How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Datadog Lists API

The Lists API from Datadog — 75 operation(s) for lists.

Datadog Lists API is one of 290 APIs that Datadog publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 4 JSON Schema definitions.

Tagged areas include List. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, an API reference, and 4 JSON Schemas.

This API exposes 78 operations across 75 paths, and defines 921 schemas. It is described by OpenAPI 3.0.0, at version 1.0.

Requests are made against 3 base URLs: https://{subdomain}.{site}, {protocol}://{name}, https://{subdomain}.{site}.

78 operations 75 paths 921 schemas 1 DELETE72 GET4 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
1.0
Base URL
https://api.datadoghq.com
Authentication
OAuth 2.0, API Key, API Key, HTTP Bearer
Resource Areas
1

Authentication & Security 4

Datadog Lists API declares 4 security schemes for authenticating requests. It supports OAuth 2.0 (AuthZ) using the authorizationCode flow, exposing 68 scopes. An API key is passed in the header as DD-API-KEY (apiKeyAuth). An API key is passed in the header as DD-APPLICATION-KEY (appKeyAuth). It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

  • AuthZ — This API uses OAuth 2 with the implicit grant flow.
  • apiKeyAuth — Your Datadog API Key.
  • appKeyAuth — Your Datadog APP Key.

Paths & Operations 78

Across 75 paths, the API surfaces 78 operations — 1 DELETE, 72 GET, 4 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Lists 78
GET
/api/v2/apicatalog/apideprecated
Datadog List Apis
ListAPIs 3 params → 200400403429
GET
/api/v2/apm/config/retention-filters
Datadog List All Apm Retention Filters
ListApmRetentionFilters → 200403429
GET
/api/v2/app-builder/apps
Datadog List Apps
ListApps 11 params → 200400403429
GET
/api/v2/audit/events
Datadog Get a List of Audit Logs Events
ListAuditLogs 6 params → 200400403429
GET
/api/v2/authn_mappings
Datadog List All Authn Mappings
ListAuthNMappings 5 params → 200403429
GET
/api/v2/catalog/entity
Datadog Get a List of Entities
ListCatalogEntity 10 params → 200403429
GET
/api/v2/catalog/relation
Datadog Get a List of Entity Relations
ListCatalogRelation 6 params → 200403429
GET
/api/v2/ci/pipelines/events
Datadog Get a List of Pipelines Events
ListCIAppPipelineEvents 6 params → 200400403429
GET
/api/v2/ci/tests/events
Datadog Get a List of Tests Events
ListCIAppTestEvents 6 params → 200400403429
GET
/api/v2/cloud_security_management/resource_filters
Datadog List Resource Filters
GetResourceEvaluationFilters 3 params → 200400403429
GET
/api/v2/cost/aws_cur_config
Datadog List Cloud Cost Management Aws Cur Configs
ListCostAWSCURConfigs → 200403429
GET
/api/v2/cost/azure_uc_config
Datadog List Cloud Cost Management Azure Configs
ListCostAzureUCConfigs → 200403429
GET
/api/v2/cost/budgets
Datadog List Budgets
ListBudgets → 200429
GET
/api/v2/cost/custom_costs
Datadog List Custom Costs Files
ListCustomCostsFiles → 200403429
DELETE
/api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards
Datadog Delete Items from a Dashboard List
DeleteDashboardListItems 1 param body → 200400403404429
GET
/api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards
Datadog Get Items of a Dashboard List
GetDashboardListItems 1 param → 200403404429
POST
/api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards
Datadog Add Items to a Dashboard List
CreateDashboardListItems 1 param body → 200400403404429
PUT
/api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards
Datadog Update Items of a Dashboard List
UpdateDashboardListItems 1 param body → 200400403404429
POST
/api/v2/dora/deployments
Datadog Get a List of Deployment Events
ListDORADeployments body → 200400403429
POST
/api/v2/dora/failures
Datadog Get a List of Failure Events
ListDORAFailures body → 200400403429
GET
/api/v2/events
Datadog Get a List of Events
ListEvents 6 params → 200400403429
GET
/api/v2/incidents
Datadog Get a List of Incidents
ListIncidents 3 params → 200400401403404429
GET
/api/v2/incidents/config/types
Datadog Get a List of Incident Types
ListIncidentTypes 1 param → 200400401403429
GET
/api/v2/incidents/{incident_id}/attachments
Datadog Get a List of Attachments
ListIncidentAttachments 3 params → 200400401403404429
GET
/api/v2/incidents/{incident_id}/relationships/integrations
Datadog Get a List of an Incident's Integration Metadata
ListIncidentIntegrations 1 param → 200400401403404429
GET
/api/v2/incidents/{incident_id}/relationships/todos
Datadog Get a List of an Incident's Todos
ListIncidentTodos 1 param → 200400401403404429
GET
/api/v2/integration/aws/accounts
Datadog List All Aws Integrations
ListAWSAccounts 1 param → 200403429
GET
/api/v2/integration/aws/available_namespaces
Datadog List Available Namespaces
ListAWSNamespaces → 200403429
GET
/api/v2/integration/aws/logs/services
Datadog Get List of Aws Log Ready Services
ListAWSLogsServices → 200403429
GET
/api/v2/integration/gcp/accounts
Datadog List All Gcp Sts-enabled Service Accounts
ListGCPSTSAccounts → 200403404429
GET
/api/v2/integration/gcp/sts_delegate
Datadog List Delegate Account
GetGCPSTSDelegate → 200403429
GET
/api/v2/integrations/cloudflare/accounts
Datadog List Cloudflare Accounts
ListCloudflareAccounts → 200400403404429
GET
/api/v2/integrations/confluent-cloud/accounts
Datadog List Confluent Accounts
ListConfluentAccount → 200400403404429
GET
/api/v2/integrations/confluent-cloud/accounts/{account_id}/resources
Datadog List Confluent Account Resources
ListConfluentResource 1 param → 200400403404429
GET
/api/v2/integrations/fastly/accounts
Datadog List Fastly Accounts
ListFastlyAccounts → 200400403404429
GET
/api/v2/integrations/fastly/accounts/{account_id}/services
Datadog List Fastly Services
ListFastlyServices 1 param → 200400403404429
GET
/api/v2/integrations/okta/accounts
Datadog List Okta Accounts
ListOktaAccounts → 200400403404429
GET
/api/v2/logs/config/archives/{archive_id}/readers
Datadog List Read Roles for an Archive
ListArchiveReadRoles 1 param → 200400403404429
GET
/api/v2/logs/config/restriction_queries
Datadog List Restriction Queries
ListRestrictionQueries 2 params → 200403429
GET
/api/v2/logs/config/restriction_queries/{restriction_query_id}/roles
Datadog List Roles for a Restriction Query
ListRestrictionQueryRoles 3 params → 200400403404429
GET
/api/v2/metrics
Datadog Get a List of Metrics
ListTagConfigurations 10 params → 200400403429
GET
/api/v2/metrics/{metric_name}/active-configurations
Datadog List Active Tags and Aggregations
ListActiveMetricConfigurations 2 params → 200400403404429
GET
/api/v2/metrics/{metric_name}/all-tags
Datadog List Tags by Metric Name
ListTagsByMetricName 1 param → 200400403404429
GET
/api/v2/metrics/{metric_name}/tags
Datadog List Tag Configuration by Name
ListTagConfigurationByName 1 param → 200403404429
GET
/api/v2/metrics/{metric_name}/volumes
Datadog List Distinct Metric Volumes by Metric Name
ListVolumesByMetricName 1 param → 200400403404429
GET
/api/v2/ndm/devices
Datadog Get the List of Devices
ListDevices 4 params → 200400403429
GET
/api/v2/ndm/interfaces
Datadog Get the List of Interfaces of the Device
GetInterfaces 2 params → 200403429
GET
/api/v2/ndm/tags/devices/{device_id}
Datadog Get the List of Tags for a Device
ListDeviceUserTags 1 param → 200403404429
GET
/api/v2/org_configs
Datadog List Org Configs
ListOrgConfigs → 200400401403429
GET
/api/v2/permissions
Datadog List Permissions
ListPermissions → 200400403429
GET
/api/v2/posture_management/findings
Datadog List Findings
ListFindings 13 params → 200400403404429
GET
/api/v2/remote_config/products/asm/waf/custom_rules
Datadog List All Waf Custom Rules
ListApplicationSecurityWAFCustomRules → 200403429
GET
/api/v2/remote_config/products/asm/waf/exclusion_filters
Datadog List All Waf Exclusion Filters
ListApplicationSecurityWafExclusionFilters → 200403429
GET
/api/v2/remote_config/products/obs_pipelines/pipelines
Datadog List Pipelines
ListPipelines 2 params → 200400403429
GET
/api/v2/roles
Datadog List Roles
ListRoles 5 params → 200403429
GET
/api/v2/roles/{role_id}/permissions
Datadog List Permissions for a Role
ListRolePermissions 1 param → 200403404429
GET
/api/v2/rum/applications
Datadog List All the Rum Applications
GetRUMApplications → 200404429
GET
/api/v2/rum/events
Datadog Get a List of Rum Events
ListRUMEvents 6 params → 200400403429
GET
/api/v2/scim/Groups
Datadog List Groups
ListSCIMGroups 3 params → 200400429
GET
/api/v2/scim/Users
Datadog List Users
ListSCIMUsers 3 params → 200400429
GET
/api/v2/scorecard/outcomes
Datadog List All Rule Outcomes
ListScorecardOutcomes 10 params → 200400403429
GET
/api/v2/scorecard/rules
Datadog List All Rules
ListScorecardRules 10 params → 200400403429
GET
/api/v2/security/assets
Datadog List Vulnerable Assets
ListVulnerableAssets 16 params → 200400403404429
GET
/api/v2/security/signals/notification_rules
Datadog Get the List of Signal-based Notification Rules
GetSignalNotificationRules → 200403429
GET
/api/v2/security/vulnerabilities
Datadog List Vulnerabilities
ListVulnerabilities 40 params → 200400403404429
GET
/api/v2/security/vulnerabilities/notification_rules
Datadog Get the List of Vulnerability Notification Rules
GetVulnerabilityNotificationRules → 200403429
GET
/api/v2/security_monitoring/rules
Datadog List Rules
ListSecurityMonitoringRules 2 params → 200400429
GET
/api/v2/security_monitoring/signals
Datadog Get a Quick List of Security Signals
ListSecurityMonitoringSignals 6 params → 200400403429
POST
/api/v2/security_monitoring/signals/search
Datadog Get a List of Security Signals
SearchSecurityMonitoringSignals body → 200400403429
GET
/api/v2/sensitive-data-scanner/config
Datadog List Scanning Groups
ListScanningGroups → 200400403429
GET
/api/v2/sensitive-data-scanner/config/standard-patterns
Datadog List Standard Patterns
ListStandardPatterns → 200400403429
GET
/api/v2/service_accounts/{service_account_id}/application_keys
Datadog List Application Keys for This Service Account
ListServiceAccountApplicationKeys 7 params → 200400403404429
GET
/api/v2/servicesdeprecated
Datadog Get a List of All Incident Services
ListIncidentServices 4 params → 200400401403404429
GET
/api/v2/siem-historical-detections/jobs
Datadog List Historical Jobs
ListHistoricalJobs 4 params → 200400403429
GET
/api/v2/spans/events
Datadog Get a List of Spans
ListSpansGet 6 params → 200400403422429
GET
/api/v2/teamsdeprecated
Datadog Get a List of All Incident Teams
ListIncidentTeams 4 params → 200400401403404429
GET
/api/v2/users
Datadog List All Users
ListUsers 6 params → 200400403429
GET
/api/v2/workflows/{workflow_id}/instances
Datadog List Workflow Instances
ListWorkflowInstances 3 params → 200400403429

Schemas 921

The contract defines 921 schemas that model the data the API accepts and returns. The most detailed are SecurityMonitoringStandardRuleResponse (24 properties), IncidentResponseAttributes (24 properties), VulnerabilityAttributes (20 properties), DeviceAttributes (20 properties). Each schema is shown below with its type and property counts.

SecurityMonitoringRuleEvaluationWindow
integer
A time window is specified to match when at least one of the cases matches true. This is a sliding window and evaluates in real time. For third party detection…
SecurityMonitoringSignalListRequestFilter
object
Search filters for listing security signals.
3 properties
AuditLogsResponsePage
object
Paging attributes.
1 property
AWSMetricsConfig
object
AWS Metrics Collection config.
6 properties
RuleName
string
Name of the notification rule.
SecurityMonitoringRuleNewValueOptionsLearningThreshold
integer
A number of occurrences after which signals will be generated for values that weren't learned.
ObservabilityPipelineSplunkHecDestinationEncoding
string
Encoding format for log events.
FindingMute
object
Information about the mute status of this finding.
6 properties
MetricDistinctVolume
object
Object for a single metric's distinct volume.
3 properties
ObservabilityPipelineRenameFieldsProcessorType
string
The processor type. The value should always be renamefields.
SecurityMonitoringSignalType
string
The type of event.
VulnerabilityRelationshipsAffectsData
object
Asset affected by this vulnerability.
2 properties 2 required
EntityV3
Entity schema v3.
ListRulesResponseLinks
object
Links attributes.
1 property
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property 1 required
OrganizationAttributes
object
Attributes of the organization.
8 properties
ListTagsResponse
object
List tags response.
1 property
DependencyLocation
object
Static library vulnerability location.
5 properties 5 required
OrgConfigReadAttributes
object
Readable attributes of an Org Config.
5 properties 4 required
IncidentIntegrationMetadataType
string
Integration metadata resource type.
DeploymentAttributes
object
The attributes object containing the version ID of the published app.
1 property
VulnerabilityAttributes
object
The JSON:API attributes of the vulnerability.
20 properties 14 required
ObservabilityPipelineSensitiveDataScannerProcessorActionHashAction
string
Action type that replaces the matched sensitive data with a hashed representation, preserving structure while securing content.
RelationshipToRuleDataObject
object
Rule relationship data.
2 properties
OrgConfigListResponse
object
A response with multiple Org Configs.
1 property 1 required
ObservabilityPipelineHttpClientSourceType
string
The source type. The value should always be httpclient.
ObservabilityPipelineSensitiveDataScannerProcessorRule
object
Defines a rule for detecting sensitive data, including matching pattern, scope, and the action to take.
6 properties 5 required
DeploymentRelationship
object
Information pointing to the app's publication status.
2 properties
IncidentServicesResponse
object
Response with a list of incident service payloads.
3 properties 1 required
SecurityMonitoringFilterAction
string
The type of filtering action.
JSONAPIErrorResponse
object
API error response.
1 property 1 required
UserResponseIncludedItem
An object related to a user.
AuditLogsEventType
string
Type of the event.
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
DORAListDeploymentsRequestDataType
string
The definition of DORAListDeploymentsRequestDataType object.
MetricTagConfigurationMetricTypeCategory
string
The metric's type category.
FastlyServiceType
string
The JSON:API type for this API. Should always be fastly-services.
DashboardListAddItemsRequest
object
Request containing a list of dashboards to add.
1 property
DashboardListDeleteItemsRequest
object
Request containing a list of dashboards to delete.
1 property
ObservabilityPipelineRsyslogSourceType
string
The source type. The value should always be rsyslog.
SecurityMonitoringRuleDecreaseCriticalityBasedOnEnv
boolean
If true, signals in non-production environments have a lower severity than what is defined by the rule case, which can reduce signal noise. The severity is dec…
ApplicationSecurityWafExclusionFilterOnMatch
string
The action taken when the exclusion filter matches. When set to monitor, security traces are emitted but the requests are not blocked. By default, security tra…
JiraIntegrationMetadataIssuesItem
object
Item in the Jira integration metadata issue array.
5 properties 2 required
RelationIncludeType
string
Supported include types for relations.
FindingAttributes
object
The JSON:API attributes of the finding.
10 properties
AccountFilteringConfig
object
The account filtering configuration.
3 properties
ObservabilityPipelineOcsfMappingLibrary
string
Predefined library mappings for common log formats.
AuthNMappingResourceType
string
The type of resource being mapped to.
ApplicationSecurityWafCustomRuleListResponse
object
Response object that includes a list of WAF custom rules.
1 property
EntityToOncalls
object
Entity to oncalls relationship.
1 property
ApplicationSecurityWafCustomRuleConditionInputAddress
string
Input from the request on which the condition should apply.
RuleSeverity
string
Severity of a security rule.
CIAppPipelineEventTypeName
string
Type of the event.
RelationshipToUser
object
Relationship to user.
1 property 1 required
RelationshipToTeamData
object
Relationship to Team object.
2 properties
CodeLocation
object
Code vulnerability location.
3 properties 1 required
CIAppWarning
object
A warning message indicating something that went wrong with the query.
3 properties
AWSAccountID
string
AWS Account ID.
Version
integer
Version of the notification rule. It is updated when the rule is modified.
DeviceAttributesInterfaceStatuses
object
Count of the device interfaces by status
4 properties
GCPSTSDelegateAccountAttributes
object
Your delegate account attributes.
1 property
CustomCostListResponseMeta
object
Meta for the response from the List Custom Costs endpoints.
2 properties
ObservabilityPipelineGeneratedMetricIncrementByFieldStrategy
string
Uses a numeric field in the log event as the metric increment.
RelationshipToPermissionData
object
Relationship to permission object.
2 properties
SpansWarning
object
A warning message indicating something that went wrong with the query.
3 properties
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
RUMApplicationsResponse
object
RUM applications response.
1 property
DashboardListUpdateItemsResponse
object
Response containing a list of updated dashboards.
1 property
AwsCURConfig
object
AWS CUR config.
3 properties 2 required
SensitiveDataScannerStandardPatternData
object
A standard pattern.
1 property
MetricMetaPage
object
Paging attributes. Only present if pagination query parameters were provided.
4 properties
AWSNamespacesResponse
object
AWS Namespaces response body.
1 property 1 required
InterfaceAttributes
object
The interface attributes
7 properties
ObservabilityPipelineDedupeProcessorMode
string
The deduplication mode to apply to the fields.
IncidentResponseMetaPagination
object
Pagination properties.
3 properties
EPSS
object
Vulnerability EPSS severity.
2 properties 2 required
SecurityMonitoringRuleCaseActionOptions
object
Options for the rule action
2 properties
ConfluentResourceType
string
The JSON:API type for this request.
ObservabilityPipelineAmazonDataFirehoseSource
object
The amazondatafirehose source ingests logs from AWS Data Firehose.
4 properties 2 required
VulnerabilityEcosystem
string
The related vulnerability asset ecosystem.
ObservabilityPipelineSensitiveDataScannerProcessorScopeIncludeTarget
string
Applies the rule only to included fields.
HistoricalJobOptions
object
Job options.
7 properties
ListDevicesResponseMetadata
object
Object describing meta attributes of response.
1 property
UsersResponse
object
Response containing information about multiple users.
3 properties
EntityResponseIncludedOncall
object
Included oncall.
3 properties
OutcomesBatchResponseAttributes
object
The JSON:API attributes for an outcome.
5 properties
CIAppResponseStatus
string
The status of the response.
Deployment
object
The version of the app that was published.
4 properties
JiraIntegrationMetadata
object
Incident integration metadata for the Jira integration.
1 property 1 required
EntityV3DatastoreDatadog
object
Datadog product integrations for the datastore entity.
3 properties
AWSLogsServicesResponseDataType
string
The AWSLogsServicesResponseData type.
ObservabilityPipelineFilterProcessor
object
The filter processor allows conditional processing of logs based on a Datadog search query. Logs that match the include query are passed through; others are di…
4 properties 4 required
DeploymentMetadata
object
Metadata object containing the publication creation information.
4 properties
IncidentResponseMeta
object
The metadata object containing pagination metadata.
1 property
Enabled
boolean
Field used to enable or disable the rule.
HistoricalJobQuery
object
Query for selecting logs analyzed by the historical job.
8 properties
RelationResponse
object
Relation response data.
6 properties
JobDefinition
object
Definition of a historical job.
14 properties 7 required
EventsSort
string
The sort parameters when querying events.
AzureStorageDestinationType
string
The destination type. The value should always be azurestorage.
EventStatusType
string
If an alert event is enabled, its status is one of the following: failure, error, warning, info, success, userupdate, recommendation, or snapshot.
ObservabilityPipelineRsyslogDestination
object
The rsyslog destination forwards logs to an external rsyslog server over TCP or UDP using the syslog protocol.
5 properties 3 required
Targets
array
List of recipients to notify when a notification rule is triggered. Many different target types are supported, such as email addresses, Slack channels, and Pag…
DORAListDeploymentsRequestAttributes
object
Attributes to get a list of deployments.
5 properties
ObservabilityPipelineMetadataEntry
object
A custom metadata entry.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorActionHash
object
Configuration for hashing matched sensitive values.
2 properties 1 required
WorkflowListInstancesResponseMetaPage
object
Page information for the list instances response.
1 property
ObservabilityPipelineParseGrokProcessor
object
The parsegrok processor extracts structured fields from unstructured log messages using Grok patterns.
6 properties 5 required
IncidentTypeAttributes
object
Incident type's attributes.
8 properties 1 required
ObservabilityPipelineSumoLogicDestinationType
string
The destination type. The value should always be sumologic.
DashboardListUpdateItemsRequest
object
Request containing the list of dashboards to update to.
1 property
EntityResponseIncludedRelatedOncallAttributes
object
Included related oncall attributes.
2 properties
CloudflareAccountResponseData
object
Data object of a Cloudflare account.
3 properties 3 required
MetricDistinctVolumeAttributes
object
Object containing the definition of a metric's distinct volume.
1 property
Permission
object
Permission object.
3 properties 1 required
SecurityMonitoringReferenceTable
object
Reference tables used in the queries.
5 properties
ListAPIsResponseDataAttributes
object
Attributes for ListAPIsResponseData.
1 property
OutcomesResponseIncludedRuleAttributes
object
Details of a rule.
2 properties
GCPSTSServiceAccountAttributes
object
Attributes associated with your service account.
11 properties
AzureUCConfigPair
object
Azure config pair.
3 properties 2 required
OktaAccountResponseData
object
Data object of an Okta account
3 properties 3 required
ObservabilityPipelineSyslogNgDestinationType
string
The destination type. The value should always be syslogng.
ListVulnerableAssetsResponse
object
The expected response schema when listing vulnerable assets.
3 properties 1 required
ObservabilityPipelineEnrichmentTableFileEncodingType
string
Specifies the encoding format (e.g., CSV) used for enrichment tables.
EntityResponseIncludedRelatedIncidentAttributes
object
Incident attributes.
5 properties
Finding
object
A single finding without the message and resource configuration.
3 properties
ListExternalUserGroupResponseResourcesItemsMembersItems
object
The definition of a member belonging to a group in the List groups response.
4 properties
ObservabilityPipelineElasticsearchDestinationType
string
The destination type. The value should always be elasticsearch.
QuerySortOrder
string
Direction of sort.
AWSNamespacesResponseData
object
AWS Namespaces response data.
3 properties 2 required
EntityAttributes
object
Entity attributes.
8 properties
RUMApplicationList
object
RUM application list.
3 properties 2 required
AuthNMappingRelationships
object
All relationships associated with AuthN Mapping.
3 properties
ObservabilityPipelineFluentdSourceType
string
The source type. The value should always be fluentd.
RetentionFilterAll
object
The definition of the retention filter.
3 properties 3 required
DORAListFailuresRequestAttributes
object
Attributes to get a list of failures.
5 properties
RelationResponseMeta
object
Relation response metadata.
2 properties
AWSNamespacesResponseDataType
string
The AWSNamespacesResponseData type.
FindingEvaluationChangedAt
integer
The date on which the evaluation for this finding changed (Unix ms).
SecurityMonitoringListRulesResponse
object
List of rules.
2 properties
ListFindingsMeta
object
Metadata for pagination.
2 properties
ConfluentResourcesResponse
object
Response schema when interacting with a list of Confluent resources.
1 property
ListFindingsPage
object
Pagination and findings count information.
2 properties
ObservabilityPipelineOcsfMapperProcessorMappingMapping
Defines a single mapping rule for transforming logs into the OCSF schema.
ObservabilityPipelineSplunkHecSource
object
The splunkhec source implements the Splunk HTTP Event Collector (HEC) API.
3 properties 2 required
Event
object
The metadata associated with a request.
4 properties
CustomCostsFileMetadata
object
Schema of a Custom Costs metadata.
8 properties
APIErrorResponse
object
API error response.
1 property 1 required
ListAPIsResponseMetaPagination
object
Pagination metadata information for ListAPIsResponse.
3 properties
XRayServicesIncludeAll
object
Include all services.
1 property 1 required
RelationResponseType
string
Relation type.
ObservabilityPipelineSensitiveDataScannerProcessorKeywordOptions
object
Configuration for keywords used to reinforce sensitive data pattern detection.
2 properties 2 required
ObservabilityPipelineAmazonOpenSearchDestination
object
The amazonopensearch destination writes logs to Amazon OpenSearch.
5 properties 4 required
ObservabilityPipelineAmazonS3SourceType
string
The source type. Always amazons3.
ObservabilityPipelineSumoLogicSourceType
string
The source type. The value should always be sumologic.
MSTeamsIntegrationMetadataTeamsItem
object
Item in the Microsoft Teams integration metadata teams array.
4 properties 4 required
EventResponse
object
The object description of an event after being processed and stored by Datadog.
3 properties
IncidentTodoAttributes
object
Incident todo's attributes.
7 properties 2 required
ListEntityCatalogResponse
object
List entity response.
4 properties
ObservabilityPipelineEnrichmentTableGeoIp
object
Uses a GeoIP database to enrich logs based on an IP field.
3 properties 3 required
ListHistoricalJobsResponse
object
List of historical jobs.
2 properties
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties 1 required
Library
object
Vulnerability library.
2 properties 1 required
CloudConfigurationRuleComplianceSignalOptions
object
How to generate compliance signals. Useful for cloudconfiguration rules only.
4 properties
ApplicationSecurityWafCustomRuleConditionInput
object
Input from the request on which the condition should apply.
2 properties 1 required
State
string
The state of the rule evaluation.
AWSLogsServicesResponse
object
AWS Logs Services response body
1 property 1 required
FastlyAccounResponseAttributes
object
Attributes object of a Fastly account.
2 properties 1 required
AWSNamespaceTagFilter
object
AWS Metrics Collection tag filters list. Defaults to []. The array of custom AWS resource tags (in the form key:value) defines a filter that Datadog uses when…
2 properties
EntityV3MetadataAdditionalOwnersItems
object
The definition of Entity V3 Metadata Additional Owners Items object.
2 properties 1 required
ApplicationSecurityWafCustomRuleActionParameters
object
The definition of ApplicationSecurityWafCustomRuleActionParameters object.
2 properties
ObservabilityPipelineSentinelOneDestinationType
string
The destination type. The value should always be sentinelone.
ObservabilityPipelineGoogleCloudStorageDestinationType
string
The destination type. Always googlecloudstorage.
ApplicationSecurityWafCustomRuleScope
object
The scope of the WAF custom rule.
2 properties 2 required
AWSAuthConfigKeys
object
AWS Authentication config to integrate your account using an access key pair.
2 properties 1 required
XRayServicesList
AWS X-Ray services to collect traces from. Defaults to includeonly.
SecurityMonitoringThirdPartyRuleCase
object
Case when signal is generated by a third party rule.
4 properties
SensitiveDataScannerRuleType
string
Sensitive Data Scanner rule type.
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
RelationshipToSAMLAssertionAttribute
object
AuthN Mapping relationship to SAML Assertion Attribute.
1 property 1 required
AuditLogsSort
string
Sort parameters when querying events.
SpansAttributes
object
JSON object containing all span attributes and their associated values.
17 properties
AWSNamespaceFilters
AWS Metrics namespace filters. Defaults to excludeonly.
EventsResponseMetadata
object
The metadata associated with a request.
5 properties
ObservabilityPipelineThrottleProcessor
object
The throttle processor limits the number of events that pass through over a given time window.
7 properties 6 required
ListExternalUserGroupResponseResourcesItems
object
Resources returned in response to a List groups request.
6 properties
IncludeType
string
Supported include types.
SensitiveDataScannerConfigurationData
object
A Sensitive Data Scanner configuration data.
1 property
EntityV3DatadogPipelines
object
CI Pipelines association.
1 property
ApplicationSecurityWafExclusionFilterScope
object
Deploy on services based on their environment and/or service name.
2 properties
GCPSTSDelegateAccountResponse
object
Your delegate service account response data.
1 property
AWSAccountsResponse
object
AWS Accounts response body.
1 property 1 required
IncidentTodoAssigneeHandle
string
Assignee's @-handle.
EntityV3System
object
Schema for system entities.
7 properties 3 required
ObservabilityPipelineSumoLogicDestinationHeaderCustomFieldsItem
object
Single key-value pair used as a custom log header for Sumo Logic.
2 properties 2 required
RuleId
string
The unique ID for a scorecard rule.
EntityV3MetadataLinksItems
object
The definition of Entity V3 Metadata Links Items object.
4 properties 3 required
RelationshipToOrganizations
object
Relationship to organizations.
1 property 1 required
LeakedKeyType
string
The definition of LeakedKeyType object.
ObservabilityPipelineQuotaProcessorLimitEnforceType
string
Unit for quota enforcement in bytes for data size or events for count.
DORAEvent
object
A DORA event.
3 properties
IncidentTodoType
string
Todo resource type.
NullableRelationshipToUser
object
Relationship to user.
1 property 1 required
CIAppResponsePage
object
Paging attributes.
1 property
RUMApplicationListAttributes
object
RUM application list attributes.
10 properties 8 required
SecurityMonitoringRuleNewValueOptionsLearningDuration
integer
The duration in days during which values are learned, and after which signals will be generated for values that weren't learned. If set to 0, a signal will be…
PermissionsResponse
object
Payload with API-returned permissions.
1 property
DORAListFailuresRequestData
object
The JSON:API data.
2 properties 1 required
AWSResourcesConfig
object
AWS Resources Collection config.
2 properties
Selectors
object
Selectors are used to filter security issues for which notifications should be generated. Users can specify rule severities, rule types, a query to filter secu…
4 properties 1 required
ObservabilityPipelineRsyslogDestinationType
string
The destination type. The value should always be rsyslog.
SecurityMonitoringRuleNewValueOptions
object
Options on new value detection method.
4 properties
EventsListResponseLinks
object
Links attributes.
1 property
AWSAccountResponseAttributes
object
AWS Account response attributes.
11 properties 1 required
RolesResponse
object
Response containing information about multiple roles.
2 properties
ListExternalUserGroupResponse
object
List groups response object.
5 properties
RetentionFiltersResponse
object
An ordered list of retention filters.
1 property 1 required
ObservabilityPipelineQuotaProcessorOverflowAction
string
The action to take when the quota is exceeded. Options: - drop: Drop the event. - noaction: Let the event pass through. - overflowrouting: Route to an overflow…
ResponseMetaAttributes
object
Object describing meta attributes of response.
1 property
CIAppResponseLinks
object
Links attributes.
1 property
SensitiveDataScannerRule
object
Rule item included in the group.
2 properties
ObservabilityPipelineSplunkHecSourceType
string
The source type. Always splunkhec.
EntityV3Metadata
object
The definition of Entity V3 Metadata object.
12 properties 1 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeAllTarget
string
Applies the rule to all fields.
ObservabilityPipelineSumoLogicDestinationEncoding
string
The output encoding format.
ApplicationSecurityWafCustomRuleType
string
The type of the resource. The value should always be customrule.
NotificationRuleQuery
string
The query is composed of one or several key:value pairs, which can be used to filter security issues on tags and attributes.
AWSAccountConfigID
string
Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/ap…
ObservabilityPipelineParseGrokProcessorType
string
The processor type. The value should always be parsegrok.
RUMResponseStatus
string
The status of the response.
RestrictionQueryWithoutRelationships
object
Restriction query object returned by the API.
3 properties
FastlyServiceAttributes
object
Attributes object for Fastly service requests.
1 property
ObservabilityPipelineAmazonOpenSearchDestinationType
string
The destination type. The value should always be amazonopensearch.
ExternalUserGroupMeta
object
Metadata associated with a group.
4 properties
SecurityMonitoringRuleCaseActionOptionsUserBehaviorName
string
Used with the case action of type 'userbehavior'. The value specified in this field is applied as a risk tag to all users affected by the rule.
ObservabilityPipelineRsyslogSource
object
The rsyslog source listens for logs over TCP or UDP from an rsyslog server using the syslog protocol.
4 properties 3 required
IncidentAttachmentAttributes
The attributes object for an attachment.
SecurityMonitoringRuleNewValueOptionsForgetAfter
integer
The duration in days after which a learned value is forgotten.
IncidentAttachmentRelatedObject
string
The object related to an incident attachment.
AuthNMappingIncluded
Included data in the AuthN Mapping response.
JSONAPIErrorItem
object
API error response body
5 properties
ObservabilityPipelineLogstashSourceType
string
The source type. The value should always be logstash.
SensitiveDataScannerMeta
object
Meta response containing information about the API.
6 properties
MetricCustomAggregations
array
Deprecated. You no longer need to configure specific time and space aggregations for Metrics Without Limits.
RestrictionQueryAttributes
object
Attributes of the restriction query.
3 properties
RuleTypesItems
string
Security rule type which can be used in security rules. Signal-based notification rules can filter signals based on rule types applicationsecurity, logdetectio…
AWSLogsServicesResponseData
object
AWS Logs Services response body
3 properties 2 required
LeakedKeyAttributes
object
The definition of LeakedKeyAttributes object.
2 properties 1 required
EventResponseAttributes
object
The object description of an event response attribute.
4 properties
ObservabilityPipelineGeneratedMetric
object
Defines a log-based custom metric, including its name, type, filter, value computation strategy, and optional grouping fields.
5 properties 4 required
VulnerabilityTool
string
The vulnerability tool.
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
SensitiveDataScannerRuleAttributes
object
Attributes of the Sensitive Data Scanner rule.
10 properties
AWSRegionsIncludeAll
object
Include all regions. Defaults to true.
1 property 1 required
ObservabilityPipelineGoogleChronicleDestination
object
The googlechronicle destination sends logs to Google Chronicle.
7 properties 5 required
IncidentTodoAnonymousAssigneeSource
string
The source of the anonymous assignee.
MetricTagConfigurationType
string
The metric tag configuration resource type.
AWSRegions
AWS Regions to collect data from. Defaults to includeall.
ApiID
string
API identifier.
ObservabilityPipelineEnrichmentTableFileKeyItemsComparison
string
Defines how to compare key fields for enrichment table lookups.
SecurityMonitoringStandardRuleQuery
object
Query for matching rule.
9 properties
SecurityMonitoringSignalRuleResponse
object
Rule.
18 properties
FindingResourceType
string
The resource type of this finding.
EntityV3APISpecInterfaceDefinition
object
The definition of EntityV3APISpecInterfaceDefinition object.
1 property
RetentionFilterAllAttributes
object
The attributes of the retention filter.
12 properties
AuditLogsResponseMetadata
object
The metadata associated with a request.
5 properties
ObservabilityPipelineParseGrokProcessorRuleMatchRule
object
Defines a Grok parsing rule, which extracts structured fields from log content using named Grok patterns. Each rule must have a unique name and a valid Datadog…
2 properties 2 required
ObservabilityPipelineKafkaSource
object
The kafka source ingests data from Apache Kafka topics.
7 properties 4 required
RUMResponseMetadata
object
The metadata associated with a request.
5 properties
ListTagsResponseDataAttributes
object
The definition of ListTagsResponseDataAttributes object.
1 property
EntityV3APISpecInterfaceFileRef
object
The definition of EntityV3APISpecInterfaceFileRef object.
1 property
SecurityMonitoringSignalListRequestPage
object
The paging attributes for listing security signals.
2 properties
RelationAttributes
object
Relation attributes.
3 properties
ListAppsResponseDataItems
object
An app definition object. This contains only basic information about the app such as ID, name, and tags.
5 properties 3 required
ListExternalUsersResponseResourcesItems
object
Resources returned in response to a List users request.
8 properties
OktaAccountsResponse
object
The expected response schema when getting Okta accounts.
1 property
CustomCostsFileMetadataHighLevel
object
JSON API format for a Custom Costs file.
3 properties
AWSLambdaForwarderConfig
object
Log Autosubscription configuration for Datadog Forwarder Lambda functions. Automatically set up triggers for existing and new logs for some services, ensuring…
2 properties
MetricCustomSpaceAggregation
string
A space aggregation for use in query.
ObservabilityPipelineSplunkTcpSource
object
The splunktcp source receives logs from a Splunk Universal Forwarder over TCP. TLS is supported for secure transmission.
3 properties 2 required
ObservabilityPipelineParseJSONProcessor
object
The parsejson processor extracts JSON from a specified field and flattens it into the event. This is useful when logs contain embedded JSON as a string.
5 properties 5 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternType
string
Indicates that a predefined library pattern is used.
AppsSortField
string
The field and direction to sort apps by
SensitiveDataScannerGroupItem
object
Data related to a Sensitive Data Scanner Group.
2 properties
SensitiveDataScannerStandardPatternsResponseData
object
List Standard patterns response data.
1 property
VulnerabilitiesType
string
The JSON:API type.
MetricIngestedIndexedVolumeType
string
The metric ingested and indexed volume type.
EntityV3MetadataContactsItems
object
The definition of Entity V3 Metadata Contacts Items object.
3 properties 2 required
EntityResponseIncludedRelatedEntityAttributes
object
Related entity attributes.
4 properties
SensitiveDataScannerStandardPatternAttributes
object
Attributes of the Sensitive Data Scanner standard pattern.
6 properties
RelationshipToOrganization
object
Relationship to an organization.
1 property 1 required
ObservabilityPipelineElasticsearchDestination
object
The elasticsearch destination writes logs to an Elasticsearch cluster.
5 properties 3 required
IncidentTeamResponseAttributes
object
The incident team's attributes from a response.
3 properties
ObservabilityPipelineHttpClientSource
object
The httpclient source scrapes logs from HTTP endpoints at regular intervals.
7 properties 3 required
ApplicationKeyResponseIncludedItem
An object related to an application key.
IncidentTypeObject
object
Incident type response data.
3 properties 2 required
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
SensitiveDataScannerGroupList
object
List of groups, ordered.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternType
string
Indicates a custom regular expression is used for matching.
IncidentTodoRelationships
object
The incident's relationships from a response.
2 properties
AuditLogsEventAttributes
object
JSON object containing all event attributes and their associated values.
5 properties
ObservabilityPipelineReduceProcessorMergeStrategy
object
Defines how a specific field should be merged across grouped events.
2 properties 2 required
EventPriority
string
The priority of the event's monitor. For example, normal or low.
ObservabilityPipelineGcpAuth
object
GCP credentials used to authenticate with Google Cloud Storage.
1 property 1 required
GCPSTSDelegateAccount
object
Datadog principal service account info.
3 properties
OutcomesResponseData
array
List of rule outcomes.
EntityResponseIncludedRawSchemaType
string
Raw schema type.
HistoricalJobListMeta
object
Metadata about the list of jobs.
1 property
AwsCURConfigsResponse
object
List of AWS CUR configs.
1 property
ObservabilityPipelineRenameFieldsProcessor
object
The renamefields processor changes field names.
5 properties 5 required
IncidentTeamIncludedItems
An object related to an incident team which is present in the included payload.
ObservabilityPipelineAmazonDataFirehoseSourceType
string
The source type. The value should always be amazondatafirehose.
ListAppsResponseDataItemsAttributes
object
Basic information about the app such as name, description, and tags.
5 properties
ApplicationSecurityWafCustomRuleData
object
Object for a single WAF custom rule.
3 properties
TriggerSource
string
The type of security issues on which the rule applies. Notification rules based on security signals need to use the trigger source "securitysignals", while not…
DORAListDeploymentsRequestData
object
The JSON:API data.
2 properties 1 required
HistoricalJobResponseAttributes
object
Historical job attributes.
8 properties
SecurityMonitoringRuleOptions
object
Options.
10 properties
TeamType
string
Team type
SensitiveDataScannerGetConfigResponseData
object
Response data related to the scanning groups.
4 properties
SAMLAssertionAttributeAttributes
object
Key/Value pair of attributes used in SAML assertion attributes.
2 properties
ObservabilityPipelineThrottleProcessorType
string
The processor type. The value should always be throttle.
EntityResponseData
array
List of entity data.
DashboardListItemResponse
object
A dashboard within a list.
2 properties 2 required
EntityV3QueueDatadog
object
Datadog product integrations for the datastore entity.
3 properties
VulnerabilityRelationshipsAffects
object
Relationship type.
1 property 1 required
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties 2 required
ObservabilityPipelineSentinelOneDestination
object
The sentinelone destination sends logs to SentinelOne.
4 properties 4 required
OrgConfigRead
object
A single Org Config.
3 properties 3 required
SecurityMonitoringRuleKeepAlive
integer
Once a signal is generated, the signal will remain "open" if a case is matched at least once within this keep alive window. For third party detection method, t…
MetricType
string
The metric resource type.
AssetAttributes
object
The JSON:API attributes of the asset.
7 properties 4 required
SecurityMonitoringSignalsListResponseMetaPage
object
Paging attributes.
1 property
EntityResponseIncludedRawSchema
object
Included raw schema.
3 properties
ObservabilityPipelineDedupeProcessorType
string
The processor type. The value should always be dedupe.
ObservabilityPipelineSampleProcessorType
string
The processor type. The value should always be sample.
ObservabilityPipelineEnrichmentTableProcessorType
string
The processor type. The value should always be enrichmenttable.
HistoricalJobDataType
string
Type of payload.
ObservabilityPipelineSentinelOneDestinationRegion
string
The SentinelOne region to send logs to.
SecurityMonitoringRuleSeverity
string
Severity of the Security Signal.
RelationshipArray
array
Relationships.
ApplicationKeyRelationships
object
Resources related to the application key.
1 property
LeakedKey
object
The definition of LeakedKey object.
3 properties 3 required
ObservabilityPipelineSyslogSourceMode
string
Protocol used by the syslog source to receive messages.
FindingResourceDiscoveryDate
integer
The date on which the resource was discovered (Unix ms).
VulnerabilityType
string
The vulnerability type.
ObservabilityPipelineAddEnvVarsProcessorType
string
The processor type. The value should always be addenvvars.
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptions
object
Controls how partial redaction is applied, including character count and direction.
2 properties 2 required
ObservabilityPipelineGeneratedMetricIncrementByField
object
Strategy that increments a generated metric based on the value of a log field.
2 properties 2 required
ObservabilityPipelineSplunkHecDestinationType
string
The destination type. Always splunkhec.
SensitiveDataScannerGroupData
object
A scanning group data.
1 property
ApplicationSecurityWafExclusionFilterResource
object
A JSON:API resource for an WAF exclusion filter.
3 properties
VulnerabilityStatus
string
The vulnerability status.
GCPSTSServiceAccountsResponse
object
Object containing all your STS enabled accounts.
1 property
DashboardType
string
The type of the dashboard.
MetricsAndMetricTagConfigurations
Object for a metrics and metric tag configurations.
AzureUCConfigPairAttributes
object
Attributes for Azure config pair.
2 properties 1 required
ObservabilityPipelineGeneratedMetricIncrementByOneStrategy
string
Increments the metric by 1 for each matching event.
ObservabilityPipelineSyslogNgSource
object
The syslogng source listens for logs over TCP or UDP from a syslog-ng server using the syslog protocol.
4 properties 3 required
SensitiveDataScannerGroupAttributes
object
Attributes of the Sensitive Data Scanner group.
5 properties
WorkflowListInstancesResponseMeta
object
Metadata about the instances list
1 property
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
SensitiveDataScannerRuleRelationships
object
Relationships of a scanning rule.
2 properties
SecurityMonitoringSignalsListResponseLinks
object
Links attributes.
1 property
RelationToEntity
object
Relation to entity.
2 properties
ObservabilityPipelineAmazonOpenSearchDestinationAuthStrategy
string
The authentication strategy to use.
RUMEventType
string
Type of the event.
MicrosoftSentinelDestination
object
The microsoftsentinel destination forwards logs to Microsoft Sentinel.
7 properties 7 required
CloudConfigurationRegoRule
object
Rule details.
2 properties 2 required
MetricMetaPageType
string
Type of metric pagination.
ListAppsResponseMeta
object
Pagination metadata.
1 property
SensitiveDataScannerGetConfigResponse
object
Get all groups response.
3 properties
GetResourceEvaluationFiltersResponseData
object
The definition of GetResourceFilterResponseData object.
3 properties
RoleResponseRelationships
object
Relationships of the role object returned by the API.
1 property
ObservabilityPipelineGeneratedMetricMetricType
string
Type of metric to create.
EntityV3ServiceSpec
object
The definition of Entity V3 Service Spec object.
6 properties
ObservabilityPipelineAddEnvVarsProcessorVariable
object
Defines a mapping between an environment variable and a log field.
2 properties 2 required
SpansAggregateResponseStatus
string
The status of the response.
FindingType
string
The JSON:API type for findings.
ObservabilityPipelineSensitiveDataScannerProcessorScope
Determines which parts of the log the pattern-matching rule should be applied to.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExclude
object
Excludes specific fields from sensitive data scanning.
2 properties 2 required
OutcomesResponseLinks
object
Links attributes.
1 property
IncidentRespondersType
string
The incident responders type.
EntityV3Queue
object
Schema for queue entities.
7 properties 3 required
CIAppResponseMetadataWithPagination
object
The metadata associated with a request.
5 properties
RelationshipToRule
object
Scorecard create rule response relationship.
1 property
SecurityMonitoringRuleImpossibleTravelOptions
object
Options on impossible travel detection method.
1 property
ApmRetentionFilterType
string
The type of the resource.
GetResourceEvaluationFiltersResponse
object
The definition of GetResourceEvaluationFiltersResponse object.
1 property 1 required
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties 2 required
OktaAccountAttributes
object
Attributes object for an Okta account.
6 properties 3 required
AzureUCConfigPairType
string
Type of Azure config pair.
ObservabilityPipelineQuotaProcessorType
string
The processor type. The value should always be quota.
ApplicationSecurityWafExclusionFilterType
string
Type of the resource. The value should always be exclusionfilter.
ListDevicesResponseMetadataPage
object
Pagination object.
1 property
ApplicationSecurityWafCustomRuleAttributes
object
A WAF custom rule.
9 properties 5 required
Role
object
Role object returned by the API.
4 properties 1 required
IncidentTeamResponseData
object
Incident Team data from a response.
4 properties
CloudConfigurationComplianceRuleOptions
object
Options for cloudconfiguration rules. Fields resourceType and regoRule are mandatory when managing custom cloudconfiguration rules.
3 properties
SensitiveDataScannerConfigurationRelationships
object
Relationships of the configuration.
1 property
ObservabilityPipelineReduceProcessorType
string
The processor type. The value should always be reduce.
EntityResponseIncludedRelatedEntityMeta
object
Included related entity meta.
4 properties
ObservabilityPipelineParseJSONProcessorType
string
The processor type. The value should always be parsejson.
AuthNMappingsType
string
AuthN Mappings resource type.
SensitiveDataScannerGetConfigIncludedArray
array
Included objects from relationships.
AWSLogsServicesResponseAttributes
object
AWS Logs Services response body
1 property 1 required
AuditLogsResponseLinks
object
Links attributes.
1 property
IncidentNonDatadogCreator
object
Incident's non Datadog creator.
2 properties
ObservabilityPipelineTls
object
Configuration for enabling TLS encryption between the pipeline component and external services.
3 properties 1 required
MetricName
string
The metric name for this resource.
RuleUser
object
User creating or modifying a rule.
2 properties
SAMLAssertionAttributesType
string
SAML assertion attributes resource type.
OutcomesResponseDataItem
object
A single rule outcome.
4 properties
EntityRelationships
object
Entity relationships.
5 properties
DORAListFailuresRequestDataType
string
The definition of DORAListFailuresRequestDataType object.
FindingResource
string
The resource name of this finding.
IncidentServiceIncludedItems
An object related to an incident service which is present in the included payload.
EntityV3DatadogEvents
array
Events associations.
ObservabilityPipelineEnrichmentTableFileSchemaItemsType
string
Declares allowed data types for enrichment table columns.
ObservabilityPipelineDatadogLogsDestination
object
The datadoglogs destination forwards logs to Datadog Log Management.
3 properties 3 required
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternOptions
object
Options for defining a custom regex pattern.
1 property 1 required
CloudflareAccountType
string
The JSON:API type for this API. Should always be cloudflare-accounts.
ObservabilityPipelineRenameFieldsProcessorField
object
Defines how to rename a field in log events.
3 properties 3 required
RelationshipToRoles
object
Relationship to roles.
1 property
MetricTagConfiguration
object
Object for a single metric tag configuration.
3 properties
ObservabilityPipelineAwsAuth
object
AWS authentication credentials used for accessing AWS services such as S3. If omitted, the system’s default credentials are used (for example, the IAM role and…
3 properties
ObservabilityPipelineConfigProcessorItem
A processor for the pipeline.
EntityV3SystemKind
string
The definition of Entity V3 System Kind object.
SecurityMonitoringRuleNewValueOptionsLearningMethod
string
The learning method used to determine when signals should be generated for values that weren't learned.
Pagination
object
Pagination object.
2 properties
SensitiveDataScannerGroupRelationships
object
Relationships of the group.
2 properties
SecurityMonitoringRuleCaseAction
object
Action to perform when a signal is triggered. Only available for Application Security rule type.
2 properties
ObservabilityPipelineAddEnvVarsProcessor
object
The addenvvars processor adds environment variable values to log events.
5 properties 5 required
ObservabilityPipelineSensitiveDataScannerProcessorPattern
Pattern detection configuration for identifying sensitive data using either a custom regex or a library reference.
ObservabilityPipelineSyslogNgSourceType
string
The source type. The value should always be syslogng.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedact
object
Configuration for completely redacting matched sensitive data.
2 properties 2 required
ObservabilityPipelineReduceProcessor
object
The reduce processor aggregates and merges logs based on matching keys and merge strategies.
6 properties 6 required
ObservabilityPipelineGenerateMetricsProcessorType
string
The processor type. Always generatedatadogmetrics.
GCPSTSServiceAccount
object
Info on your service account.
4 properties
ObservabilityPipelineParseGrokProcessorRuleSupportRule
object
The Grok helper rule referenced in the parsing rules.
2 properties 2 required
RelationshipToOutcomeData
object
The JSON:API relationship to an outcome, which returns the related rule id.
2 properties
AssetType
string
The asset type
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
VulnerabilitySeverity
string
The vulnerability severity.
EntityV3QueueKind
string
The definition of Entity V3 Queue Kind object.
DORAListResponse
object
Response for the DORA list endpoints.
1 property
Vulnerability
object
A single vulnerability
4 properties 4 required
SecurityMonitoringRuleCase
object
Case when signal is generated.
5 properties
MetricSuggestedTagsAndAggregations
object
Object for a single metric's actively queried tags and aggregations.
3 properties
IncidentAttachmentsResponseIncludedItem
An object related to an attachment that is included in the response.
ObservabilityPipelineOcsfMapperProcessor
object
The ocsfmapper processor transforms logs into the OCSF schema using a predefined mapping configuration.
5 properties 5 required
ApplicationSecurityWafExclusionFiltersResponse
object
Response object for multiple WAF exclusion filters.
1 property
ObservabilityPipelineSplunkTcpSourceType
string
The source type. Always splunktcp.
MonitorType
object
Attributes from the monitor that triggered the event.
11 properties
SecurityMonitoringFilter
object
The rule's suppression filter.
2 properties
ApplicationSecurityWafExclusionFilterRulesTarget
object
Target WAF rules based either on an identifier or tags.
2 properties
EntityResponseIncludedRawSchemaAttributes
object
Included raw schema attributes.
1 property
AWSAccountPartition
string
AWS partition your AWS account is scoped to. Defaults to aws. See [Partitions](https://docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/pa…
RolesType
string
Roles type.
MetricCustomTimeAggregation
string
A time aggregation for use in query.
AuthNMappingAttributes
object
Attributes of AuthN Mapping.
5 properties
ObservabilityPipelineKafkaSourceType
string
The source type. The value should always be kafka.
RelationshipToPermissions
object
Relationship to multiple permissions objects.
1 property
EntityData
object
Entity data.
5 properties
FindingRule
object
The rule that triggered this finding.
2 properties
IncidentTeamRelationships
object
The incident team's relationships.
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationStorageClass
string
Storage class used for objects stored in GCS.
ObservabilityPipelineConfig
object
Specifies the pipeline's configuration, including its sources, processors, and destinations.
3 properties 2 required
IncidentTodoListResponse
object
Response with a list of incident todos.
3 properties 1 required
RelationMeta
object
Relation metadata.
4 properties
RUMEventAttributes
object
JSON object containing all event attributes and their associated values.
4 properties
SensitiveDataScannerStandardPattern
object
Data containing the standard pattern id.
2 properties
UsersType
string
Users resource type.
SensitiveDataScannerConfiguration
object
A Sensitive Data Scanner configuration.
2 properties
ObservabilityPipelineRemoveFieldsProcessorType
string
The processor type. The value should always be removefields.
AwsCURConfigType
string
Type of AWS CUR config.
RUMApplicationListType
string
RUM application list type.
ApplicationSecurityWafCustomRuleTagsCategory
string
The category of the WAF Rule, can be either businesslogic, attackattempt or securityresponse.
EntityToRawSchema
object
Entity to raw schema relationship.
1 property
IncidentTypeListResponse
object
Response with a list of incident types.
1 property 1 required
IncidentTodoResponseIncludedItem
An object related to an incident todo that is included in the response.
ObservabilityPipelineSumoLogicSource
object
The sumologic source receives logs from Sumo Logic collectors.
2 properties 2 required
EntityV3APIVersion
string
The schema version of entity type. The field is known as schema-version in the previous version.
ObservabilityPipelineHttpClientSourceAuthStrategy
string
Optional authentication strategy for HTTP requests.
EntityV3DatadogEventItem
object
Events association item.
2 properties
AuthNMappingsResponse
object
Array of AuthN Mappings response.
3 properties
EventsListResponse
object
The response object with all events matching the request and pagination information.
3 properties
PermissionAttributes
object
Attributes of a permission.
7 properties
VulnerabilityRisks
object
Vulnerability risks.
5 properties 4 required
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
ObservabilityPipelineOcsfMapperProcessorMapping
object
Defines how specific events are transformed to OCSF using a mapping configuration.
2 properties 2 required
MicrosoftSentinelDestinationType
string
The destination type. The value should always be microsoftsentinel.
RelationshipToOutcome
object
The JSON:API relationship to a scorecard outcome.
1 property
ObservabilityPipelineQuotaProcessorLimit
object
The maximum amount of data or number of events allowed before the quota is enforced. Can be specified in bytes or events.
2 properties 2 required
ResourceFilterAttributes
object
Attributes of a resource filter.
2 properties 1 required
NotificationRule
object
Notification rules allow full control over notifications generated by the various Datadog security products. They allow users to define the conditions under wh…
3 properties 3 required
SecurityMonitoringRuleThirdPartyOptions
object
Options on third party detection method.
4 properties
ListAppsResponse
object
A paginated list of apps matching the specified filters and sorting.
3 properties
ListPipelinesResponse
object
Represents the response payload containing a list of pipelines and associated metadata.
2 properties 1 required
ListFindingsData
array
Array of findings.
ListExternalUsersResponse
object
List users response object.
5 properties
EntityV3ServiceDatadog
object
Datadog product integrations for the service entity.
5 properties
SlackIntegrationMetadata
object
Incident integration metadata for the Slack integration.
1 property 1 required
IncidentIntegrationMetadataResponseIncludedItem
An object related to an incident integration metadata that is included in the response.
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties 2 required
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property 1 required
ApplicationSecurityWafCustomRuleConditionOperator
string
Operator to use for the WAF Condition.
EventsResponseMetadataPage
object
Pagination attributes.
1 property
IncidentTodoResponseData
object
Incident todo response data.
4 properties 2 required
GetInterfacesData
object
The interfaces list data
3 properties
EntityToRelatedEntities
object
Entity to related entities relationship.
1 property
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties 2 required
ListEntityCatalogResponseIncludedItem
List entity response included item.
AuditLogsEvent
object
Object description of an Audit Logs event after it is processed and stored by Datadog.
3 properties
MetricTagConfigurationMetricTypes
string
The metric's type.
SensitiveDataScannerTextReplacement
object
Object describing how the scanned event will be replaced.
3 properties
AssetVersion
object
Asset version.
2 properties
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties 2 required
SecurityMonitoringRuleCaseActionType
string
The action type.
ObservabilityPipelineSampleProcessor
object
The sample processor allows probabilistic sampling of logs at a fixed rate.
6 properties 4 required
CIAppPipelineEventsResponse
object
Response object with all pipeline events matching the request and pagination information.
3 properties
EntityV3API
object
Schema for API entities.
7 properties 3 required
FastlyService
object
The schema representation of a Fastly service.
2 properties 1 required
ObservabilityPipelineData
object
Contains the pipeline’s ID, type, and configuration attributes.
3 properties 3 required
MetricsListResponseLinks
object
Pagination links. Only present if pagination query parameters were provided.
5 properties
OrgConfigType
string
Data type of an Org Config.
AWSAccountResponseData
object
AWS Account response data.
3 properties 2 required
DashboardListItemRequest
object
A dashboard within a list.
2 properties 2 required
ApplicationSecurityWafCustomRuleActionAction
string
Override the default action to take when the WAF custom rule would block.
SensitiveDataScannerGroupIncludedItem
object
A Scanning Group included item.
4 properties
RelationshipToTeam
object
Relationship to team.
1 property
WorkflowInstanceListItem
object
An item in the workflow instances list.
1 property
EntityV3SystemSpec
object
The definition of Entity V3 System Spec object.
3 properties
RelationshipToRole
object
Relationship to role.
1 property
RuleType
string
The JSON:API type for scorecard rules.
WorkflowListInstancesResponse
object
Response returned when listing workflow instances.
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationAcl
string
Access control list setting for objects written to the bucket.
SecurityMonitoringSignalsListResponseMeta
object
Meta attributes.
1 property
MetricTagConfigurationAttributes
object
Object containing the definition of a metric tag configuration attributes.
7 properties
ObservabilityPipelineGoogleChronicleDestinationType
string
The destination type. The value should always be googlechronicle.
DashboardListDeleteItemsResponse
object
Response containing a list of deleted dashboards.
1 property
RUMEvent
object
Object description of a RUM event after being processed and stored by Datadog.
3 properties
ObservabilityPipelineDedupeProcessor
object
The dedupe processor removes duplicate fields in log events.
6 properties 6 required
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
ObservabilityPipelineGoogleChronicleDestinationEncoding
string
The encoding format for the logs sent to Chronicle.
NotificationRulesType
string
The rule type associated to notification rules.
ObservabilityPipelineSensitiveDataScannerProcessorScopeInclude
object
Includes only specific fields for sensitive data scanning.
2 properties 2 required
ObservabilityPipelineAmazonS3DestinationType
string
The destination type. Always amazons3.
EntityV3Datastore
object
Schema for datastore entities.
7 properties 3 required
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties 2 required
FindingID
string
The unique ID for this finding.
IncidentServiceType
string
Incident service resource type.
ObservabilityPipelineFilterProcessorType
string
The processor type. The value should always be filter.
MSTeamsIntegrationMetadata
object
Incident integration metadata for the Microsoft Teams integration.
1 property 1 required
SensitiveDataScannerProduct
string
Datadog product onto which Sensitive Data Scanner can be activated.
SecurityMonitoringThirdPartyRuleCaseCreate
object
Case when a signal is generated by a third party rule.
4 properties 1 required
RelationshipToRuleData
object
Relationship data for a rule.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorScopeExcludeTarget
string
Excludes specific fields from processing.
FindingMuteReason
string
The reason why this finding is muted or unmuted.
ApplicationSecurityWafExclusionFilterRulesTargetTags
object
Target multiple WAF rules based on their tags.
2 properties
Creator
object
Creator of the object.
3 properties
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
EntityResponseMeta
object
Entity metadata.
2 properties
SecurityMonitoringSignal
object
Object description of a security signal.
3 properties
MetricIngestedIndexedVolumeAttributes
object
Object containing the definition of a metric's ingested and indexed volume.
2 properties
ObservabilityPipelineParseGrokProcessorRule
object
A Grok parsing rule used in the parsegrok processor. Each rule defines how to extract structured fields from a specific log field using Grok patterns.
3 properties 3 required
MetricSuggestedAggregations
array
List of aggregation combinations that have been actively queried.
RuleTypes
array
Security rule types used as filters in security rules.
MetricAllTags
object
Object for a single metric's indexed tags.
3 properties
CalculatedField
object
Calculated field.
2 properties 2 required
AuditLogsEventsResponse
object
Response object with all events matching the request and pagination information.
3 properties
SensitiveDataScannerFilter
object
Filter for the Scanning Group.
1 property
AWSNamespacesResponseAttributes
object
AWS Namespaces response attributes.
1 property 1 required
ObservabilityPipelineGeneratedMetricIncrementByOne
object
Strategy that increments a generated metric by one for each matching event.
1 property 1 required
AwsCURConfigAttributes
object
Attributes for An AWS CUR config.
12 properties 6 required
ListPipelinesResponseMeta
object
Metadata about the response.
1 property
ListRulesResponseData
array
Array of rule details.
SecurityMonitoringSignalRuleResponseQuery
object
Query for matching rule on signals.
9 properties
ObservabilityPipelineNewRelicDestinationRegion
string
The New Relic region.
EntityV3APIKind
string
The definition of Entity V3 API Kind object.
AuthNMappingTeam
object
Team.
3 properties
SecurityMonitoringSignalsSort
string
The sort parameters used for querying security signals.
GCPServiceAccountType
string
The type of account.
ObservabilityPipelineEnrichmentTableFileEncoding
object
File encoding format.
3 properties 3 required
EventsWarning
object
A warning message indicating something is wrong with the query.
3 properties
IncidentIntegrationMetadataMetadata
Incident integration metadata's metadata attribute.
ApplicationSecurityWafCustomRuleMetadata
object
Metadata associated with the WAF Custom Rule.
6 properties
EntityV3APIDatadog
object
Datadog product integrations for the API entity.
5 properties
ScorecardType
string
The JSON:API type for scorecard.
RestrictionQueryRoleAttribute
object
Attributes of the role for a restriction query.
1 property
ListEntityCatalogResponseIncluded
array
List entity response included.
SpansListResponse
object
Response object with all spans matching the request and pagination information.
3 properties
UserResponseRelationships
object
Relationships of the user object returned by the API.
4 properties
SecurityMonitoringSignalsListResponse
object
The response object with all security signals matching the request and pagination information.
3 properties
SpansListResponseLinks
object
Links attributes.
1 property
AssetEntityType
string
The JSON:API type.
ObservabilityPipelineEnrichmentTableFileSchemaItems
object
Describes a single column and its type in an enrichment table schema.
2 properties 2 required
ObservabilityPipelineNewRelicDestinationType
string
The destination type. The value should always be newrelic.
ExternalUserNameType
object
The components of user's real name
1 property
HistoricalJobResponseData
object
Historical job response data.
3 properties
GCPServiceAccountMeta
object
Additional information related to your service account.
1 property
MetricAllTagsResponse
object
Response object that includes a single metric's indexed tags.
1 property
SecurityMonitoringRuleCaseCreate
object
Case when signal is generated.
5 properties 1 required
ApplicationSecurityWafExclusionFilterAttributes
object
Attributes describing a WAF exclusion filter.
11 properties
RelationType
string
Supported relation types.
TagsEventAttribute
array
Array of tags associated with your event.
RelationResponseData
array
Array of relation responses
CloudflareAccountsResponse
object
The expected response schema when getting Cloudflare accounts.
1 property
Budget
object
A budget.
3 properties
AzureUCConfigsResponse
object
List of Azure accounts with configs.
1 property
ApplicationSecurityWafExclusionFilterMetadata
object
Extra information about the exclusion filter.
6 properties
FastlyAccountsResponse
object
The expected response schema when getting Fastly accounts.
1 property
AuthNMappingsSort
string
Sorting options for AuthN Mappings.
Span
object
Object description of a spans after being processed and stored by Datadog.
3 properties
ObservabilityPipelineSyslogNgDestination
object
The syslogng destination forwards logs to an external syslog-ng server over TCP or UDP using the syslog protocol.
5 properties 3 required
VulnerabilityRelationships
object
Related entities object.
1 property 1 required
DeviceAttributes
object
The device attributes
20 properties
SlackIntegrationMetadataChannelItem
object
Item in the Slack integration metadata channel array.
4 properties 3 required
ObservabilityPipelineEnrichmentTableFileKeyItems
object
Defines how to map log fields to enrichment table columns during lookups.
3 properties 3 required
EntityV3APISpecInterface
The API definition.
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactAction
string
Action type that redacts part of the sensitive data while preserving a configurable number of characters, typically used for masking purposes (e.g., show last…
Organization
object
Organization object.
3 properties 1 required
EntityV3DatadogCodeLocationItem
object
Code location item.
2 properties
Metric
object
Object for a single metric tag configuration.
2 properties
MetricSuggestedTagsAttributes
object
Object containing the definition of a metric's actively queried tags and aggregations.
2 properties
SecurityMonitoringRuleImpossibleTravelOptionsBaselineUserLocations
boolean
If true, signals are suppressed for the first 24 hours. In that time, Datadog learns the user's regular access locations. This can be helpful to reduce noise a…
ExternalUserMeta
object
Metadata associated with a user.
4 properties
ObservabilityPipelineDatadogAgentSource
object
The datadogagent source collects logs from the Datadog Agent.
3 properties 2 required
RelationshipToUsers
object
Relationship to users.
1 property 1 required
ObservabilityPipelineHttpServerSourceType
string
The source type. The value should always be httpserver.
VulnerabilityCvss
object
Vulnerability severities.
2 properties 2 required
OutcomeType
string
The JSON:API type for an outcome.
OutcomesResponse
object
Scorecard outcomes - the result of a rule for a service.
3 properties
ConfluentResourceResponseData
object
Confluent Cloud resource data.
3 properties 3 required
NullableRelationshipToUserData
object
Relationship to user object.
2 properties 2 required
AppMeta
object
Metadata of an app.
9 properties
ListAPIsResponse
object
Response for ListAPIs.
2 properties
PermissionsType
string
Permissions resource type.
EntityToSchema
object
Entity to detail schema relationship.
1 property
ApplicationKeyResponseMetaPage
object
Additional information related to the application key response.
1 property
SecurityMonitoringSignalRuleType
string
The rule type.
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternOptions
object
Options for selecting a predefined library pattern and enabling keyword support.
2 properties 1 required
ObservabilityPipelineAmazonS3DestinationStorageClass
string
S3 storage class.
PartialApplicationKey
object
Partial Datadog application key.
4 properties
EventType
string
Type of the event.
Links
object
The JSON:API links related to pagination.
5 properties 3 required
ObservabilityPipelineDecoding
string
The decoding format used to interpret incoming logs.
RelationshipItem
object
Relationship entry.
2 properties
IncidentTodoAnonymousAssignee
object
Anonymous assignee entity.
4 properties 4 required
EntityResponseIncludedRelatedOncallEscalationItem
object
Oncall escalation.
3 properties
EntityV3DatadogCodeLocations
array
Schema for mapping source code locations to an entity.
CustomCostsFileListResponse
object
Response for List Custom Costs files.
2 properties
CIAppEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
IncidentAttachmentAttachmentType
string
The type of the incident attachment attributes.
ListAppsResponseMetaPage
object
Information on the total number of apps, to be used for pagination.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactOptions
object
Configuration for fully redacting sensitive data.
1 property 1 required
GetInterfacesResponse
object
The GetInterfaces operation's response.
1 property
CIAppSort
string
Sort parameters when querying events.
RuleAttributes
object
Details of a rule.
9 properties
EntityResponseIncludedOncallType
string
Oncall type.
MetricTagConfigurationResponse
object
Response object which includes a single metric's tag configuration.
1 property
DashboardListItems
object
Dashboards within a list.
2 properties 1 required
IncidentTypeType
string
Incident type resource type.
DashboardListAddItemsResponse
object
Response containing a list of added dashboards.
1 property
IncidentAttachmentData
object
A single incident attachment.
4 properties 4 required
EntityV3APISpec
object
The definition of Entity V3 API Spec object.
5 properties
FindingEvaluation
string
The evaluation of the finding.
RUMWarning
object
A warning message indicating something that went wrong with the query.
3 properties
IncidentIntegrationMetadataAttributes
object
Incident integration metadata's attributes for a create request.
6 properties 2 required
SensitiveDataScannerGroup
object
A scanning group.
2 properties
Advisory
object
Advisory.
3 properties 2 required
ObservabilityPipelineConfigDestinationItem
A destination for the pipeline.
MetricVolumesResponse
object
Response object which includes a single metric's volume.
1 property
IncidentServiceResponseData
object
Incident Service data from responses.
4 properties 2 required
OutcomesResponseIncludedItem
object
Attributes of the included rule.
3 properties
DevicesListData
object
The devices list data
3 properties
AWSAccountTags
array
Tags to apply to all hosts and metrics reporting for this account. Defaults to [].
EntityV3DatastoreSpec
object
The definition of Entity V3 Datastore Spec object.
4 properties
AWSAuthConfigRole
object
AWS Authentication config to integrate your account using an IAM role.
2 properties 1 required
ObservabilityPipelineGoogleCloudStorageDestination
object
The googlecloudstorage destination stores logs in a Google Cloud Storage (GCS) bucket. It requires a bucket name, GCP authentication, and metadata fields.
9 properties 7 required
SecurityMonitoringRuleTypeRead
string
The rule type.
IncidentTeamType
string
Incident Team resource type.
BudgetArray
object
An array of budgets.
1 property
ObservabilityPipelineConfigSourceItem
A data source for the pipeline.
ListEntityCatalogResponseLinks
object
List entity response links.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorAction
Defines what action to take when sensitive data is matched.
ObservabilityPipelineNewRelicDestination
object
The newrelic destination sends logs to the New Relic platform.
4 properties 4 required
ObservabilityPipelineHttpServerSourceAuthStrategy
string
HTTP authentication method.
ObservabilityPipelineSensitiveDataScannerProcessorCustomPattern
object
Defines a custom regex-based pattern for identifying sensitive data in logs.
2 properties 2 required
SecurityMonitoringRuleMaxSignalDuration
integer
A signal will "close" regardless of the query being matched once the time exceeds the maximum duration. This time is calculated from the first seen timestamp.
ObservabilityPipelineFluentdSource
object
The fluentd source ingests logs from a Fluentd-compatible service.
3 properties 2 required
ApplicationSecurityWafCustomRuleAction
object
The definition of ApplicationSecurityWafCustomRuleAction object.
2 properties
ObservabilityPipelineFluentBitSource
object
The fluentbit source ingests logs from Fluent Bit.
3 properties 2 required
AssetRisks
object
Asset risks.
5 properties 1 required
IncidentIntegrationRelationships
object
The incident's integration relationships from a response.
2 properties
RestrictionQueryRole
object
Partial role object.
3 properties
OutcomesResponseIncluded
array
Array of rule details.
InterfaceAttributesStatus
string
The interface status
EntityV3DatadogLogItem
object
Log association item.
2 properties
AWSLogsConfig
object
AWS Logs Collection config.
1 property
RelationshipToSAMLAssertionAttributeData
object
Data of AuthN Mapping relationship to SAML Assertion Attribute.
2 properties 2 required
MetricCustomAggregation
object
A time and space aggregation combination for use in query.
2 properties 2 required
UserAttributes
object
Attributes of user object returned by the API.
12 properties
MetricVolumes
Possible response objects for a metric's volume.
SensitiveDataScannerTextReplacementType
string
Type of the replacement text. None means no replacement. hash means the data will be stubbed. replacementstring means that one can chose a text to replace the…
ListAPIsResponseMeta
object
Metadata for ListAPIsResponse.
1 property
ApplicationSecurityWafCustomRuleConditionParameters
object
The scope of the WAF custom rule.
6 properties 1 required
SecurityMonitoringRuleQueryAggregation
string
The aggregation type.
SecurityMonitoringRuleResponse
Create a new rule.
IncidentType
string
Incident resource type.
ListTagsResponseData
object
The list tags response data.
3 properties
NotificationRuleAttributes
object
Attributes of the notification rule.
10 properties 9 required
SensitiveDataScannerIncludedKeywordConfiguration
object
Object defining a set of keywords and a number of characters that help reduce noise. You can provide a list of keywords you would like to check within a define…
3 properties 2 required
EntityV3DatadogIntegrationOpsgenie
object
An Opsgenie integration schema.
2 properties 1 required
AzureStorageDestination
object
The azurestorage destination forwards logs to an Azure Blob Storage container.
5 properties 4 required
EntityResponseIncludedRelatedOncallEscalations
array
Oncall escalations.
IncidentIntegrationMetadataResponseData
object
Incident integration metadata from a response.
4 properties 2 required
CIAppTestEvent
object
Object description of test event after being processed and stored by Datadog.
3 properties
IncidentAttachmentType
string
The incident attachment resource type.
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
MetricIngestedIndexedVolume
object
Object for a single metric's ingested and indexed volume.
3 properties
SpansSort
string
Sort parameters when querying spans.
ListApplicationKeysResponse
object
Response for a list of application keys.
3 properties
BudgetAttributes
object
The attributes of a budget.
11 properties
ApplicationSecurityWafCustomRuleCondition
object
One condition of the WAF Custom Rule.
2 properties 2 required
RoleAttributes
object
Attributes of the role.
4 properties
ObservabilityPipelineHttpServerSource
object
The httpserver source collects logs over HTTP POST from external services.
5 properties 4 required
OktaAccountType
string
Account type for an Okta account.
SensitiveDataScannerGetConfigIncludedItem
An object related to the configuration.
IncidentAttachmentsResponse
object
The response object containing an incident's attachments.
2 properties 1 required
User
object
User object returned by the API.
4 properties
ObservabilityPipelineOpenSearchDestinationType
string
The destination type. The value should always be opensearch.
EntityV3DatastoreKind
string
The definition of Entity V3 Datastore Kind object.
DashboardListItem
object
A dashboard within a list.
14 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessor
object
The sensitivedatascanner processor detects and optionally redacts sensitive data in log events.
5 properties 5 required
AuthNMapping
object
The AuthN Mapping object returned by API.
4 properties 2 required
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property 1 required
ObservabilityPipelineDatadogLogsDestinationType
string
The destination type. The value should always be datadoglogs.
ObservabilityPipelineSensitiveDataScannerProcessorType
string
The processor type. The value should always be sensitivedatascanner.
ObservabilityPipelineKafkaSourceSasl
object
Specifies the SASL mechanism for authenticating with a Kafka cluster.
1 property
ObservabilityPipelineSplunkHecDestination
object
The splunkhec destination forwards logs to Splunk using the HTTP Event Collector (HEC).
7 properties 3 required
EntityResponseIncludedRelatedEntity
object
Included related entity.
4 properties
EntityV3Integrations
object
A base schema for defining third-party integrations.
2 properties
CustomCostsUser
object
Metadata of the user that has uploaded the Custom Costs file.
3 properties
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property 1 required
IncidentServiceRelationships
object
The incident service's relationships.
2 properties
SecurityMonitoringRuleHardcodedEvaluatorType
string
Hardcoded evaluator type.
RelationshipToUserData
object
Relationship to user object.
2 properties 2 required
SecurityMonitoringStandardDataSource
string
Source of events, either logs, audit trail, or Datadog events.
ObservabilityPipelineGooglePubSubSourceType
string
The source type. The value should always be googlepubsub.
GCPMetricNamespaceConfig
object
Configuration for a GCP metric namespace.
2 properties
AppDefinitionType
string
The app definition type.
CustomCostsFileUsageChargePeriod
object
Usage charge period of a Custom Costs file.
2 properties
IncidentTodoAssignee
A todo assignee.
ListDevicesResponse
object
List devices response.
2 properties
IncidentTodoAssigneeArray
array
Array of todo assignees.
ResourceFilterRequestType
string
Constant string to identify the request type.
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties 2 required
AuditLogsWarning
object
Warning message indicating something that went wrong with the query.
3 properties
ConfluentAccountResponseData
object
An API key and API secret pair that represents a Confluent account.
3 properties 3 required
SpansResponseMetadataPage
object
Paging attributes.
1 property
EmailTypeType
string
The type of email.
RelationEntity
object
Relation entity reference.
3 properties
ObservabilityPipelineGenerateMetricsProcessor
object
The generatedatadogmetrics processor creates custom metrics from logs and sends them to Datadog. Metrics can be counters, gauges, or distributions and optional…
5 properties 5 required
ListRelationCatalogResponseLinks
object
List relation response links.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedact
object
Configuration for partially redacting matched sensitive data.
2 properties 2 required
AssetOperatingSystem
object
Asset operating system.
2 properties 1 required
EntityMeta
object
Entity metadata.
4 properties
FindingTags
array
The tags associated with this finding.
Remediation
object
Vulnerability remediation.
8 properties 8 required
CIAppTestEventsResponse
object
Response object with all test events matching the request and pagination information.
3 properties
ObservabilityPipelineSumoLogicDestination
object
The sumologic destination forwards logs to Sumo Logic.
8 properties 3 required
IncidentUserData
object
User object returned by the API.
3 properties
ObservabilityPipelineMetricValue
Specifies how the value of the generated metric is computed.
EntityResponseIncludedSchemaAttributes
object
Included schema.
1 property
IncidentResponseData
object
Incident data from a response.
4 properties 2 required
RuleOutcomeRelationships
object
The JSON:API relationship to a scorecard rule.
1 property
ObservabilityPipelineQuotaProcessorOverride
object
Defines a custom quota limit that applies to specific log events based on matching field values.
2 properties 2 required
SensitiveDataScannerConfigurationType
string
Sensitive Data Scanner configuration type.
SAMLAssertionAttribute
object
SAML assertion attribute.
3 properties 2 required
MetricsAndMetricTagConfigurationsResponse
object
Response object that includes metrics and metric tag configurations.
3 properties
EntityV3DatadogPerformance
object
Performance stats association.
1 property
AzureUCConfig
object
Azure config.
15 properties 9 required
EntityToIncidents
object
Entity to incidents relationship.
1 property
ObservabilityPipelineRemoveFieldsProcessor
object
The removefields processor deletes specified fields from logs.
5 properties 5 required
DeploymentRelationshipData
object
Data object containing the deployment ID.
2 properties
CIAppPipelineEvent
object
Object description of a pipeline event after being processed and stored by Datadog.
3 properties
IncidentUserDefinedFieldType
string
The incident user defined fields type.
FindingStatus
string
The status of the finding.
CIAppTestLevel
string
Test run level.
SpansFilter
object
The spans filter used to index spans.
1 property
RelationRelationships
object
Relation relationships.
2 properties
IncidentTeamsResponse
object
Response with a list of incident team payloads.
3 properties 1 required
MetricSuggestedTagsAndAggregationsResponse
object
Response object that includes a single metric's actively queried tags and aggregations.
1 property
SensitiveDataScannerRuleIncludedItem
object
A Scanning Rule included item.
4 properties
OrganizationsType
string
Organizations resource type.
EntityV3QueueSpec
object
The definition of Entity V3 Queue Spec object.
4 properties
SecurityMonitoringSignalAttributes
object
The object containing all signal attributes and their associated values.
4 properties
ListRelationCatalogResponse
object
List entity relation response.
4 properties
ApplicationSecurityWafCustomRuleConditionOptions
object
Options for the operator of this condition.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptionsDirection
string
Indicates whether to redact characters from the first or last part of the matched value.
EntityResponseIncludedSchema
object
Included detail entity schema.
3 properties
FindingVulnerabilityType
string
The vulnerability type of the finding.
ObservabilityPipelineAmazonS3Source
object
The amazons3 source ingests logs from an Amazon S3 bucket. It supports AWS authentication and TLS encryption.
5 properties 3 required
ApplicationKeysType
string
Application Keys resource type.
ListFindingsResponse
object
The expected response schema when listing findings.
2 properties 2 required
CIAppPipelineEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
ObservabilityPipelineAddFieldsProcessor
object
The addfields processor adds static key-value fields to logs.
5 properties 5 required
ObservabilityPipelineLogstashSource
object
The logstash source ingests logs from a Logstash forwarder.
3 properties 2 required
AWSNamespaceFiltersIncludeOnly
object
Include only these namespaces.
1 property 1 required
EntityV3DatadogLogs
array
Logs association.
ListVulnerabilitiesResponse
object
The expected response schema when listing vulnerabilities.
3 properties 1 required
ListRelationCatalogResponseIncluded
array
List relation response included entities.
ObservabilityPipelineAddFieldsProcessorType
string
The processor type. The value should always be addfields.
GCPSTSDelegateAccountType
string
The type of account.
SpansListResponseMetadata
object
The metadata associated with a request.
5 properties
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property 1 required
EntityResponseIncludedIncident
object
Included incident.
3 properties
RetentionFilterAllType
string
The type of retention filter.
CloudflareAccountResponseAttributes
object
Attributes object of a Cloudflare account.
4 properties 1 required
ConfluentResourceResponseAttributes
object
Model representation of a Confluent Cloud resource.
4 properties 1 required
ObservabilityPipelineEnrichmentTableFile
object
Defines a static enrichment table loaded from a CSV file.
4 properties 4 required
SensitiveDataScannerStandardPatternsResponseItem
object
Standard pattern item.
3 properties
ObservabilityPipelineAmazonS3Destination
object
The amazons3 destination sends your logs in Datadog-rehydratable format to an Amazon S3 bucket for archiving.
9 properties 6 required
CVSS
object
Vulnerability severity.
3 properties 3 required
DORAListDeploymentsRequest
object
Request to get a list of deployments.
1 property 1 required
ObservabilityPipelineElasticsearchDestinationApiVersion
string
The Elasticsearch API version to use. Set to auto to auto-detect.
CIAppPipelineLevel
string
Pipeline execution level.
TimeAggregation
integer
Time aggregation period (in seconds) is used to aggregate the results of the notification rule evaluation. Results are aggregated over a selected time frame us…
AWSNamespaceFiltersExcludeOnly
object
Exclude only these namespaces from metrics collection. Defaults to ["AWS/SQS", "AWS/ElasticMapReduce"]. AWS/SQS and AWS/ElasticMapReduce are excluded by defaul…
1 property 1 required
ConfluentAccountsResponse
object
Confluent account returned by the API.
1 property
ApplicationSecurityWafCustomRuleTags
object
Tags associated with the WAF Custom Rule. The concatenation of category and type will form the security activity field associated with the traces.
2 properties 2 required
DORAListFailuresRequest
object
Request to get a list of failures.
1 property 1 required
MetricActiveConfigurationType
string
The metric actively queried configuration resource type.
EventAttributes
object
Object description of attributes from your event.
19 properties
ObservabilityPipelineFieldValue
object
Represents a static key-value pair used in various processors.
2 properties 2 required
Date
integer
Date as Unix timestamp in milliseconds.
ObservabilityPipelineDataAttributes
object
Defines the pipeline’s name and its components (sources, processors, and destinations).
2 properties 2 required
ObservabilityPipelineEnrichmentTableProcessor
object
The enrichmenttable processor enriches logs using a static CSV file or GeoIP database.
7 properties 5 required
ApplicationKeyResponseMeta
object
Additional information related to the application key response.
2 properties
MetricAllTagsAttributes
object
Object containing the definition of a metric's tags.
1 property
EntityV3Service
object
Schema for service entities.
7 properties 3 required
EntityResponseIncludedSchemaType
string
Schema type.
ObservabilityPipelineDatadogAgentSourceType
string
The source type. The value should always be datadogagent.
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
IncidentsResponse
object
Response with a list of incidents.
3 properties 1 required
ObservabilityPipelinePipelineKafkaSourceSaslMechanism
string
SASL mechanism used for Kafka authentication.
ObservabilityPipelineFluentBitSourceType
string
The source type. The value should always be fluentbit.
IncidentServiceResponseAttributes
object
The incident service's attributes from a response.
3 properties
RUMSort
string
Sort parameters when querying events.
IncidentImpactsType
string
The incident impacts type.
RelationshipToRoleData
object
Relationship to role object.
2 properties
ListRulesResponse
object
Scorecard rules response.
2 properties
RelationshipToOrganizationData
object
Relationship to organization object.
2 properties 2 required
RolesSort
string
Sorting options for roles.
FastlyAccountResponseData
object
Data object of a Fastly account.
3 properties 3 required
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties 2 required
PartialApplicationKeyAttributes
object
Attributes of a partial application key.
4 properties
EntityV3SystemDatadog
object
Datadog product integrations for the service entity.
4 properties
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPattern
object
Specifies a pattern from Datadog’s sensitive data detection library to match known sensitive data types.
2 properties 2 required
ConfluentAccountType
string
The JSON:API type for this API. Should always be confluent-cloud-accounts.
XRayServicesIncludeOnly
object
Include only these services. Defaults to [].
1 property 1 required
FastlyAccountType
string
The JSON:API type for this API. Should always be fastly-accounts.
ObservabilityPipelineAmazonOpenSearchDestinationAuth
object
Authentication settings for the Amazon OpenSearch destination. The strategy field determines whether basic or AWS-based authentication is used.
5 properties 1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactAction
string
Action type that completely replaces the matched sensitive data with a fixed replacement string to remove all visibility.
ListAppsResponseDataItemsRelationships
object
The app's publication information.
1 property
AWSAccountType
string
AWS Account resource type.
RUMResponseLinks
object
Links attributes.
1 property
IncidentIntegrationMetadataListResponse
object
Response with a list of incident integration metadata.
3 properties 1 required
AuditLogsResponseStatus
string
The status of the response.
EntityResponseIncludedRelatedEntityType
string
Related entity.
AWSTracesConfig
object
AWS Traces Collection config.
1 property
FastlyServicesResponse
object
The expected response schema when getting Fastly services.
1 property
AWSRegionsIncludeOnly
object
Include only these regions.
1 property 1 required
MetricPaginationMeta
object
Response metadata object.
1 property
CIAppTestEventTypeName
string
Type of the event.
ListAPIsResponseData
object
Data envelope for ListAPIsResponse.
2 properties
ApplicationKeysSort
string
Sorting options
SensitiveDataScannerRuleData
object
Rules included in the group.
1 property
ObservabilityPipelineGooglePubSubSource
object
The googlepubsub source ingests logs from a Google Cloud Pub/Sub subscription.
7 properties 6 required
EntityResponseIncludedIncidentType
string
Incident description.
ObservabilityPipelineReduceProcessorMergeStrategyStrategy
string
The merge strategy to apply.
BudgetEntry
object
The entry of a budget.
3 properties
ID
string
The ID of a notification rule.
AuthNMappingTeamAttributes
object
Team attributes.
7 properties
SensitiveDataScannerStandardPatternType
string
Sensitive Data Scanner standard pattern type.
SecurityMonitoringThirdPartyRootQuery
object
A query to be combined with the third party case query.
2 properties
SensitiveDataScannerGroupType
string
Sensitive Data Scanner group type.
FastlyServiceData
object
Data object for Fastly service requests.
3 properties 2 required
VulnerabilityDependencyLocations
object
Static library vulnerability location.
3 properties 1 required
ConfluentAccountResponseAttributes
object
The attributes of a Confluent account.
3 properties 1 required
ObservabilityPipelineOcsfMapperProcessorType
string
The processor type. The value should always be ocsfmapper.
EntityV3ServiceKind
string
The definition of Entity V3 Service Kind object.
RestrictionQueryListResponse
object
Response containing information about multiple restriction queries.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorScopeAll
object
Applies scanning across all available fields.
1 property 1 required
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties 2 required
ListRulesResponseDataItem
object
Rule details.
4 properties
RestrictionQueryRolesResponse
object
Response containing information about roles attached to a restriction query.
1 property
RUMEventsResponse
object
Response object with all events matching the request and pagination information.
3 properties
Asset
object
A single vulnerable asset
3 properties 3 required
Metadata
object
The metadata related to this request.
3 properties 3 required
ObservabilityPipelineKafkaSourceLibrdkafkaOption
object
Represents a key-value pair used to configure low-level librdkafka client options for Kafka sources, such as timeouts, buffer sizes, and security settings.
2 properties 2 required
SecurityMonitoringSignalListRequest
object
The request for a security signal list.
3 properties
MetricDistinctVolumeType
string
The metric distinct volume type.
ApplicationSecurityWafExclusionFilterID
string
The identifier of the WAF exclusion filter.
IncidentSeverity
string
The incident severity.
EntityV3DatadogIntegrationPagerduty
object
A PagerDuty integration schema.
1 property 1 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeOptions
object
Fields to which the scope rule applies.
1 property 1 required
SensitiveDataScannerStandardPatternsResponse
array
List Standard patterns response.
ObservabilityPipelineOpenSearchDestination
object
The opensearch destination writes logs to an OpenSearch cluster.
4 properties 3 required
AppDeploymentType
string
The deployment type.
RUMResponsePage
object
Paging attributes.
1 property
IncidentRelatedObject
string
Object related to an incident.
AWSAuthConfig
AWS Authentication config.
SpansType
string
Type of the span.
SecurityMonitoringStandardRuleResponse
object
Rule.
24 properties
ExternalUserEmailType
object
Email address for the user.
3 properties
TagFilter
object
Tag filter for the budget's entries.
2 properties
SecurityMonitoringRuleDetectionMethod
string
The detection method.
ObservabilityPipelineQuotaProcessor
object
The Quota Processor measures logging traffic for logs that match a specified filter. When the configured daily quota is met, the processor can drop or alert.
11 properties 7 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

datadog-lists-api-openapi.yml Raw ↑

Other APIs Datadog publishes across the network.

Datadog Dashboards API
Datadog Synthetics API
Datadog Service Level Objectives API
Datadog Security Monitoring API
Datadog Service Definition API
Datadog Software Catalog API
Datadog Users API
Datadog Roles API
Datadog Key Management API
Datadog Organizations API
Datadog Downtimes API
Datadog RUM API
Where this information came from

This is an independent, third-party profile of Datadog Lists API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.