How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Datadog Search API

The Search API from Datadog — 10 operation(s) for search.

Datadog Search API is one of 290 APIs that Datadog publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 4 JSON Schema definitions.

Tagged areas include Search. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, an API reference, and 4 JSON Schemas.

This API exposes 10 operations across 10 paths, and defines 187 schemas. It is described by OpenAPI 3.0.0, at version 1.0.

Requests are made against 3 base URLs: https://{subdomain}.{site}, {protocol}://{name}, https://{subdomain}.{site}.

10 operations 10 paths 187 schemas 3 GET7 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
1.0
Base URL
https://api.datadoghq.com
Authentication
OAuth 2.0, API Key, API Key, HTTP Bearer
Resource Areas
1

Authentication & Security 4

Datadog Search API declares 4 security schemes for authenticating requests. It supports OAuth 2.0 (AuthZ) using the authorizationCode flow, exposing 68 scopes. An API key is passed in the header as DD-API-KEY (apiKeyAuth). An API key is passed in the header as DD-APPLICATION-KEY (appKeyAuth). It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

  • AuthZ — This API uses OAuth 2 with the implicit grant flow.
  • apiKeyAuth — Your Datadog API Key.
  • appKeyAuth — Your Datadog APP Key.

Paths & Operations 10

Across 10 paths, the API surfaces 10 operations — 3 GET, 7 POST. Each is listed below with its method, path, parameters, and response codes.

Search 10
POST
/api/v2/audit/events/search
Datadog Search Audit Logs Events
SearchAuditLogs body → 200400403429
GET
/api/v2/cases
Datadog Search Cases
SearchCases 5 params → 200400401403404429
POST
/api/v2/ci/pipelines/events/search
Datadog Search Pipelines Events
SearchCIAppPipelineEvents body → 200400403429
POST
/api/v2/ci/tests/events/search
Datadog Search Tests Events
SearchCIAppTestEvents body → 200400403429
POST
/api/v2/events/search
Datadog Search Events
SearchEvents body → 200400403429
GET
/api/v2/incidents/search
Datadog Search for Incidents
SearchIncidents 5 params → 200400401403404429
GET
/api/v2/logs/events
Datadog Search Logs (get)
ListLogsGet 8 params → 200400403429
POST
/api/v2/logs/events/search
Datadog Search Logs (post)
ListLogs body → 200400403429
POST
/api/v2/rum/events/search
Datadog Search Rum Events
SearchRUMEvents body → 200400403429
POST
/api/v2/spans/events/search
Datadog Search Spans
ListSpans body → 200400403422429

Schemas 187

The contract defines 187 schemas that model the data the API accepts and returns. The most detailed are IncidentResponseAttributes (24 properties), EventAttributes (19 properties), SpansAttributes (17 properties), CaseAttributes (12 properties). Each schema is shown below with its type and property counts.

RUMResponseStatus
string
The status of the response.
JiraIssueResult
object
Jira issue information
4 properties
AuditLogsResponsePage
object
Paging attributes.
1 property
RUMEventAttributes
object
JSON object containing all event attributes and their associated values.
4 properties
UsersType
string
Users resource type.
IncidentAttachmentAttributes
The attributes object for an attachment.
JSONAPIErrorItem
object
API error response body
5 properties
SpansListRequest
object
The request for a spans list.
1 property
IncidentSearchResponse
object
Response with incidents and facets.
3 properties 1 required
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property 1 required
EventResponseAttributes
object
The object description of an event response attribute.
4 properties
IncidentSearchResponseAttributes
object
Attributes returned by an incident search.
3 properties 3 required
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
CasePriority
string
Case priority
EventsRequestPage
object
Pagination settings.
2 properties
SpansListRequestData
object
The object containing the query content.
2 properties
IncidentType
string
Incident resource type.
IncidentIntegrationMetadataType
string
Integration metadata resource type.
EventsListResponse
object
The response object with all events matching the request and pagination information.
3 properties
IncidentSearchResponseIncidentsData
object
Incident returned by the search.
1 property 1 required
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
AuditLogsResponseMetadata
object
The metadata associated with a request.
5 properties
CIAppTestsQueryFilter
object
The search and filter query settings.
3 properties
JSONAPIErrorResponse
object
API error response.
1 property 1 required
LogsStorageTier
string
Specifies storage type as indexes, online-archives or flex
RUMResponseMetadata
object
The metadata associated with a request.
5 properties
CIAppTestEvent
object
Object description of test event after being processed and stored by Datadog.
3 properties
AuditLogsEventType
string
Type of the event.
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
IncidentAttachmentType
string
The incident attachment resource type.
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
IncidentSearchResponseMeta
object
The metadata object containing pagination metadata.
1 property
SpansSort
string
Sort parameters when querying spans.
CaseAttributes
object
Case attributes
12 properties
LogsListRequest
object
The request for a logs list.
4 properties
CaseSortableField
string
Case field that can be sorted on
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties 2 required
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property 1 required
EventsResponseMetadataPage
object
Pagination attributes.
1 property
IncidentSearchResponseNumericFacetData
object
Facet data numeric attributes of an incident.
2 properties 2 required
CIAppPipelineEventTypeName
string
Type of the event.
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties 2 required
RelationshipToUser
object
Relationship to user.
1 property 1 required
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property 1 required
AuditLogsEvent
object
Object description of an Audit Logs event after it is processed and stored by Datadog.
3 properties
CIAppWarning
object
A warning message indicating something that went wrong with the query.
3 properties
RUMSearchEventsRequest
object
The request for a RUM events list.
4 properties
RUMQueryFilter
object
The search and filter query settings.
3 properties
ServiceNowTicket
object
ServiceNow ticket attached to case
2 properties
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties 2 required
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
CIAppTestEventsRequest
object
The request for a tests search.
4 properties
SpansWarning
object
A warning message indicating something that went wrong with the query.
3 properties
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property 1 required
CIAppPipelineEventsResponse
object
Response object with all pipeline events matching the request and pagination information.
3 properties
CasesResponseMeta
object
Cases response metadata
1 property
RelationshipToUserData
object
Relationship to user object.
2 properties 2 required
RUMQueryPageOptions
object
Paging attributes for listing events.
2 properties
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
IncidentResponseMetaPagination
object
Pagination properties.
3 properties
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties 2 required
AuditLogsWarning
object
Warning message indicating something that went wrong with the query.
3 properties
AuditLogsEventAttributes
object
JSON object containing all event attributes and their associated values.
5 properties
EventPriority
string
The priority of the event's monitor. For example, normal or low.
SpansResponseMetadataPage
object
Paging attributes.
1 property
CIAppResponseStatus
string
The status of the response.
LogsResponseMetadataPage
object
Paging attributes.
1 property
SpansListRequestType
string
The type of resource. The value should always be searchrequest.
LogType
string
Type of the event.
EventStatusType
string
If an alert event is enabled, its status is one of the following: failure, error, warning, info, success, userupdate, recommendation, or snapshot.
CIAppTestEventsResponse
object
Response object with all test events matching the request and pagination information.
3 properties
EventsSort
string
The sort parameters when querying events.
IncidentUserData
object
User object returned by the API.
3 properties
RUMQueryOptions
object
Global query options that are used during the query. Note: Only supply timezone or time offset, not both. Otherwise, the query fails.
2 properties
IncidentResponseData
object
Incident data from a response.
4 properties 2 required
CIAppPipelinesQueryFilter
object
The search and filter query settings.
3 properties
RUMEvent
object
Object description of a RUM event after being processed and stored by Datadog.
3 properties
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
LogsSort
string
Sort parameters when querying logs.
CaseRelationships
object
Resources related to a case
4 properties
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties 2 required
CasesResponseMetaPagination
object
Pagination metadata
3 properties
CIAppPipelineEvent
object
Object description of a pipeline event after being processed and stored by Datadog.
3 properties
IncidentUserDefinedFieldType
string
The incident user defined fields type.
CIAppTestLevel
string
Test run level.
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties 2 required
CIAppPipelineEventsRequest
object
The request for a pipelines search.
4 properties
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
CaseResourceType
string
Case resource type
ProjectRelationshipData
object
Relationship to project object
2 properties 2 required
AuditLogsSearchEventsRequest
object
The request for a Audit Logs events list.
4 properties
AuditLogsEventsResponse
object
Response object with all events matching the request and pagination information.
3 properties
Case
object
A case
4 properties 3 required
ServiceNowTicketResult
object
ServiceNow ticket information
1 property
AuditLogsQueryOptions
object
Global query options that are used during the query. Note: Specify either timezone or time offset, not both. Otherwise, the query fails.
2 properties
LogsAggregateResponseStatus
string
The status of the response
IncidentSearchResponseFacetsData
object
Facet data for incidents returned by a search query.
11 properties
CIAppPipelineEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
LogsResponseMetadata
object
The metadata associated with a request
5 properties
CasesResponse
object
Response with cases
2 properties
SpansListRequestAttributes
object
The object containing all the query parameters.
4 properties
EventsWarning
object
A warning message indicating something is wrong with the query.
3 properties
IncidentSearchResponseFacetCount
integer
Count of the facet value appearing in search results.
SpansListResponseMetadata
object
The metadata associated with a request.
5 properties
Event
object
The metadata associated with a request.
4 properties
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property 1 required
APIErrorResponse
object
API error response.
1 property 1 required
SpansListResponse
object
Response object with all spans matching the request and pagination information.
3 properties
SpansQueryOptions
object
Global query options that are used during the query. Note: You should only supply timezone or time offset but not both otherwise the query will fail.
2 properties
SpansListResponseLinks
object
Links attributes.
1 property
EventsQueryOptions
object
The global query options that are used. Either provide a timezone or a time offset but not both, otherwise the query fails.
2 properties
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
AuditLogsQueryPageOptions
object
Paging attributes for listing events.
2 properties
EventResponse
object
The object description of an event after being processed and stored by Datadog.
3 properties
RUMEventType
string
Type of the event.
CIAppPipelineLevel
string
Pipeline execution level.
EventAttributes
object
Object description of attributes from your event.
19 properties
LogsListResponse
object
Response object with all logs matching the request and pagination information.
3 properties
ProjectRelationship
object
Relationship to project
1 property 1 required
TagsEventAttribute
array
Array of tags associated with your event.
SpansAggregateResponseStatus
string
The status of the response.
CIAppQueryOptions
object
Global query options that are used during the query. Only supply timezone or time offset, not both. Otherwise, the query fails.
2 properties
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties 1 required
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
EventsListRequest
object
The object sent with the request to retrieve a list of events from your organization.
4 properties
IncidentRespondersType
string
The incident responders type.
CIAppResponseMetadataWithPagination
object
The metadata associated with a request.
5 properties
NullableUserRelationshipData
object
Relationship to user object.
2 properties 2 required
LogsListResponseLinks
object
Links attributes.
1 property
RUMSort
string
Sort parameters when querying events.
IncidentSearchResponseData
object
Data returned by an incident search.
2 properties
Span
object
Object description of a spans after being processed and stored by Datadog.
3 properties
IncidentSearchResponseFieldFacetData
object
Facet value and number of occurrences for a property field of an incident.
2 properties
IncidentImpactsType
string
The incident impacts type.
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties 2 required
JiraIssue
object
Jira issue attached to case
2 properties
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties 2 required
IncidentSearchResultsType
string
Incident search result type.
Case3rdPartyTicketStatus
string
Case status
LogsListRequestPage
object
Paging attributes for listing logs.
2 properties
LogsQueryOptions
object
Global query options that are used during the query. Note: These fields are currently deprecated and do not affect the query results.
2 properties
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
AuditLogsSort
string
Sort parameters when querying events.
SpansAttributes
object
JSON object containing all span attributes and their associated values.
17 properties
LogsQueryFilter
object
The search and filter query settings
5 properties
EventsResponseMetadata
object
The metadata associated with a request.
5 properties
AuditLogsResponseLinks
object
Links attributes.
1 property
RUMResponseLinks
object
Links attributes.
1 property
AuditLogsResponseStatus
string
The status of the response.
IncidentNonDatadogCreator
object
Incident's non Datadog creator.
2 properties
NullableRelationshipToUserData
object
Relationship to user object.
2 properties 2 required
ProjectResourceType
string
Project resource type
CIAppTestEventTypeName
string
Type of the event.
EventType
string
Type of the event.
CaseStatus
string
Case status
SpansListRequestPage
object
Paging attributes for listing spans.
2 properties
CIAppQueryPageOptions
object
Paging attributes for listing events.
2 properties
CIAppEventAttributes
object
JSON object containing all event attributes and their associated values.
3 properties
LogAttributes
object
JSON object containing all log attributes and their associated values.
7 properties
AuditLogsQueryFilter
object
Search and filter query settings.
3 properties
Log
object
Object description of a log after being processed and stored by Datadog.
3 properties
EventsQueryFilter
object
The search and filter query settings.
3 properties
CIAppResponsePage
object
Paging attributes.
1 property
NullableRelationshipToUser
object
Relationship to user.
1 property 1 required
CIAppSort
string
Sort parameters when querying events.
UserResourceType
string
User resource type.
SpansQueryFilter
object
The search and filter query settings.
3 properties
IncidentSearchSortOrder
string
The ways searched incidents can be sorted.
NullableUserRelationship
object
Relationship to user.
1 property 1 required
LogsWarning
object
A warning message indicating something that went wrong with the query
3 properties
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties 2 required
RUMEventsResponse
object
Response object with all events matching the request and pagination information.
3 properties
IncidentAttachmentData
object
A single incident attachment.
4 properties 4 required
CaseType
string
Case type
IncidentSearchResponsePropertyFieldFacetData
object
Facet data for the incident property fields.
3 properties 2 required
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
EventsListResponseLinks
object
Links attributes.
1 property
MonitorType
object
Attributes from the monitor that triggered the event.
11 properties
RUMWarning
object
A warning message indicating something that went wrong with the query.
3 properties
IncidentSeverity
string
The incident severity.
CIAppResponseLinks
object
Links attributes.
1 property
IncidentSearchResponseNumericFacetDataAggregates
object
Aggregate information for numeric incident data.
2 properties
SpansType
string
Type of the span.
RUMResponsePage
object
Paging attributes.
1 property
IncidentRelatedObject
string
Object related to an incident.
IncidentSearchResponseUserFacetData
object
Facet data for user attributes of an incident.
5 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

datadog-search-api-openapi.yml Raw ↑

Other APIs Datadog publishes across the network.

Datadog Dashboards API
Datadog Synthetics API
Datadog Service Level Objectives API
Datadog Security Monitoring API
Datadog Service Definition API
Datadog Software Catalog API
Datadog Users API
Datadog Roles API
Datadog Key Management API
Datadog Organizations API
Datadog Downtimes API
Datadog RUM API
Where this information came from

This is an independent, third-party profile of Datadog Search API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.