measures logging traffic for logs that match a specified filter. When the configured daily quota is met, the processor can drop or alert.
11 properties
7 required
Annotation
object
A list of annotations used in the workflow. These are like sticky notes for your workflow!
3 properties
3 required
CostByOrgType
string
Type of cost data.
SecurityMonitoringRuleNewValueOptionsLearningThreshold
integer
A number of occurrences after which signals will be generated for values that weren't learned.
ComponentType
string
The UI component type.
EntityV3
Entity schema v3.
GithubWebhookTrigger
object
Trigger a workflow from a GitHub webhook. To trigger a workflow from GitHub, you must set a webhookSecret. In your GitHub Webhook Settings, set the Payload URL…
1 property
APIKeyResponse
object
Response for retrieving an API key.
2 properties
IncidentIntegrationMetadataType
string
Integration metadata resource type.
TeamLink
object
Team link
3 properties
3 required
DeploymentAttributes
object
The attributes object containing the version ID of the published app.
1 property
MicrosoftTeamsWorkflowsWebhookHandlesResponse
object
Response with a list of Workflows webhook handles.
1 property
1 required
FullAPIKey
object
Datadog API key.
4 properties
ObservabilityPipelineSensitiveDataScannerProcessorRule
object
Defines a rule for detecting sensitive data, including matching pattern, scope, and the action to take.
6 properties
5 required
DeploymentRelationship
object
Information pointing to the app's publication status.
2 properties
DowntimeScheduleRecurrenceRrule
string
The RRULE standard for defining recurring events. For example, to have a recurring event on the first day of each month, set the type to rrule and set the FREQ…
UserAttributesStatus
string
The user's status.
WidgetLiveSpan
string
The available timeframes depend on the widget you are using.
EscalationPolicyStepAttributesAssignment
string
Specifies how this escalation step will assign targets (example default or round-robin).
SecurityMonitoringRuleDecreaseCriticalityBasedOnEnv
boolean
If true, signals in non-production environments have a lower severity than what is defined by the rule case, which can reduce signal noise. The severity is dec…
JiraIntegrationMetadataIssuesItem
object
Item in the Jira integration metadata issue array.
5 properties
2 required
ApplicationSecurityWafCustomRuleConditionInputAddress
string
Input from the request on which the condition should apply.
EscalationPolicyUserType
string
Users resource type.
ContainerAttributes
object
Attributes for a container.
10 properties
RelationshipToUser
object
Relationship to user.
1 property
1 required
RelationshipToTeamData
object
Relationship to Team object.
2 properties
AWSAccountID
string
AWS Account ID.
DeviceAttributesInterfaceStatuses
object
Count of the device interfaces by status
4 properties
ObservabilityPipelineGeneratedMetricIncrementByFieldStrategy
string
Uses a numeric field in the log event as the metric increment.
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
AwsScanOptionsType
string
The type of the resource. The value should always be awsscanoptions.
ComponentGridProperties
object
Properties of a grid component.
3 properties
TriggerRateLimit
object
Defines a rate limit for a trigger.
2 properties
ShiftDataRelationships
object
The definition of ShiftDataRelationships object.
1 property
ObservabilityPipelineAmazonDataFirehoseSource
object
The amazondatafirehose source ingests logs from AWS Data Firehose.
4 properties
2 required
HistoricalJobOptions
object
Job options.
7 properties
ListDevicesResponseMetadata
object
Object describing meta attributes of response.
1 property
UsersResponse
object
Response containing information about multiple users.
3 properties
CIAppResponseStatus
string
The status of the response.
SpansMetricResponseCompute
object
The compute rule to compute the span-based metric.
3 properties
RoutingRuleRelationships
object
Specifies relationships for a routing rule, linking to associated policy resources.
1 property
RelationResponse
object
Relation response data.
6 properties
ObservabilityPipelineRsyslogDestination
object
The rsyslog destination forwards logs to an external rsyslog server over TCP or UDP using the syslog protocol.
5 properties
3 required
Targets
array
List of recipients to notify when a notification rule is triggered. Many different target types are supported, such as email addresses, Slack channels, and Pag…
CsmServerlessCoverageAnalysisResponse
object
CSM Serverless Resources Coverage Analysis response.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorActionHash
object
Configuration for hashing matched sensitive values.
2 properties
1 required
EntityResponseIncludedRelatedOncallAttributes
object
Included related oncall attributes.
2 properties
ServiceDefinitionV2Dot2Version
string
Schema version being used.
EscalationPolicy
object
Represents a complete escalation policy response, including policy data and optionally included related resources.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorKeywordOptions
object
Configuration for keywords used to reinforce sensitive data pattern detection.
2 properties
2 required
ObservabilityPipelineSumoLogicSourceType
string
The source type. The value should always be sumologic.
SpansMetricResponseFilter
object
The span-based metric filter. Spans matching this filter will be aggregated in this metric.
1 property
ProjectedCostResponse
object
Projected Cost response.
1 property
PowerpacksResponseMeta
object
Powerpack response metadata.
1 property
ApplicationSecurityWafCustomRuleConditionInput
object
Input from the request on which the condition should apply.
2 properties
1 required
FastlyAccounResponseAttributes
object
Attributes object of a Fastly account.
2 properties
1 required
SecurityMonitoringSignalResponse
object
Security Signal response data object.
1 property
ObservabilityPipelineSentinelOneDestinationType
string
The destination type. The value should always be sentinelone.
ApplicationSecurityWafCustomRuleScope
object
The scope of the WAF custom rule.
2 properties
2 required
SecurityMonitoringThirdPartyRuleCase
object
Case when signal is generated by a third party rule.
4 properties
ActionQuerySpecConnectionGroup
object
The connection group to use for an action query.
2 properties
MonitorNotificationRuleResponseIncludedItem
An object related to a monitor notification rule.
AWSAuthConfigKeys
object
AWS Authentication config to integrate your account using an access key pair.
2 properties
1 required
XRayServicesList
AWS X-Ray services to collect traces from. Defaults to includeonly.
OpsgenieServiceType
string
Opsgenie service resource type.
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
RoutingRuleRelationshipsPolicyDataType
string
Indicates that the resource is of type 'policies'.
RestrictionPolicyBinding
object
Specifies which principals are associated with a relation.
2 properties
2 required
APITriggerWrapper
object
Schema for an API-based trigger.
2 properties
1 required
ObservabilityPipelineSumoLogicDestinationHeaderCustomFieldsItem
object
Single key-value pair used as a custom log header for Sumo Logic.
2 properties
2 required
Log
object
Object description of a log after being processed and stored by Datadog.
3 properties
HTTPTokenAuthType
string
The definition of HTTPTokenAuthType object.
TeamOnCallRespondersIncluded
Represents an union of related resources included in the response, such as users and escalation steps.
DORAEvent
object
A DORA event.
3 properties
TeamRelationshipsLinks
object
Links attributes.
1 property
CustomDestinationsResponse
object
The available custom destinations.
1 property
AWSResourcesConfig
object
AWS Resources Collection config.
2 properties
AWSAccountResponseAttributes
object
AWS Account response attributes.
11 properties
1 required
DORAFetchResponse
object
Response for the DORA fetch endpoints.
1 property
CompletionGate
object
Used to create conditions before running subsequent actions.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeAllTarget
string
Applies the rule to all fields.
HourlyUsageMeasurement
object
Usage amount for a given usage type.
2 properties
ApplicationSecurityWafCustomRuleType
string
The type of the resource. The value should always be customrule.
LogsMetricResponseFilter
object
The log-based metric filter. Logs matching this filter will be aggregated in this metric.
1 property
RestrictionQueryWithoutRelationships
object
Restriction query object returned by the API.
3 properties
PowerpackTemplateVariable
object
Powerpack template variables.
4 properties
1 required
ObservabilityPipelineRsyslogSource
object
The rsyslog source listens for logs over TCP or UDP from an rsyslog server using the syslog protocol.
4 properties
3 required
APITrigger
object
Trigger a workflow from an API request. The workflow must be published.
1 property
IncidentAttachmentAttributes
The attributes object for an attachment.
DomainAllowlistResponseData
object
The email domain allowlist response for an org.
3 properties
1 required
AuthNMappingIncluded
Included data in the AuthN Mapping response.
ActiveBillingDimensionsResponse
object
Active billing dimensions response.
1 property
AwsOnDemandAttributes
object
Attributes for the AWS on demand task.
4 properties
DowntimeRelationshipsCreatedByData
object
Data for the user who created the downtime.
2 properties
RuleTypesItems
string
Security rule type which can be used in security rules. Signal-based notification rules can filter signals based on rule types applicationsecurity, logdetectio…
AWSLogsServicesResponseData
object
AWS Logs Services response body
3 properties
2 required
ServiceDefinitionSchema
Service definition schema.
ActionQuerySpecInputs
The inputs to the action query. These are the values that are passed to the action when it is triggered.
MonitorNotificationRuleId
string
The ID of the monitor notification rule.
IncidentTodoAnonymousAssigneeSource
string
The source of the anonymous assignee.
StepDisplayBounds
object
The definition of StepDisplayBounds object.
2 properties
MetricTagConfigurationType
string
The metric tag configuration resource type.
ApiID
string
API identifier.
ObservabilityPipelineEnrichmentTableFileKeyItemsComparison
string
Defines how to compare key fields for enrichment table lookups.
SecurityMonitoringSignalRuleResponse
object
Rule.
18 properties
FindingResourceType
string
The resource type of this finding.
EntityV3APISpecInterfaceDefinition
object
The definition of EntityV3APISpecInterfaceDefinition object.
1 property
ObservabilityPipelineParseGrokProcessorRuleMatchRule
object
Defines a Grok parsing rule, which extracts structured fields from log content using named Grok patterns. Each rule must have a unique name and a valid Datadog…
2 properties
2 required
AWSLambdaForwarderConfig
object
Log Autosubscription configuration for Datadog Forwarder Lambda functions. Automatically set up triggers for existing and new logs for some services, ensuring…
2 properties
ObservabilityPipelineParseJSONProcessor
object
The parsejson processor extracts JSON from a specified field and flattens it into the event. This is useful when logs contain embedded JSON as a string.
5 properties
5 required
IPAllowlistEntryType
string
IP allowlist Entry type.
APIKeysType
string
API Keys resource type.
RelationshipToOrganization
object
Relationship to an organization.
1 property
1 required
TeamOnCallRespondersDataRelationshipsResponders
object
Defines the list of users assigned as on-call responders for the team.
1 property
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
ComponentGridPropertiesIsVisible
Whether the grid component and its children are visible. If a string, it must be a valid JavaScript expression that evaluates to a boolean.
IncidentTodoRelationships
object
The incident's relationships from a response.
2 properties
ObservabilityPipelineReduceProcessorMergeStrategy
object
Defines how a specific field should be merged across grouped events.
2 properties
2 required
ServiceDefinitionV2Integrations
object
Third party integrations that Datadog supports.
2 properties
DetailedFinding
object
A single finding with with message and resource configuration.
3 properties
EntityResponseIncludedRawSchemaType
string
Raw schema type.
ShiftDataRelationshipsUserData
object
Represents a reference to the user assigned to this shift, containing the user's ID and resource type.
2 properties
2 required
SendSlackMessageActionType
string
Indicates that the action is a send Slack message action.
ObservabilityPipelineAmazonDataFirehoseSourceType
string
The source type. The value should always be amazondatafirehose.
BillingDimensionsMappingBodyItem
object
The mapping data for each billing dimension.
3 properties
DORAListDeploymentsRequestData
object
The JSON:API data.
2 properties
1 required
EntityResponseData
array
List of entity data.
SecurityMonitoringRuleKeepAlive
integer
Once a signal is generated, the signal will remain "open" if a case is matched at least once within this keep alive window. For third party detection method, t…
ReadinessGateThresholdType
string
The definition of ReadinessGateThresholdType object.
MetricType
string
The metric resource type.
CaseResourceType
string
Case resource type
ObservabilityPipelineDedupeProcessorType
string
The processor type. The value should always be dedupe.
EntityResponseIncludedRawSchema
object
Included raw schema.
3 properties
ServiceDefinitionV2Dot2Pagerduty
object
PagerDuty integration for the service.
1 property
ObservabilityPipelineSentinelOneDestinationRegion
string
The SentinelOne region to send logs to.
UserTeamPermission
object
A user's permissions for a given team
3 properties
2 required
FindingResourceDiscoveryDate
integer
The date on which the resource was discovered (Unix ms).
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptions
object
Controls how partial redaction is applied, including character count and direction.
2 properties
2 required
ObservabilityPipelineGeneratedMetricIncrementByField
object
Strategy that increments a generated metric based on the value of a log field.
2 properties
2 required
FullAPIKeyAttributes
object
Attributes of a full API key.
7 properties
DashboardType
string
The type of the dashboard.
Weekday
string
A day of the week.
MetricsAndMetricTagConfigurations
Object for a metrics and metric tag configurations.
DataTransformProperties
object
The properties of the data transformer.
1 property
EscalationPolicyStepRelationships
object
Represents the relationship of an escalation policy step to its targets.
1 property
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
HistoricalJobResponse
object
Historical job response.
1 property
ObservabilityPipelineGeneratedMetricMetricType
string
Type of metric to create.
SpansAggregateResponseStatus
string
The status of the response.
AwsScanOptionsData
object
Single AWS Scan Options entry.
3 properties
UsageAttributesObject
object
Usage attributes data.
6 properties
CustomDestinationResponseForwardDestination
A custom destination's location to forward logs.
SecurityMonitoringRuleImpossibleTravelOptions
object
Options on impossible travel detection method.
1 property
OktaAccountAttributes
object
Attributes object for an Okta account.
6 properties
3 required
Case3rdPartyTicketStatus
string
Case status
Urgency
string
Specifies the level of urgency for a routing rule (low, high, or dynamic).
UserTeamTeamType
string
User team team type
TeamAttributes
object
Team attributes
12 properties
2 required
Role
object
Role object returned by the API.
4 properties
1 required
CloudConfigurationComplianceRuleOptions
object
Options for cloudconfiguration rules. Fields resourceType and regoRule are mandatory when managing custom cloudconfiguration rules.
3 properties
CustomDestinationResponseElasticsearchDestinationAuth
object
Basic access authentication.
EntityResponseIncludedRelatedEntityMeta
object
Included related entity meta.
4 properties
AuthNMappingsType
string
AuthN Mappings resource type.
ListDowntimesResponse
object
Response for retrieving all downtimes.
3 properties
AWSLogsServicesResponseAttributes
object
AWS Logs Services response body
1 property
1 required
AuditLogsResponseLinks
object
Links attributes.
1 property
ServiceDefinitionV2Dot1Pagerduty
object
PagerDuty integration for the service.
1 property
OutboundEdge
object
The definition of OutboundEdge object.
2 properties
2 required
IncidentServiceIncludedItems
An object related to an incident service which is present in the included payload.
DORAListFailuresRequestDataType
string
The definition of DORAListFailuresRequestDataType object.
MonitorNotificationRuleRecipients
array
A list of recipients to notify. Uses the same format as the monitor message field. Must not start with an '@'.
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternOptions
object
Options for defining a custom regex pattern.
1 property
1 required
CloudflareAccountType
string
The JSON:API type for this API. Should always be cloudflare-accounts.
ObservabilityPipelineAwsAuth
object
AWS authentication credentials used for accessing AWS services such as S3. If omitted, the system’s default credentials are used (for example, the IAM role and…
3 properties
ObservabilityPipelineConfigProcessorItem
A processor for the pipeline.
SingleAggregatedConnectionResponseArray
object
List of aggregated connections.
1 property
CustomDestinationResponseDefinition
object
The definition of a custom destination.
3 properties
ServiceDefinitionV2LinkType
string
Link type.
ObservabilityPipelineReduceProcessor
object
The reduce processor aggregates and merges logs based on matching keys and merge strategies.
6 properties
6 required
RumMetricResponseFilter
object
The rum-based metric filter. RUM events matching this filter will be aggregated in this metric.
1 property
RestrictionQueryRelationships
object
Relationships of the restriction query object.
1 property
RoutingRuleType
string
Team routing rules resource type.
CsmCoverageAnalysis
object
CSM Coverage Analysis.
4 properties
IncidentAttachmentsResponseIncludedItem
An object related to an attachment that is included in the response.
UserTeamsResponse
object
Team memberships response
4 properties
CustomConnectionType
string
The custom connection type.
SecurityMonitoringFilter
object
The rule's suppression filter.
2 properties
ConfluentAccountResponse
object
The expected response schema when getting a Confluent account.
1 property
AuthNMappingAttributes
object
Attributes of AuthN Mapping.
5 properties
FindingRule
object
The rule that triggered this finding.
2 properties
LogsArchiveDestinationGCSType
string
Type of the GCS archive destination.
JiraIssueResult
object
Jira issue information
4 properties
ContainerGroupRelationships
object
Relationships to containers inside a container group.
1 property
ContainerImageGroupAttributes
object
Attributes for a Container Image Group.
3 properties
IncidentTypeListResponse
object
Response with a list of incident types.
1 property
1 required
TeamLinkAttributes
object
Team link attributes
4 properties
2 required
ActionQuery
object
An action query. This query type is used to trigger an action, such as sending a HTTP request.
5 properties
4 required
CSMAgentsType
string
The type of the resource. The value should always be datadogagent.
PermissionAttributes
object
Attributes of a permission.
7 properties
SBOMMetadata
object
Provides additional information about a BOM.
1 property
NotificationRule
object
Notification rules allow full control over notifications generated by the various Datadog security products. They allow users to define the conditions under wh…
3 properties
3 required
ActionQueryPollingIntervalInMs
If specified, the app will poll the query at the specified interval in milliseconds. The minimum polling interval is 15 seconds. The query will only poll when…
LogsMetricResponse
object
The log-based metric object.
1 property
ApplicationSecurityWafExclusionFilterResponse
object
Response object for a single WAF exclusion filter.
1 property
SlackIntegrationMetadata
object
Incident integration metadata for the Slack integration.
1 property
1 required
IncidentTodoResponseData
object
Incident todo response data.
4 properties
2 required
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties
2 required
CloudWorkloadSecurityAgentRuleData
object
Object for a single Agent rule
3 properties
AWSAccountResponseData
object
AWS Account response data.
3 properties
2 required
MicrosoftTeamsTenantBasedHandleInfoResponseData
object
Tenant-based handle data from a response.
3 properties
EscalationRelationshipsRespondersDataItemsType
string
Represents the resource type for users assigned as responders in an escalation step.
RelationshipToTeam
object
Relationship to team.
1 property
MonitorNotificationRuleRelationshipsCreatedBy
object
The user who created the monitor notification rule.
1 property
LayerRelationshipsMembers
object
Holds an array of references to the members of a Layer, each containing member IDs.
1 property
ProjectAttributes
object
Project attributes
2 properties
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeInclude
object
Includes only specific fields for sensitive data scanning.
2 properties
2 required
EntityV3Datastore
object
Schema for datastore entities.
7 properties
3 required
IncidentServiceType
string
Incident service resource type.
TeamRoutingRulesDataRelationshipsRulesDataItemsType
string
Indicates that the resource is of type 'teamroutingrules'.
SLOReportStatusGetResponse
object
The SLO report status response.
1 property
Creator
object
Creator of the object.
3 properties
EntityResponseMeta
object
Entity metadata.
2 properties
MonitorConfigPolicyAttributeResponse
object
Policy and policy type for a monitor configuration policy.
2 properties
AuditLogsEventsResponse
object
Response object with all events matching the request and pagination information.
3 properties
SecurityTrigger
object
Trigger a workflow from a Security Signal or Finding. For automatic triggering a handle must be configured and the workflow must be published.
1 property
WorklflowGetInstanceResponseDataAttributes
object
The attributes of the instance response data.
1 property
TeamOnCallRespondersDataRelationshipsEscalationsDataItems
object
Represents a link to a specific escalation policy step associated with the on-call team.
2 properties
2 required
ServiceDefinitionV2Dot1EmailType
string
Contact type.
TeamPermissionSettingType
string
Team permission setting type
SecurityMonitoringSignalsSort
string
The sort parameters used for querying security signals.
IncidentTodoResponse
object
Response with an incident todo.
2 properties
1 required
ListEntityCatalogResponseIncluded
array
List entity response included.
ObservabilityPipelineEnrichmentTableFileSchemaItems
object
Describes a single column and its type in an enrichment table schema.
2 properties
2 required
ObservabilityPipelineNewRelicDestinationType
string
The destination type. The value should always be newrelic.
HTTPCredentials
The definition of HTTPCredentials object.
RoutingRuleRelationshipsPolicyData
object
Represents the policy data reference, containing the policy's ID and resource type.
2 properties
2 required
ConnectionEnv
object
A list of connections or connection groups used in the workflow.
3 properties
1 required
ContainerMetaPage
object
Paging attributes.
6 properties
RumMetricResponseCompute
object
The compute rule to compute the rum-based metric.
3 properties
RestrictionPolicy
object
Restriction policy object.
3 properties
3 required
SBOM
object
A single SBOM
3 properties
DeviceAttributes
object
The device attributes
20 properties
EscalationRelationshipsResponders
object
Lists the users involved in a specific step of the escalation policy.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactAction
string
Action type that redacts part of the sensitive data while preserving a configurable number of characters, typically used for masking purposes (e.g., show last…
ExternalUserMeta
object
Metadata associated with a user.
4 properties
ExternalUserGroup
object
Definition of a group.
6 properties
CustomDestinationResponseForwardDestinationHttpType
string
Type of the HTTP destination.
ConfluentResourceResponseData
object
Confluent Cloud resource data.
3 properties
3 required
OktaAccountResponse
object
Response object for an Okta account.
1 property
LogsMetricResponseComputeAggregationType
string
The type of aggregation to use.
EntityToSchema
object
Entity to detail schema relationship.
1 property
SecurityMonitoringSignalRuleType
string
The rule type.
AwsOnDemandData
object
Single AWS on demand task.
3 properties
EventType
string
Type of the event.
PartialApplicationKey
object
Partial Datadog application key.
4 properties
MicrosoftTeamsGetChannelByNameResponse
object
Response with channel, team, and tenant ID information.
1 property
IncidentTodoAnonymousAssignee
object
Anonymous assignee entity.
4 properties
4 required
SBOMComponent
object
Software or hardware component.
5 properties
3 required
EntityResponseIncludedRelatedOncallEscalationItem
object
Oncall escalation.
3 properties
GetInterfacesResponse
object
The GetInterfaces operation's response.
1 property
GetActionConnectionResponse
object
The response for found connection
1 property
UserResourceType
string
User resource type.
CustomDestinationType
string
The type of the resource. The value should always be customdestination.
EntityResponseIncludedOncallType
string
Oncall type.
PowerpackInnerWidgetLayout
object
Powerpack inner widget layout.
4 properties
4 required
IncidentAttachmentData
object
A single incident attachment.
4 properties
4 required
EntityV3APISpec
object
The definition of Entity V3 API Spec object.
5 properties
CaseType
string
Case type
RetryStrategy
object
The definition of RetryStrategy object.
2 properties
1 required
HourlyUsageMetadata
object
The object containing document metadata.
1 property
RetryStrategyKind
string
The definition of RetryStrategyKind object.
TeamRoutingRulesDataRelationshipsRules
object
Holds references to a set of routing rules in a relationship.
1 property
UserInvitationDataAttributes
object
Attributes of a user invitation.
4 properties
MonitorNotificationRuleRelationshipsCreatedByData
object
Data for the user who created the monitor notification rule.
2 properties
SecurityFilterResponse
object
Response object which includes a single security filter.
2 properties
AWSAccountTags
array
Tags to apply to all hosts and metrics reporting for this account. Defaults to [].
CsmCloudAccountsCoverageAnalysisAttributes
object
CSM Cloud Accounts Coverage Analysis attributes.
5 properties
ObservabilityPipelineGoogleCloudStorageDestination
object
The googlecloudstorage destination stores logs in a Google Cloud Storage (GCS) bucket. It requires a bucket name, GCP authentication, and metadata fields.
9 properties
7 required
ListEntityCatalogResponseLinks
object
List entity response links.
3 properties
ServiceDefinitionV1Integrations
object
Third party integrations that Datadog supports.
1 property
CustomCostsFileMetadataWithContentHighLevel
object
JSON API format of for a Custom Costs file with content.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorCustomPattern
object
Defines a custom regex-based pattern for identifying sensitive data in logs.
2 properties
2 required
CloudWorkloadSecurityAgentRuleKill
object
Kill system call applied on the container matching the rule
1 property
ServiceDefinitionSchemaVersions
string
Schema versions
RuleVersionUpdateType
string
The type of change.
UserAttributes
object
Attributes of user object returned by the API.
12 properties
ApplicationSecurityWafCustomRuleConditionParameters
object
The scope of the WAF custom rule.
6 properties
1 required
IncidentType
string
Incident resource type.
Component
object
[Definition of a UI component in the app](https://docs.datadoghq.com/servicemanagement/appbuilder/components/)
5 properties
3 required
RestrictionQueryResponseIncludedItem
An object related to a restriction query.
EntityV3DatadogIntegrationOpsgenie
object
An Opsgenie integration schema.
2 properties
1 required
UserInvitationsType
string
User invitations type.
IncidentIntegrationMetadataResponseData
object
Incident integration metadata from a response.
4 properties
2 required
InputSchema
object
A list of input parameters for the workflow. These can be used as dynamic runtime values in your workflow.
1 property
UserTarget
object
Represents a user target for an escalation policy step, including the user's ID and resource type.
2 properties
2 required
SecurityMonitoringSuppressionResponse
object
Response object containing a single suppression rule.
1 property
SecurityFilterMeta
object
Optional metadata associated to the response.
1 property
RoleAttributes
object
Attributes of the role.
4 properties
LogsArchiveIntegrationAzure
object
The Azure archive's integration destination.
2 properties
2 required
IncidentAttachmentsResponse
object
The response object containing an incident's attachments.
2 properties
1 required
User
object
User object returned by the API.
4 properties
EntityV3DatastoreKind
string
The definition of Entity V3 Datastore Kind object.
ObservabilityPipelineSensitiveDataScannerProcessor
object
The sensitivedatascanner processor detects and optionally redacts sensitive data in log events.
5 properties
5 required
ContainerImagesResponse
object
List of Container Images.
3 properties
ObservabilityPipelineDatadogLogsDestinationType
string
The destination type. The value should always be datadoglogs.
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property
1 required
CostAttributionTagNames
object
Tag keys and values. A null value here means that the requested tag breakdown cannot be applied because it does not match the [tags configured for usage attrib…
UserTeamRole
string
The user's role within the team
ActionQueryMockedOutputs
The mocked outputs of the action query. This is useful for testing the app without actually running the action.
EntityResponseIncludedRelatedEntity
object
Included related entity.
4 properties
EntityV3Integrations
object
A base schema for defining third-party integrations.
2 properties
CostByOrgAttributes
object
Cost attributes data.
8 properties
HTTPIntegrationType
string
The definition of HTTPIntegrationType object.
ConfluentAccountResponseData
object
An API key and API secret pair that represents a Confluent account.
3 properties
3 required
EmailTypeType
string
The type of email.
ObservabilityPipelineGenerateMetricsProcessor
object
The generatedatadogmetrics processor creates custom metrics from logs and sends them to Datadog. Metrics can be counters, gauges, or distributions and optional…
5 properties
5 required
RelationEntity
object
Relation entity reference.
3 properties
ListRelationCatalogResponseLinks
object
List relation response links.
3 properties
LogsResponseMetadataPage
object
Paging attributes.
1 property
EntityMeta
object
Entity metadata.
4 properties
ScheduleTriggerWrapper
object
Schema for a Schedule-based trigger.
2 properties
1 required
IncidentResponseData
object
Incident data from a response.
4 properties
2 required
FullApplicationKeyAttributes
object
Attributes of a full application key.
5 properties
MetricsAndMetricTagConfigurationsResponse
object
Response object that includes metrics and metric tag configurations.
3 properties
PowerpackData
object
Powerpack data object.
4 properties
EscalationRelationshipsRespondersDataItems
object
Represents a user assigned to an escalation step.
2 properties
2 required
DeploymentRelationshipData
object
Data object containing the deployment ID.
2 properties
CIAppPipelineEvent
object
Object description of a pipeline event after being processed and stored by Datadog.
3 properties
IncidentUserDefinedFieldType
string
The incident user defined fields type.
FindingStatus
string
The status of the finding.
CIAppTestLevel
string
Test run level.
MonitorNotificationRuleResourceType
string
Monitor notification rule resource type.
RelationRelationships
object
Relation relationships.
2 properties
OrganizationsType
string
Organizations resource type.
ListRelationCatalogResponse
object
List entity relation response.
4 properties
MonitorDowntimeMatchResponseAttributes
object
Downtime match details.
4 properties
ServiceDefinitionV2OpsgenieRegion
string
Opsgenie instance region.
ApplicationSecurityWafCustomRuleConditionOptions
object
Options for the operator of this condition.
2 properties
CaseTriggerWrapper
object
Schema for a Case-based trigger.
2 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptionsDirection
string
Indicates whether to redact characters from the first or last part of the matched value.
EntityResponseIncludedSchema
object
Included detail entity schema.
3 properties
MonitorConfigPolicyType
string
The monitor configuration policy type.
UsersRelationship
object
Relationship to users.
1 property
1 required
MicrosoftTeamsTenantBasedHandleInfoType
string
Tenant-based handle resource type.
RumMetricResponseUniqueness
object
The rule to count updatable events. Is only set if eventtype is session or view.
1 property
DORAListDeploymentsRequest
object
Request to get a list of deployments.
1 property
1 required
ObservabilityPipelineElasticsearchDestinationApiVersion
string
The Elasticsearch API version to use. Set to auto to auto-detect.
ServiceDefinitionV2Contact
Service owner's contacts information.
WorkflowUserRelationshipType
string
The definition of WorkflowUserRelationshipType object.
EventAttributes
object
Object description of attributes from your event.
19 properties
ObservabilityPipelinePipelineKafkaSourceSaslMechanism
string
SASL mechanism used for Kafka authentication.
RelationshipToOrganizationData
object
Relationship to organization object.
2 properties
2 required
MonthlyCostAttributionBody
object
Cost data.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPattern
object
Specifies a pattern from Datadog’s sensitive data detection library to match known sensitive data types.
2 properties
2 required
DashboardTriggerWrapper
object
Schema for a Dashboard-based trigger.
2 properties
1 required
XRayServicesIncludeOnly
object
Include only these services. Defaults to [].
1 property
1 required
OrgConfigGetResponse
object
A response with a single Org Config.
1 property
1 required
PowerpackGroupWidget
object
Powerpack group widget definition object.
3 properties
1 required
CustomDestinationResponseAttributes
object
The attributes associated with the custom destination.
7 properties
SecurityFilterFilteredDataType
string
The filtered data type.
OpsgenieServiceRegionType
string
The region for the Opsgenie service.
CustomDestinationResponseForwardDestinationSplunkType
string
Type of the Splunk HTTP Event Collector (HEC) destination.
ProjectResourceType
string
Project resource type
RUMApplicationAttributes
object
RUM application attributes.
11 properties
9 required
ContainerImageMetaPage
object
Paging attributes.
6 properties
ObservabilityPipelineGooglePubSubSource
object
The googlepubsub source ingests logs from a Google Cloud Pub/Sub subscription.
7 properties
6 required
DowntimeMetaPage
object
Object containing the total filtered count.
1 property
RumMetricsResponse
object
All the available rum-based metric objects.
1 property
PowerpackGroupWidgetLayout
object
Powerpack group widget layout.
4 properties
4 required
ObservabilityPipelineOcsfMapperProcessorType
string
The processor type. The value should always be ocsfmapper.
SpecVersion
string
The version of the CycloneDX specification a BOM conforms to.
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties
2 required
ObservabilityPipelineKafkaSourceLibrdkafkaOption
object
Represents a key-value pair used to configure low-level librdkafka client options for Kafka sources, such as timeouts, buffer sizes, and security settings.
2 properties
2 required
UsageDataObject
object
Usage data.
3 properties
LayerRelationships
object
Holds references to objects related to the Layer entity, such as its members.
1 property
DowntimeNotifyEndStateTypes
string
State that will trigger a monitor notification when the notifyendtypes action occurs.
DowntimeScheduleRecurrencesResponse
object
A recurring downtime schedule definition.
3 properties
1 required
SpansMetricResponse
object
The span-based metric object.
1 property
ActiveBillingDimensionsAttributes
object
List of active billing dimensions.
2 properties
RUMResponsePage
object
Paging attributes.
1 property
ExternalUserEmailType
object
Email address for the user.
3 properties
TagFilter
object
Tag filter for the budget's entries.
2 properties
SendSlackMessageAction
object
Sends a message to a Slack channel.
3 properties
3 required
SecurityMonitoringRuleEvaluationWindow
integer
A time window is specified to match when at least one of the cases matches true. This is a sliding window and evaluates in real time. For third party detection…
AuditLogsResponsePage
object
Paging attributes.
1 property
RuleName
string
Name of the notification rule.
UserTeamRelationships
object
Relationship between membership and a user
2 properties
CustomCostsFileGetResponse
object
Response for Get Custom Costs files.
2 properties
ObservabilityPipelineRenameFieldsProcessorType
string
The processor type. The value should always be renamefields.
ObservabilityPipelineHttpClientSourceType
string
The source type. The value should always be httpclient.
SecurityMonitoringFilterAction
string
The type of filtering action.
JSONAPIErrorResponse
object
API error response.
1 property
1 required
CaseTrigger
object
Trigger a workflow from a Case. For automatic triggering a handle must be configured and the workflow must be published.
1 property
TeamLinksResponse
object
Team links response
1 property
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
MetricTagConfigurationMetricTypeCategory
string
The metric's type category.
ActionQueryType
string
The action query type.
ScheduleDataRelationshipsLayersDataItems
object
Relates a layer to this schedule, identified by id and type (must be layers).
2 properties
2 required
ApplicationSecurityWafExclusionFilterOnMatch
string
The action taken when the exclusion filter matches. When set to monitor, security traces are emitted but the requests are not blocked. By default, security tra…
RelationIncludeType
string
Supported include types for relations.
CsmHostsAndContainersCoverageAnalysisData
object
CSM Hosts and Containers Coverage Analysis data.
3 properties
ServiceDefinitionV2Link
object
Service's external links.
3 properties
3 required
ScheduleDataRelationshipsLayersDataItemsType
string
Layers resource type.
RelationshipToPermissionData
object
Relationship to permission object.
2 properties
MetricMetaPage
object
Paging attributes. Only present if pagination query parameters were provided.
4 properties
InterfaceAttributes
object
The interface attributes
7 properties
IPAllowlistEntry
object
IP allowlist entry object.
1 property
1 required
CloudWorkloadSecurityAgentRuleAction
object
The action the rule can perform if triggered
4 properties
AppBuilderEventType
string
The response to the event.
SecurityMonitoringRuleCaseActionOptions
object
Options for the rule action
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeIncludeTarget
string
Applies the rule only to included fields.
EntityResponseIncludedOncall
object
Included oncall.
3 properties
DetailedFindingType
string
The JSON:API type for findings that have the message and resource configuration.
ObservabilityPipelineFilterProcessor
object
The filter processor allows conditional processing of logs based on a Datadog search query. Logs that match the include query are passed through; others are di…
4 properties
4 required
JiraIntegrationMetadata
object
Incident integration metadata for the Jira integration.
1 property
1 required
DeploymentMetadata
object
Metadata object containing the publication creation information.
4 properties
TeamPermissionSetting
object
Team permission setting
3 properties
2 required
Enabled
boolean
Field used to enable or disable the rule.
JobDefinition
object
Definition of a historical job.
14 properties
7 required
IncidentTypeAttributes
object
Incident type's attributes.
8 properties
1 required
ObservabilityPipelineParseGrokProcessor
object
The parsegrok processor extracts structured fields from unstructured log messages using Grok patterns.
6 properties
5 required
ObservabilityPipelineSumoLogicDestinationType
string
The destination type. The value should always be sumologic.
SecurityMonitoringReferenceTable
object
Reference tables used in the queries.
5 properties
ServiceDefinitionDataAttributes
object
Service definition attributes.
2 properties
DowntimeScheduleRecurrenceResponse
object
An RRULE-based recurring downtime.
3 properties
ProjectRelationshipData
object
Relationship to project object
2 properties
2 required
IncidentResponse
object
Response with an incident.
2 properties
1 required
RUMApplicationType
string
RUM application response type.
ObservabilityPipelineElasticsearchDestinationType
string
The destination type. The value should always be elasticsearch.
DORAListFailuresRequestAttributes
object
Attributes to get a list of failures.
5 properties
RumRetentionFilterType
string
The type of the resource. The value should always be retentionfilters.
CsmCloudAccountsCoverageAnalysisData
object
CSM Cloud Accounts Coverage Analysis data.
3 properties
ObservabilityPipelineSplunkHecSource
object
The splunkhec source implements the Splunk HTTP Event Collector (HEC) API.
3 properties
2 required
ObservabilityPipelineAmazonS3SourceType
string
The source type. Always amazons3.
UserInvitationResponse
object
User invitation as returned by the API.
1 property
IncidentTodoAttributes
object
Incident todo's attributes.
7 properties
2 required
ListEntityCatalogResponse
object
List entity response.
4 properties
RumMetricEventType
string
The type of RUM events to filter on.
TeamResponse
object
Response with a team
1 property
CloudConfigurationRuleComplianceSignalOptions
object
How to generate compliance signals. Useful for cloudconfiguration rules only.
4 properties
UserInvitationRelationships
object
Relationships data for user invitation.
1 property
1 required
DowntimeRelationships
object
All relationships associated with downtime.
2 properties
TeamRoutingRulesDataRelationships
object
Specifies relationships for team routing rules, including rule references.
1 property
StateVariableProperties
object
The properties of the state variable.
1 property
TeamOnCallRespondersDataRelationshipsEscalations
object
Defines the escalation policy steps linked to the team's on-call configuration.
1 property
HourlyUsage
object
Hourly usage for a product family for an org.
3 properties
TeamsResponse
object
Response with multiple teams
4 properties
MonitorConfigPolicyPolicy
Configuration for the policy.
ServiceDefinitionGetResponse
object
Get service definition response.
1 property
EscalationType
string
Represents the resource type for individual steps in an escalation policy used during incident response.
LogsArchiveDestinationGCS
object
The GCS archive destination.
4 properties
3 required
ObservabilityPipelineThrottleProcessor
object
The throttle processor limits the number of events that pass through over a given time window.
7 properties
6 required
RumRetentionFilterEnabled
boolean
Whether the retention filter is enabled.
IncludeType
string
Supported include types.
ProjectedCostAttributes
object
Projected Cost attributes data.
8 properties
TeamPermissionSettingsResponse
object
Team permission settings response
1 property
IncidentTodoType
string
Todo resource type.
GetRuleVersionHistoryData
object
Data for the rule version history.
3 properties
ShiftDataRelationshipsUserDataType
string
Indicates that the related resource is of type 'users'.
NullableUserRelationship
object
Relationship to user.
1 property
1 required
LogsMetricResponseData
object
The log-based metric properties.
3 properties
ObservabilityPipelineQuotaProcessorOverflowAction
string
The action to take when the quota is exceeded. Options: - drop: Drop the event. - noaction: Let the event pass through. - overflowrouting: Route to an overflow…
CloudWorkloadSecurityAgentPolicyAttributes
object
A Cloud Workload Security Agent policy returned by the API
15 properties
ResponseMetaAttributes
object
Object describing meta attributes of response.
1 property
CIAppResponseLinks
object
Links attributes.
1 property
ObservabilityPipelineSplunkHecSourceType
string
The source type. Always splunkhec.
LogsMetricType
string
The type of the resource. The value should always be logsmetrics.
EntityV3Metadata
object
The definition of Entity V3 Metadata object.
12 properties
1 required
Step
object
A Step is a sub-component of a workflow. Each Step performs an action.
9 properties
2 required
ProjectRelationships
object
Project relationships
2 properties
NotificationRuleQuery
string
The query is composed of one or several key:value pairs, which can be used to filter security issues on tags and attributes.
ScheduleTrigger
object
Trigger a workflow from a Schedule. The workflow must be published.
1 property
1 required
ContainerImageItem
Possible Container Image models.
SecurityMonitoringRuleNewValueOptionsForgetAfter
integer
The duration in days after which a learned value is forgotten.
CostByOrg
object
Cost data.
3 properties
ObservabilityPipelineLogstashSourceType
string
The source type. The value should always be logstash.
SBOMMetadataComponent
object
The component that the BOM describes.
2 properties
APIKeyRelationships
object
Resources related to the API key.
2 properties
RelationshipToUserTeamPermission
object
Relationship between a user team permission and a team
2 properties
FastlyAccountResponse
object
The expected response schema when getting a Fastly account.
1 property
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
CustomDestinationAttributeTagsRestrictionListType
string
How forwardtagsrestrictionlist parameter should be interpreted. If ALLOWLIST, then only tags whose keys on the forwarded logs match the ones on the restriction…
ServiceDefinitionV2EmailType
string
Contact type.
RetentionFilterAllAttributes
object
The attributes of the retention filter.
12 properties
EscalationPolicyStepType
string
Indicates that the resource is of type steps.
AWSAccountResponse
object
AWS Account response body.
1 property
1 required
EntityV3APISpecInterfaceFileRef
object
The definition of EntityV3APISpecInterfaceFileRef object.
1 property
RelationAttributes
object
Relation attributes.
3 properties
CsmAgentsAttributes
object
A CSM Agent returned by the API.
17 properties
LogsArchiveOrderAttributes
object
The attributes associated with the archive order.
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternType
string
Indicates that a predefined library pattern is used.
Trigger
One of the triggers that can start the execution of a workflow.
DowntimeResponseAttributes
object
Downtime details.
12 properties
ServiceDefinitionV2SlackType
string
Contact type.
ScheduleDataRelationshipsLayers
object
Associates layers with this schedule in a data structure.
1 property
ObservabilityPipelineHttpClientSource
object
The httpclient source scrapes logs from HTTP endpoints at regular intervals.
7 properties
3 required
ApplicationKeyResponseIncludedItem
An object related to an application key.
TeamRoutingRules
object
Represents a complete set of team routing rules, including data and optionally included related resources.
2 properties
ContainerImageMeta
object
Response metadata object.
1 property
EventPriority
string
The priority of the event's monitor. For example, normal or low.
EscalationPolicyDataType
string
Indicates that the resource is of type policies.
ServiceDefinitionV2Dot2Integrations
object
Third party integrations that Datadog supports.
2 properties
ServiceDefinitionMetaWarnings
object
Schema validation warnings.
3 properties
AWSIntegration
object
The definition of AWSIntegration object.
2 properties
2 required
SecurityMonitoringRuleOptions
object
Options.
10 properties
LogsArchiveDestinationS3Type
string
Type of the S3 archive destination.
OrgConfigRead
object
A single Org Config.
3 properties
3 required
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties
2 required
ConnectionGroup
object
The definition of ConnectionGroup object.
3 properties
3 required
RoleResponse
object
Response containing information about a single role.
1 property
ComponentGrid
object
A grid component. The grid component is the root canvas for an app and contains all other components.
5 properties
3 required
ScheduleMember
object
Represents a single member entry in a schedule, referencing a specific user.
3 properties
1 required
IPAllowlistData
object
IP allowlist data.
3 properties
1 required
HistoricalJobDataType
string
Type of payload.
ApplicationKeyRelationships
object
Resources related to the application key.
1 property
LeakedKey
object
The definition of LeakedKey object.
3 properties
3 required
MonitorConfigPolicyResponse
object
Response for retrieving a monitor configuration policy.
1 property
ShiftData
object
The definition of ShiftData object.
4 properties
1 required
ObservabilityPipelineAddEnvVarsProcessorType
string
The processor type. The value should always be addenvvars.
ApplicationSecurityWafExclusionFilterResource
object
A JSON:API resource for an WAF exclusion filter.
3 properties
DowntimeRelationshipsCreatedBy
object
The user who created the downtime.
1 property
ObservabilityPipelineGeneratedMetricIncrementByOneStrategy
string
Increments the metric by 1 for each matching event.
SecurityMonitoringSuppressionType
string
The type of the resource. The value should always be suppressions.
ObservabilityPipelineSyslogNgSource
object
The syslogng source listens for logs over TCP or UDP from a syslog-ng server using the syslog protocol.
4 properties
3 required
SecurityMonitoringSuppressionAttributes
object
The attributes of the suppression rule.
14 properties
CloudWorkloadSecurityAgentPolicyData
object
Object for a single Agent policy
3 properties
RelationshipToUserTeamTeam
object
Relationship between team membership and team
1 property
1 required
RUMEventType
string
Type of the event.
RetryStrategyLinear
object
The definition of RetryStrategyLinear object.
2 properties
2 required
RumMetricResponseAttributes
object
The object describing a Datadog rum-based metric.
5 properties
MetricMetaPageType
string
Type of metric pagination.
GetDeviceData
object
Get device response data.
3 properties
RumRetentionFilterSampleRate
integer
The sample rate for a RUM retention filter, between 0 and 100.
CompletionCondition
object
The definition of CompletionCondition object.
3 properties
2 required
ServiceDefinitionV2Dot1OpsgenieRegion
string
Opsgenie instance region.
ProjectRelationship
object
Relationship to project
1 property
1 required
RumRetentionFilterID
string
ID of retention filter in UUID.
IncidentTeamResponse
object
Response with an incident team payload.
2 properties
1 required
ObservabilityPipelineSensitiveDataScannerProcessorScope
Determines which parts of the log the pattern-matching rule should be applied to.
UrlParam
object
The definition of UrlParam object.
2 properties
2 required
OpsgenieServiceResponseData
object
Opsgenie service data from a response.
3 properties
3 required
ApplicationSecurityWafCustomRuleAttributes
object
A WAF custom rule.
9 properties
5 required
ObservabilityPipelineParseJSONProcessorType
string
The processor type. The value should always be parsejson.
AwsScanOptionsListResponse
object
Response object that includes a list of AWS scan options.
1 property
RuleUser
object
User creating or modifying a rule.
2 properties
MetricName
string
The metric name for this resource.
SAMLAssertionAttributesType
string
SAML assertion attributes resource type.
ServiceDefinitionV2Dot2Opsgenie
object
Opsgenie integration for the service.
2 properties
1 required
HourlyUsageAttributes
object
Attributes of hourly usage for a product family for an org for a time period.
8 properties
RelationshipToRoles
object
Relationship to roles.
1 property
NotebookTriggerWrapper
object
Schema for a Notebook-based trigger.
2 properties
1 required
LogAttributes
object
JSON object containing all log attributes and their associated values.
7 properties
TeamPermissionSettingAttributes
object
Team permission setting attributes
5 properties
EntityV3SystemKind
string
The definition of Entity V3 System Kind object.
ObservabilityPipelineSyslogNgSourceType
string
The source type. The value should always be syslogng.
SecurityMonitoringRuleCaseAction
object
Action to perform when a signal is triggered. Only available for Application Security rule type.
2 properties
SingleAggregatedConnectionResponseDataType
string
Aggregated connection resource type.
ObservabilityPipelineGenerateMetricsProcessorType
string
The processor type. Always generatedatadogmetrics.
ScheduleMemberType
string
Schedule Members resource type.
ObservabilityPipelineParseGrokProcessorRuleSupportRule
object
The Grok helper rule referenced in the parsing rules.
2 properties
2 required
SecurityMonitoringRuleCase
object
Case when signal is generated.
5 properties
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
EntityV3QueueKind
string
The definition of Entity V3 Queue Kind object.
ObservabilityPipelineSplunkTcpSourceType
string
The source type. Always splunktcp.
DORAListResponse
object
Response for the DORA list endpoints.
1 property
EscalationPolicyDataRelationshipsStepsDataItems
object
Defines a relationship to a single step within an escalation policy. Contains the step's id and type.
2 properties
2 required
LogsArchiveEncryptionS3Type
string
Type of S3 encryption for a destination.
LogsArchives
object
The available archives.
1 property
SpansMetricType
string
The type of resource. The value should always be spansmetrics.
RolesType
string
Roles type.
MetricCustomTimeAggregation
string
A time aggregation for use in query.
ObservabilityPipelineKafkaSourceType
string
The source type. The value should always be kafka.
ProcessSummariesMetaPage
object
Paging attributes.
2 properties
ObservabilityPipelineConfig
object
Specifies the pipeline's configuration, including its sources, processors, and destinations.
3 properties
2 required
RelationMeta
object
Relation metadata.
4 properties
RUMEventAttributes
object
JSON object containing all event attributes and their associated values.
4 properties
UsersType
string
Users resource type.
ServiceDefinitionV1Org
object
Org related information about the service.
2 properties
StartStepNames
array
A list of steps that run first after a trigger fires.
TeamOnCallRespondersDataRelationships
object
Relationship objects linked to a team's on-call responder configuration, including escalations and responders.
2 properties
EntityToRawSchema
object
Entity to raw schema relationship.
1 property
ContainersResponse
object
List of containers.
3 properties
CostAttributionType
string
Type of cost attribution data.
ContainerItem
Possible Container models.
ContainerImage
object
Container Image object.
3 properties
UserRelationshipData
object
Relationship to user object.
2 properties
2 required
SpansMetricResponseAttributes
object
The object describing a Datadog span-based metric.
3 properties
RumRetentionFilterAttributes
object
The object describing attributes of a RUM retention filter.
5 properties
RestrictionPolicyResponse
object
Response containing information about a single restriction policy.
1 property
1 required
IncidentIntegrationMetadataResponseIncludedItem
An object related to an incident integration metadata that is included in the response.
GetInterfacesData
object
The interfaces list data
3 properties
GithubWebhookTriggerWrapper
object
Schema for a GitHub webhook-based trigger.
2 properties
1 required
MetricTagConfigurationMetricTypes
string
The metric's type.
Container
object
Container object.
3 properties
TeamLinkResponse
object
Team link response
1 property
GetRuleVersionHistoryDataType
string
Type of data.
DomainAllowlistResponseDataAttributes
object
The details of the email domain allowlist.
2 properties
EntityV3API
object
Schema for API entities.
7 properties
3 required
HourlyUsageType
string
Usage type that is being measured.
TimeRestriction
object
Defines a single time restriction rule with start and end times and the applicable weekdays.
4 properties
ApplicationSecurityWafCustomRuleActionAction
string
Override the default action to take when the WAF custom rule would block.
EntityV3SystemSpec
object
The definition of Entity V3 System Spec object.
3 properties
ScheduleDataIncludedItem
Any additional resources related to this schedule, such as teams and layers.
ObservabilityPipelineGoogleCloudStorageDestinationAcl
string
Access control list setting for objects written to the bucket.
LogsArchiveAttributes
object
The attributes associated with the archive.
7 properties
3 required
ObservabilityPipelineGoogleChronicleDestinationType
string
The destination type. The value should always be googlechronicle.
ObservabilityPipelineAmazonS3DestinationType
string
The destination type. Always amazons3.
ObservabilityPipelineGoogleChronicleDestinationEncoding
string
The encoding format for the logs sent to Chronicle.
NotificationRulesType
string
The rule type associated to notification rules.
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties
2 required
FindingID
string
The unique ID for this finding.
ObservabilityPipelineFilterProcessorType
string
The processor type. The value should always be filter.
SecurityMonitoringThirdPartyRuleCaseCreate
object
Case when a signal is generated by a third party rule.
4 properties
1 required
FindingMuteReason
string
The reason why this finding is muted or unmuted.
MicrosoftTeamsTenantBasedHandleAttributes
object
Tenant-based handle attributes.
4 properties
ApplicationSecurityWafExclusionFilterRulesTargetTags
object
Target multiple WAF rules based on their tags.
2 properties
ActiveBillingDimensionsBody
object
Active billing dimensions data.
3 properties
ObservabilityPipelineParseGrokProcessorRule
object
A Grok parsing rule used in the parsegrok processor. Each rule defines how to extract structured fields from a specific log field using Grok patterns.
3 properties
3 required
CustomDestinationResponse
object
The custom destination.
1 property
ServiceNowTicketResult
object
ServiceNow ticket information
1 property
ProjectedCost
object
Projected Cost data.
3 properties
MonitorNotificationRuleName
string
The name of the monitor notification rule.
DetailedFindingAttributes
object
The JSON:API attributes of the detailed finding.
11 properties
ObservabilityPipelineNewRelicDestinationRegion
string
The New Relic region.
DowntimeResponseData
object
Downtime data.
4 properties
EventsWarning
object
A warning message indicating something is wrong with the query.
3 properties
IncidentIntegrationMetadataMetadata
Incident integration metadata's metadata attribute.
RestrictionQueryRoleAttribute
object
Attributes of the role for a restriction query.
1 property
SpansListResponse
object
Response object with all spans matching the request and pagination information.
3 properties
ContainerMeta
object
Response metadata object.
1 property
ScheduleTargetType
string
Indicates that the resource is of type schedules.
ActionQuerySpecObject
object
The action query spec object.
4 properties
1 required
ServiceDefinitionV2Dot2OpsgenieRegion
string
Opsgenie instance region.
HTTPTokenAuth
object
The definition of HTTPTokenAuth object.
5 properties
1 required
ServiceDefinitionV2Slack
object
Service owner's Slack channel.
3 properties
2 required
SecurityMonitoringRuleCaseCreate
object
Case when signal is generated.
5 properties
1 required
RelationType
string
Supported relation types.
TagsEventAttribute
array
Array of tags associated with your event.
RumMetricUniquenessWhen
string
When to count updatable events. match when the event is first seen, or end when the event is complete.
RelationResponseData
array
Array of relation responses
LogsMetricResponseCompute
object
The compute rule to compute the log-based metric.
3 properties
InputSchemaParametersType
string
The definition of InputSchemaParametersType object.
ApplicationSecurityWafExclusionFilterAttributes
object
Attributes describing a WAF exclusion filter.
11 properties
PowerpacksResponseMetaPagination
object
Powerpack response pagination metadata.
8 properties
ApplicationSecurityWafExclusionFilterMetadata
object
Extra information about the exclusion filter.
6 properties
Span
object
Object description of a spans after being processed and stored by Datadog.
3 properties
ScheduleData
object
Represents the primary data object for a schedule, linking attributes and relationships.
4 properties
1 required
Organization
object
Organization object.
3 properties
1 required
RumMetricResponseData
object
The rum-based metric properties.
3 properties
SendTeamsMessageAction
object
Sends a message to a Microsoft Teams channel.
4 properties
4 required
ObservabilityPipelineHttpServerSourceType
string
The source type. The value should always be httpserver.
CloudWorkloadSecurityAgentRuleAttributes
object
A Cloud Workload Security Agent rule returned by the API
21 properties
NullableRelationshipToUserData
object
Relationship to user object.
2 properties
2 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternOptions
object
Options for selecting a predefined library pattern and enabling keyword support.
2 properties
1 required
ObservabilityPipelineAmazonS3DestinationStorageClass
string
S3 storage class.
ObservabilityPipelineDecoding
string
The decoding format used to interpret incoming logs.
EntityV3DatadogCodeLocations
array
Schema for mapping source code locations to an entity.
ListTeamsSort
string
Specifies the order of the returned teams
ServiceDefinitionV1Contact
object
Contact information about the service.
2 properties
CloudWorkloadSecurityAgentPolicyType
string
The type of the resource, must always be policy
CIAppSort
string
Sort parameters when querying events.
ServiceDefinitionV2Dot1Link
object
Service's external links.
4 properties
3 required
FindingEvaluation
string
The evaluation of the finding.
MicrosoftTeamsWorkflowsWebhookResponseAttributes
object
Workflows Webhook handle attributes.
1 property
ObservabilityPipeline
object
Top-level schema representing a pipeline.
1 property
1 required
IncidentIntegrationMetadataAttributes
object
Incident integration metadata's attributes for a create request.
6 properties
2 required
ObservabilityPipelineConfigDestinationItem
A destination for the pipeline.
DevicesListData
object
The devices list data
3 properties
RestrictionPolicyType
string
Restriction policy type.
EntityV3DatastoreSpec
object
The definition of Entity V3 Datastore Spec object.
4 properties
ObservabilityPipelineConfigSourceItem
A data source for the pipeline.
IncidentTeamType
string
Incident Team resource type.
ObservabilityPipelineSensitiveDataScannerProcessorAction
Defines what action to take when sensitive data is matched.
SoftwareCatalogTriggerWrapper
object
Schema for a Software Catalog-based trigger.
2 properties
1 required
ObservabilityPipelineNewRelicDestination
object
The newrelic destination sends logs to the New Relic platform.
4 properties
4 required
PartialAPIKey
object
Partial Datadog API key.
4 properties
ApplicationSecurityWafCustomRuleAction
object
The definition of ApplicationSecurityWafCustomRuleAction object.
2 properties
DowntimeScheduleCurrentDowntimeResponse
object
The most recent actual start and end dates for a recurring downtime. For a canceled downtime, this is the previously occurring downtime. For active downtimes,…
2 properties
ApplicationSecurityWafCustomRuleResponse
object
Response object that includes a single WAF custom rule.
1 property
ScheduleMemberRelationshipsUserData
object
Points to the user data associated with this schedule member, including an ID and type.
2 properties
2 required
EntityV3DatadogLogItem
object
Log association item.
2 properties
SecurityMonitoringRuleQueryAggregation
string
The aggregation type.
AzureStorageDestination
object
The azurestorage destination forwards logs to an Azure Blob Storage container.
5 properties
4 required
GetAppResponseDataAttributes
object
The app definition attributes, such as name, description, and components.
7 properties
MonitorNotificationRuleResponseAttributes
object
Attributes of the monitor notification rule.
5 properties
HTTPBody
object
The definition of HTTPBody object.
2 properties
ObservabilityPipelineHttpServerSource
object
The httpserver source collects logs over HTTP POST from external services.
5 properties
4 required
OktaAccountType
string
Account type for an Okta account.
ServiceDefinitionData
object
Service definition data.
3 properties
EscalationPolicyStep
object
Represents a single step in an escalation policy, including its attributes, relationships, and resource type.
4 properties
1 required
APIKeysSort
string
Sorting options
ObservabilityPipelineSensitiveDataScannerProcessorType
string
The processor type. The value should always be sensitivedatascanner.
ContainerGroupRelationshipsLink
object
Relationships to Containers inside a Container Group.
2 properties
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
IncidentServiceRelationships
object
The incident service's relationships.
2 properties
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property
1 required
SecurityMonitoringRuleHardcodedEvaluatorType
string
Hardcoded evaluator type.
ObservabilityPipelineGooglePubSubSourceType
string
The source type. The value should always be googlepubsub.
TeamTargetType
string
Indicates that the resource is of type teams.
ProjectsResponse
object
Response with projects
1 property
CsmHostsAndContainersCoverageAnalysisAttributes
object
CSM Hosts and Containers Coverage Analysis attributes.
5 properties
TeamPermissionSettingValues
array
Possible values for action
CloudWorkloadSecurityAgentRuleActions
array
The array of actions the rule can perform if triggered
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedact
object
Configuration for partially redacting matched sensitive data.
2 properties
2 required
ContainerImageType
string
Type of Container Image.
LogType
string
Type of the event.
ObservabilityPipelineMetricValue
Specifies how the value of the generated metric is computed.
ScheduleUser
object
Represents a user object in the context of a schedule, including their id, type, and basic attributes.
3 properties
1 required
SAMLAssertionAttribute
object
SAML assertion attribute.
3 properties
2 required
MonitorConfigPolicyResponseData
object
A monitor configuration policy data.
3 properties
ShiftIncluded
The definition of ShiftIncluded object.
ProcessSummaryType
string
Type of process summary.
SecurityFilterID
string
The ID of the security filter.
IncidentTrigger
object
Trigger a workflow from an Incident. For automatic triggering a handle must be configured and the workflow must be published.
1 property
LogsArchive
object
The logs archive.
1 property
WorklflowGetInstanceResponseData
object
The data of the instance response.
1 property
RumMetricID
string
The name of the rum-based metric.
SelfServiceTriggerWrapper
object
Schema for a Self Service-based trigger.
2 properties
1 required
OnDemandConcurrencyCapAttributes
object
On-demand concurrency cap attributes.
1 property
ActiveBillingDimensionsType
string
Type of active billing dimensions data.
TeamsResponseLinks
object
Teams response links.
5 properties
MonitorTrigger
object
Trigger a workflow from a Monitor. For automatic triggering a handle must be configured and the workflow must be published.
1 property
AWSNamespaceFiltersIncludeOnly
object
Include only these namespaces.
1 property
1 required
EntityV3DatadogLogs
array
Logs association.
SecurityMonitoringSuppression
object
The suppression rule's properties.
3 properties
ListRelationCatalogResponseIncluded
array
List relation response included entities.
ServiceDefinitionV2Dot1
object
Service definition v2.1 for providing service metadata and integrations.
12 properties
2 required
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property
1 required
RetentionFilterAllType
string
The type of retention filter.
CloudflareAccountResponseAttributes
object
Attributes object of a Cloudflare account.
4 properties
1 required
ObservabilityPipelineEnrichmentTableFile
object
Defines a static enrichment table loaded from a CSV file.
4 properties
4 required
CloudWorkloadSecurityAgentRuleActionMetadata
object
The metadata action applied on the scope matching the rule
3 properties
Layer
object
Encapsulates a layer resource, holding attributes like rotation details, plus relationships to the members covering that layer.
4 properties
1 required
RumRetentionFilterEventType
string
The type of RUM events to filter on.
IPAllowlistEntryData
object
Data of the IP allowlist entry object.
3 properties
1 required
ApplicationSecurityWafCustomRuleTags
object
Tags associated with the WAF Custom Rule. The concatenation of category and type will form the security activity field associated with the traces.
2 properties
2 required
HTTPHeader
object
The definition of HTTPHeader object.
2 properties
2 required
OutputSchema
object
A list of output parameters for the workflow.
1 property
LogsArchiveDefinition
object
The definition of an archive.
3 properties
1 required
IncidentsResponse
object
Response with a list of incidents.
3 properties
1 required
AWSAssumeRole
object
The definition of AWSAssumeRole object.
5 properties
3 required
IncidentServiceResponseAttributes
object
The incident service's attributes from a response.
3 properties
RUMSort
string
Sort parameters when querying events.
ServiceDefinitionV2Dot1Slack
object
Service owner's Slack channel.
3 properties
2 required
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties
2 required
FastlyAccountResponseData
object
Data object of a Fastly account.
3 properties
3 required
TeamOnCallRespondersDataType
string
Represents the resource type for a group of users assigned to handle on-call duties within a team.
CustomDestinationResponseForwardDestinationElasticsearch
object
The Elasticsearch destination.
5 properties
4 required
CustomDestinationResponseForwardDestinationElasticsearchType
string
Type of the Elasticsearch destination.
CostAttributionAggregatesBody
object
The object containing the aggregates.
3 properties
RelationshipToUserTeamUser
object
Relationship between team membership and user
1 property
1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactAction
string
Action type that completely replaces the matched sensitive data with a fixed replacement string to remove all visibility.
AWSAccountType
string
AWS Account resource type.
RUMResponseLinks
object
Links attributes.
1 property
SortDirection
string
The direction to sort by.
LayerRelationshipsMembersDataItems
object
Represents a single member object in a layer's members array, referencing a unique Datadog user ID.
2 properties
2 required
ApplicationKeysSort
string
Sorting options
SingleAggregatedConnectionResponseDataAttributes
object
Attributes for an aggregated connection.
12 properties
ObservabilityPipelineReduceProcessorMergeStrategyStrategy
string
The merge strategy to apply.
SecurityMonitoringThirdPartyRootQuery
object
A query to be combined with the third party case query.
2 properties
SLOReportStatusGetResponseData
object
The data portion of the SLO report status response.
3 properties
TeamIncluded
Included resources related to the team
ContainerGroupRelationshipsLinks
object
Links attributes.
1 property
CustomDestinationResponseForwardDestinationHttp
object
The HTTP destination.
3 properties
3 required
BillingDimensionsMappingBodyItemAttributesEndpointsItems
object
An endpoint's keys mapped to the billingdimension.
3 properties
SecurityMonitoringSignalListRequest
object
The request for a security signal list.
3 properties
MicrosoftTeamsChannelInfoResponseData
object
Channel data from a response.
3 properties
IncidentSeverity
string
The incident severity.
EscalationPolicyStepAttributes
object
Defines attributes for an escalation policy step, such as assignment strategy and escalation timeout.
2 properties
ApplicationSecurityWafExclusionFilterID
string
The identifier of the WAF exclusion filter.
ObservabilityPipelineOpenSearchDestination
object
The opensearch destination writes logs to an OpenSearch cluster.
4 properties
3 required
DowntimeResponseIncludedItem
An object related to a downtime.
AWSAuthConfig
AWS Authentication config.
SecurityFilterAttributes
object
The object describing a security filter.
7 properties
SpansMetricComputeAggregationType
string
The type of aggregation to use.
BillingDimensionsMappingBodyItemAttributesEndpointsItemsStatus
string
Denotes whether mapping keys were available for this endpoint.
TeamReferenceType
string
Teams resource type.
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Datadog publishes across the network.