How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Datadog Update API

The Update API from Datadog — 72 operation(s) for update.

Datadog Update API is one of 290 APIs that Datadog publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 4 JSON Schema definitions.

The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, an API reference, and 4 JSON Schemas.

This API exposes 72 operations across 72 paths, and defines 1312 schemas. It is described by OpenAPI 3.0.0, at version 1.0.

Requests are made against 3 base URLs: https://{subdomain}.{site}, {protocol}://{name}, https://{subdomain}.{site}.

72 operations 72 paths 1312 schemas 49 PATCH5 POST18 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
1.0
Base URL
https://api.datadoghq.com
Authentication
OAuth 2.0, API Key, API Key, HTTP Bearer
Resource Areas
1

Authentication & Security 4

Datadog Update API declares 4 security schemes for authenticating requests. It supports OAuth 2.0 (AuthZ) using the authorizationCode flow, exposing 68 scopes. An API key is passed in the header as DD-API-KEY (apiKeyAuth). An API key is passed in the header as DD-APPLICATION-KEY (appKeyAuth). It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

  • AuthZ — This API uses OAuth 2 with the implicit grant flow.
  • apiKeyAuth — Your Datadog API Key.
  • appKeyAuth — Your Datadog APP Key.

Paths & Operations 72

Across 72 paths, the API surfaces 72 operations — 49 PATCH, 5 POST, 18 PUT. Each is listed below with its method, path, parameters, and response codes.

Update 72
PATCH
/api/v2/actions/connections/{connection_id}
Datadog Update an Existing Action Connection
UpdateActionConnection 1 param body → 200400403404429
PUT
/api/v2/apicatalog/api/{id}/openapideprecated
Datadog Update an Api
UpdateOpenAPI 1 param body → 200400403404429
PATCH
/api/v2/apm/config/metrics/{metric_id}
Datadog Update a Span-based Metric
UpdateSpansMetric 1 param body → 200400403404429
PUT
/api/v2/apm/config/retention-filters/{filter_id}
Datadog Update a Retention Filter
UpdateApmRetentionFilter 1 param body → 200400403404429
PATCH
/api/v2/app-builder/apps/{app_id}
Datadog Update App
UpdateApp 1 param body → 200400403429
POST
/api/v2/cases/{case_id}/priority
Datadog Update Case Priority
UpdatePriority 1 param body → 200400401403404429
POST
/api/v2/cases/{case_id}/status
Datadog Update Case Status
UpdateStatus 1 param body → 200400401403404429
POST
/api/v2/catalog/entity
Datadog Create or Update Entities
UpsertCatalogEntity body → 202400403429
PUT
/api/v2/cloud_security_management/custom_frameworks/{handle}/{version}
Datadog Update a Custom Framework
UpdateCustomFramework 2 params body → 200400429500
PUT
/api/v2/cloud_security_management/resource_filters
Datadog Update Resource Filters
UpdateResourceEvaluationFilters body → 201400403429
PATCH
/api/v2/cost/aws_cur_config/{cloud_account_id}
Datadog Update Cloud Cost Management Aws Cur Config
UpdateCostAWSCURConfig 1 param body → 200403429
PATCH
/api/v2/cost/azure_uc_config/{cloud_account_id}
Datadog Update Cloud Cost Management Azure Config
UpdateCostAzureUCConfigs 1 param body → 200400403429
PUT
/api/v2/cost/budget
Datadog Create or Update a Budget
UpsertBudget body → 200400404429
PUT
/api/v2/dashboard/lists/manual/{dashboard_list_id}/dashboards
Datadog Update Items of a Dashboard List
UpdateDashboardListItems 1 param body → 200400403404429
PATCH
/api/v2/downtime/{downtime_id}
Datadog Update a Downtime
UpdateDowntime 1 param body → 200400403404429
PATCH
/api/v2/incidents/config/types/{incident_type_id}
Datadog Update an Incident Type
UpdateIncidentType 1 param body → 200400401403404429
PATCH
/api/v2/incidents/{incident_id}
Datadog Update an Existing Incident
UpdateIncident 2 params body → 200400401403404429
PATCH
/api/v2/incidents/{incident_id}/attachments
Datadog Create, Update, and Delete Incident Attachments
UpdateIncidentAttachments 2 params body → 200400401403404429
PATCH
/api/v2/incidents/{incident_id}/relationships/integrations/{integration_metadata_id}
Datadog Update an Existing Incident Integration Metadata
UpdateIncidentIntegration 2 params body → 200400401403404429
PATCH
/api/v2/incidents/{incident_id}/relationships/todos/{todo_id}
Datadog Update an Incident Todo
UpdateIncidentTodo 2 params body → 200400401403404429
PATCH
/api/v2/integration/aws/accounts/{aws_account_config_id}
Datadog Update an Aws Integration
UpdateAWSAccount 1 param body → 200400403404429
PATCH
/api/v2/integration/gcp/accounts/{account_id}
Datadog Update Sts Service Account
UpdateGCPSTSAccount 1 param body → 201400403404429
PATCH
/api/v2/integration/ms-teams/configuration/tenant-based-handles/{handle_id}
Datadog Update Tenant-based Handle
UpdateTenantBasedHandle 1 param body → 200400403404409412429
PATCH
/api/v2/integration/ms-teams/configuration/workflows-webhook-handles/{handle_id}
Datadog Update Workflows Webhook Handle
UpdateWorkflowsWebhookHandle 1 param body → 200400403404409412429
PATCH
/api/v2/integration/opsgenie/services/{integration_service_id}
Datadog Update a Single Service Object
UpdateOpsgenieService 1 param body → 200400403404409429
PATCH
/api/v2/integrations/cloudflare/accounts/{account_id}
Datadog Update Cloudflare Account
UpdateCloudflareAccount 1 param body → 200400403404429
PATCH
/api/v2/integrations/confluent-cloud/accounts/{account_id}
Datadog Update Confluent Account
UpdateConfluentAccount 1 param body → 200400403404429
PATCH
/api/v2/integrations/confluent-cloud/accounts/{account_id}/resources/{resource_id}
Datadog Update Resource in Confluent Account
UpdateConfluentResource 2 params body → 200400403404429
PATCH
/api/v2/integrations/fastly/accounts/{account_id}
Datadog Update Fastly Account
UpdateFastlyAccount 1 param body → 200400403404429
PATCH
/api/v2/integrations/fastly/accounts/{account_id}/services/{service_id}
Datadog Update Fastly Service
UpdateFastlyService 2 params body → 200400403404429
PATCH
/api/v2/integrations/okta/accounts/{account_id}
Datadog Update Okta Account
UpdateOktaAccount 1 param body → 200400403404429
PATCH
/api/v2/ip_allowlist
Datadog Update Ip Allowlist
UpdateIPAllowlist body → 200400403404429
PUT
/api/v2/logs/config/archive-order
Datadog Update Archive Order
UpdateLogsArchiveOrder body → 200400403422429
PUT
/api/v2/logs/config/archives/{archive_id}
Datadog Update an Archive
UpdateLogsArchive 1 param body → 200400403404429
PATCH
/api/v2/logs/config/custom-destinations/{custom_destination_id}
Datadog Update a Custom Destination
UpdateLogsCustomDestination 1 param body → 200400403404409429
PATCH
/api/v2/logs/config/metrics/{metric_id}
Datadog Update a Log-based Metric
UpdateLogsMetric 1 param body → 200400403404429
PATCH
/api/v2/logs/config/restriction_queries/{restriction_query_id}
Datadog Update a Restriction Query
UpdateRestrictionQuery 1 param body → 200400403404429
PATCH
/api/v2/metrics/{metric_name}/tags
Datadog Update a Tag Configuration
UpdateTagConfiguration 1 param body → 200400403422429
PATCH
/api/v2/monitor/notification_rule/{rule_id}
Datadog Update a Monitor Notification Rule
UpdateMonitorNotificationRule 1 param body → 200400403404429
PATCH
/api/v2/ndm/tags/devices/{device_id}
Datadog Update the Tags for a Device
UpdateDeviceUserTags 1 param body → 200403404429
PUT
/api/v2/on-call/escalation-policies/{policy_id}
Datadog Update On-call Escalation Policy
UpdateOnCallEscalationPolicy 2 params body → 200400401403404429
PUT
/api/v2/on-call/schedules/{schedule_id}
Datadog Update On-call Schedule
UpdateOnCallSchedule 2 params body → 200400401403404429
PATCH
/api/v2/org_configs/{org_config_name}
Datadog Update a Specific Org Config
UpdateOrgConfig 1 param body → 200400401403404429
PATCH
/api/v2/powerpacks/{powerpack_id}
Datadog Update a Powerpack
UpdatePowerpack 1 param body → 200400404429
PUT
/api/v2/remote_config/products/asm/waf/custom_rules/{custom_rule_id}
Datadog Update a Waf Custom Rule
UpdateApplicationSecurityWafCustomRule 1 param body → 200400403404409429
PUT
/api/v2/remote_config/products/asm/waf/exclusion_filters/{exclusion_filter_id}
Datadog Update a Waf Exclusion Filter
UpdateApplicationSecurityWafExclusionFilter 1 param body → 200400403404409429
PATCH
/api/v2/remote_config/products/cws/agent_rules/{agent_rule_id}
Datadog Update a Workload Protection Agent Rule
UpdateCSMThreatsAgentRule 2 params body → 200400403404409429
PATCH
/api/v2/remote_config/products/cws/policy/{policy_id}
Datadog Update a Workload Protection Policy
UpdateCSMThreatsAgentPolicy 1 param body → 200400403404409429
PUT
/api/v2/remote_config/products/obs_pipelines/pipelines/{pipeline_id}
Datadog Update a Pipeline
UpdatePipeline 1 param body → 200400403404409429
POST
/api/v2/restriction_policy/{resource_id}
Datadog Update a Restriction Policy
UpdateRestrictionPolicy 2 params body → 200400403429
PATCH
/api/v2/roles/{role_id}
Datadog Update a Role
UpdateRole 1 param body → 200400403404422429
PATCH
/api/v2/rum/applications/{app_id}/retention_filters/{rf_id}
Datadog Update a Rum Retention Filter
UpdateRetentionFilter 2 params body → 200400403404429
PATCH
/api/v2/rum/applications/{id}
Datadog Update a Rum Application
UpdateRUMApplication 1 param body → 200400404422429
PATCH
/api/v2/rum/config/metrics/{metric_id}
Datadog Update a Rum-based Metric
UpdateRumMetric 1 param body → 200400403404409429
PUT
/api/v2/scim/Groups/{group_id}
Datadog Update Group
UpdateSCIMGroup 1 param body → 200400404409429
PUT
/api/v2/scim/Users/{user_uuid}
Datadog Update User
UpdateSCIMUser 1 param body → 200400404429
PUT
/api/v2/scorecard/rules/{rule_id}
Datadog Update an Existing Rule
UpdateScorecardRule 1 param body → 200400403429
PATCH
/api/v2/security_monitoring/cloud_workload_security/agent_rules/{agent_rule_id}
Datadog Update a Workload Protection Agent Rule (us1-fed)
UpdateCloudWorkloadSecurityAgentRule 1 param body → 200400403404409429
PATCH
/api/v2/security_monitoring/configuration/security_filters/{security_filter_id}
Datadog Update a Security Filter
UpdateSecurityFilter 1 param body → 200400403404409429
PATCH
/api/v2/security_monitoring/configuration/suppressions/{suppression_id}
Datadog Update a Suppression Rule
UpdateSecurityMonitoringSuppression 1 param body → 200400403404409429
PUT
/api/v2/security_monitoring/rules/{rule_id}
Datadog Update an Existing Rule
UpdateSecurityMonitoringRule 1 param body → 200400401403404429
PATCH
/api/v2/sensitive-data-scanner/config/groups/{group_id}
Datadog Update Scanning Group
UpdateScanningGroup 1 param body → 200400403404429
PATCH
/api/v2/sensitive-data-scanner/config/rules/{rule_id}
Datadog Update Scanning Rule
UpdateScanningRule 1 param body → 200400403404429
POST
/api/v2/services/definitions
Datadog Create or Update Service Definition
CreateOrUpdateServiceDefinitions body → 200400403409429
PATCH
/api/v2/services/{service_id}deprecated
Datadog Update an Existing Incident Service
UpdateIncidentService 1 param body → 200400401403404429
PATCH
/api/v2/team/{team_id}
Datadog Update a Team
UpdateTeam 1 param body → 200400403404409429
PATCH
/api/v2/team/{team_id}/links/{link_id}
Datadog Update a Team Link
UpdateTeamLink 2 params body → 200403404429
PATCH
/api/v2/team/{team_id}/memberships/{user_id}
Datadog Update a User's Membership Attributes on a Team
UpdateTeamMembership 2 params body → 200403404429
PUT
/api/v2/team/{team_id}/permission-settings/{action}
Datadog Update Permission Setting for Team
UpdateTeamPermissionSetting 2 params body → 200403404429
PATCH
/api/v2/teams/{team_id}deprecated
Datadog Update an Existing Incident Team
UpdateIncidentTeam 1 param body → 200400401403404429
PATCH
/api/v2/users/{user_id}
Datadog Update a User
UpdateUser 1 param body → 200400403404422429
PATCH
/api/v2/workflows/{workflow_id}
Datadog Update an Existing Workflow
UpdateWorkflow 1 param body → 200400403404429

Schemas 1312

The contract defines 1312 schemas that model the data the API accepts and returns. The most detailed are IncidentResponseAttributes (24 properties), SecurityMonitoringStandardRuleResponse (24 properties), CloudWorkloadSecurityAgentRuleAttributes (21 properties), SecurityMonitoringSignalRuleResponse (18 properties). Each schema is shown below with its type and property counts.

ServiceDefinitionV2
object
Service definition V2 for providing service metadata and integrations.
11 properties 2 required
ScheduleMemberRelationshipsUserDataType
string
Users resource type.
LogsArchiveDestinationAzure
object
The Azure archive destination.
6 properties 4 required
ActionQueryCondition
Whether to run this query. If specified, the query will only run if this condition evaluates to true in JavaScript and all other conditions are also met.
OrganizationAttributes
object
Attributes of the organization.
8 properties
ServiceDefinitionV2Dot1SlackType
string
Contact type.
ListTagsResponse
object
List tags response.
1 property
OrgConfigReadAttributes
object
Readable attributes of an Org Config.
5 properties 4 required
ScheduleUpdateRequestDataAttributesLayersItems
object
Represents a layer within a schedule update, including rotation details, members, and optional restrictions.
8 properties 5 required
CustomConnectionAttributesOnPremRunner
object
Information about the Private Action Runner used by the custom connection, if the custom connection is associated with a Private Action Runner.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionHashAction
string
Action type that replaces the matched sensitive data with a hashed representation, preserving structure while securing content.
RelationshipToRuleDataObject
object
Rule relationship data.
2 properties
RelationshipToTeamLinks
object
Relationship between a team and a team link
2 properties
TeamPermissionSettingSerializerAction
string
The identifier for the action
FastlyServiceType
string
The JSON:API type for this API. Should always be fastly-services.
SpansMetricGroupBy
object
A group by rule.
2 properties 1 required
AccountFilteringConfig
object
The account filtering configuration.
3 properties
EntityToOncalls
object
Entity to oncalls relationship.
1 property
ScheduleUpdateRequestDataAttributes
object
Defines the updatable attributes for a schedule, such as name, time zone, and layers.
3 properties 3 required
ServiceNowTicket
object
ServiceNow ticket attached to case
2 properties
TeamRelationships
object
Resources related to a team
2 properties
DashboardListUpdateItemsResponse
object
Response containing a list of updated dashboards.
1 property
ObservabilityPipelineDedupeProcessorMode
string
The deduplication mode to apply to the fields.
ConfluentResourceType
string
The JSON:API type for this request.
LogsMetricUpdateCompute
object
The compute rule to compute the log-based metric.
1 property
Deployment
object
The version of the app that was published.
4 properties
RelationshipToUserTeamTeamData
object
The team associated with the membership
2 properties 2 required
EntityV3DatastoreDatadog
object
Datadog product integrations for the datastore entity.
3 properties
AzureStorageDestinationType
string
The destination type. The value should always be azurestorage.
CloudWorkloadSecurityAgentRuleUpdaterAttributes
object
The attributes of the user who last updated the Agent rule
2 properties
ObservabilityPipelineMetadataEntry
object
A custom metadata entry.
2 properties 2 required
DashboardListUpdateItemsRequest
object
Request containing the list of dashboards to update to.
1 property
PowerpackGroupWidgetDefinition
object
Powerpack group widget object.
5 properties 3 required
Permission
object
Permission object.
3 properties 1 required
ScheduleUpdateRequestDataRelationships
object
Houses relationships for the schedule update, typically referencing teams.
1 property
TeamReference
object
Provides a reference to a team, including ID, type, and basic attributes/relationships.
3 properties 1 required
LogsArchiveIntegrationGCS
object
The GCS archive's integration destination.
2 properties 1 required
CustomDestinationUpdateRequestAttributes
object
The attributes associated with the custom destination.
7 properties
CustomDestinationHttpDestinationAuthCustomHeader
object
Custom header access authentication.
3 properties 3 required
ActionConnectionDataUpdate
object
Data related to the connection update.
2 properties 2 required
GCPSTSServiceAccountAttributes
object
Attributes associated with your service account.
11 properties
ServiceDefinitionV2Dot2
object
Service definition v2.2 for providing service metadata and integrations.
15 properties 2 required
AzureUCConfigPair
object
Azure config pair.
3 properties 2 required
ObservabilityPipelineSyslogNgDestinationType
string
The destination type. The value should always be syslogng.
PowerpackAttributes
object
Powerpack attribute object.
5 properties 2 required
ObservabilityPipelineEnrichmentTableFileEncodingType
string
Specifies the encoding format (e.g., CSV) used for enrichment tables.
ServiceDefinitionsCreateRequest
Create service definitions request.
ObservabilityPipelineFluentdSourceType
string
The source type. The value should always be fluentd.
RetentionFilterAll
object
The definition of the retention filter.
3 properties 3 required
IPAllowlistAttributes
object
Attributes of the IP allowlist.
2 properties
TokenType
string
The definition of TokenType object.
ObservabilityPipelineOcsfMapperProcessorMappingMapping
Defines a single mapping rule for transforming logs into the OCSF schema.
XRayServicesIncludeAll
object
Include all services.
1 property 1 required
MSTeamsIntegrationMetadataTeamsItem
object
Item in the Microsoft Teams integration metadata teams array.
4 properties 4 required
LogsArchiveEncryptionS3
object
The S3 encryption settings.
2 properties 1 required
AWSNamespaceTagFilter
object
AWS Metrics Collection tag filters list. Defaults to []. The array of custom AWS resource tags (in the form key:value) defines a filter that Datadog uses when…
2 properties
UpdateRuleResponseData
object
The data for a rule update response.
4 properties
ObservabilityPipelineGoogleCloudStorageDestinationType
string
The destination type. Always googlecloudstorage.
DowntimeNotifyEndStateActions
string
Action that will trigger a monitor notification if the downtime is in the notifyendtypes state.
FrameworkHandleAndVersionResponseData
object
Contains type and attributes for custom frameworks.
3 properties 3 required
DataRelationshipsTeamsDataItems
object
Relates a team to this schedule, identified by id and type (must be teams).
2 properties 2 required
SensitiveDataScannerConfigurationData
object
A Sensitive Data Scanner configuration data.
1 property
ApplicationSecurityWafExclusionFilterScope
object
Deploy on services based on their environment and/or service name.
2 properties
AnnotationDisplayBounds
object
The definition of AnnotationDisplayBounds object.
4 properties
IncidentTodoAssigneeHandle
string
Assignee's @-handle.
BudgetWithEntriesData
object
A budget and all its entries.
3 properties
LogsArchiveState
string
The state of the archive.
DowntimeScheduleOneTimeCreateUpdateRequest
object
A one-time downtime definition.
2 properties
ObservabilityPipelineQuotaProcessorLimitEnforceType
string
Unit for quota enforcement in bytes for data size or events for count.
AwsCURConfigPatchRequestType
string
Type of AWS CUR config Patch Request.
SecurityMonitoringRuleNewValueOptionsLearningDuration
integer
The duration in days during which values are learned, and after which signals will be generated for values that weren't learned. If set to 0, a signal will be…
SlackTriggerWrapper
object
Schema for a Slack-based trigger.
2 properties 1 required
ObservabilityPipelineRsyslogDestinationType
string
The destination type. The value should always be rsyslog.
MonitorNotificationRuleFilter
Filter used to associate the notification rule with monitors.
SecurityFilterUpdateAttributes
object
The security filters properties to be updated.
6 properties
ErrorHandler
object
Used to handle errors in an action.
2 properties 2 required
ScheduleUpdateRequest
object
A top-level wrapper for a schedule update request, referring to the data object with the new details.
1 property 1 required
ObservabilityPipelineParseGrokProcessorType
string
The processor type. The value should always be parsegrok.
TeamTarget
object
Represents a team target for an escalation policy step, including the team's ID and resource type.
2 properties 2 required
ObservabilityPipelineAmazonOpenSearchDestinationType
string
The destination type. The value should always be amazonopensearch.
SecurityMonitoringRuleCaseActionOptionsUserBehaviorName
string
Used with the case action of type 'userbehavior'. The value specified in this field is applied as a risk tag to all users affected by the rule.
RestrictionQueryAttributes
object
Attributes of the restriction query.
3 properties
ObservabilityPipelineGeneratedMetric
object
Defines a log-based custom metric, including its name, type, filter, value computation strategy, and optional grouping fields.
5 properties 4 required
AWSRegionsIncludeAll
object
Include all regions. Defaults to true.
1 property 1 required
ObservabilityPipelineGoogleChronicleDestination
object
The googlechronicle destination sends logs to Google Chronicle.
7 properties 5 required
MicrosoftTeamsTenantBasedHandleType
string
Specifies the tenant-based handle resource type.
LogsArchiveStorageClassS3Type
string
The storage class where the archive will be stored.
LayerAttributesInterval
object
Defines how often the rotation repeats, using a combination of days and optional seconds.
2 properties
MicrosoftTeamsWorkflowsWebhookHandleAttributes
object
Workflows Webhook handle attributes.
2 properties
AWSRegions
AWS Regions to collect data from. Defaults to includeall.
ListTagsResponseDataAttributes
object
The definition of ListTagsResponseDataAttributes object.
1 property
ObservabilityPipelineKafkaSource
object
The kafka source ingests data from Apache Kafka topics.
7 properties 4 required
ObservabilityPipelineSplunkTcpSource
object
The splunktcp source receives logs from a Splunk Universal Forwarder over TCP. TLS is supported for secure transmission.
3 properties 2 required
ActionQueryMockedOutputsObject
object
The mocked outputs of the action query.
2 properties 1 required
OpenAPIEndpoint
object
Endpoint info extracted from an OpenAPI specification.
2 properties
UserTeamPermissionType
string
User team permission type
RetentionFilterUpdateRequest
object
The body of the retention filter to be updated.
1 property 1 required
LogsMetricResponseGroupBy
object
A group by rule.
2 properties
IncidentAttachmentUpdateRequest
object
The update request for an incident's attachments.
1 property 1 required
IncidentTeamResponseAttributes
object
The incident team's attributes from a response.
3 properties
IncidentTypeObject
object
Incident type response data.
3 properties 2 required
ActionQueryDebounceInMs
The minimum time in milliseconds that must pass before the query can be triggered again. This is useful for preventing accidental double-clicks from triggering…
WorkflowDataUpdateAttributes
object
The definition of WorkflowDataUpdateAttributes object.
8 properties
TeamPermissionSettingUpdateAttributes
object
Team permission setting update attributes
1 property
ApplicationSecurityWafExclusionFilterUpdateAttributes
object
Attributes for updating a WAF exclusion filter.
8 properties 2 required
AppBuilderEvent
object
An event on a UI component that triggers a response or action in an app.
2 properties
ApplicationSecurityWafCustomRuleData
object
Object for a single WAF custom rule.
3 properties
EscalationPolicyStepTargetType
string
Specifies the type of escalation target (example users, schedules, or teams).
TeamType
string
Team type
EntityV3QueueDatadog
object
Datadog product integrations for the datastore entity.
3 properties
IncidentTypeResponse
object
Incident type response data.
1 property 1 required
ObservabilityPipelineSentinelOneDestination
object
The sentinelone destination sends logs to SentinelOne.
4 properties 4 required
Case
object
A case
4 properties 3 required
ScheduleDataType
string
Schedules resource type.
ServiceDefinitionV2Opsgenie
object
Opsgenie integration for the service.
2 properties 1 required
RoleUpdateRequest
object
Update a role.
1 property 1 required
LogsArchiveOrderDefinitionType
string
Type of the archive order definition.
DowntimeNotifyEndStates
array
States that will trigger a monitor notification when the notifyendtypes action occurs.
ObservabilityPipelineAmazonOpenSearchDestinationAuthStrategy
string
The authentication strategy to use.
CustomFrameworkType
string
The type of the resource. The value must be customframework.
MicrosoftSentinelDestination
object
The microsoftsentinel destination forwards logs to Microsoft Sentinel.
7 properties 7 required
CloudConfigurationRegoRule
object
Rule details.
2 properties 2 required
CompletionConditionOperator
string
The definition of CompletionConditionOperator object.
ActionConnectionIntegrationUpdate
The definition of ActionConnectionIntegrationUpdate object.
MicrosoftTeamsWorkflowsWebhookHandleType
string
Specifies the Workflows webhook handle resource type.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExclude
object
Excludes specific fields from sensitive data scanning.
2 properties 2 required
RumRetentionFilterUpdateRequest
object
The RUM retention filter body to update.
1 property 1 required
AzureUCConfigPairsResponse
object
Response of Azure config pair.
1 property
ServiceDefinitionV2Pagerduty
string
PagerDuty service URL for the service.
IncidentTeamResponseData
object
Incident Team data from a response.
4 properties
CustomDestinationHttpDestinationAuthBasic
object
Basic access authentication.
3 properties 3 required
Connection
object
The definition of Connection object.
2 properties 2 required
IncidentNonDatadogCreator
object
Incident's non Datadog creator.
2 properties
ScheduleUserAttributes
object
Provides basic user information for a schedule, including a name and email address.
3 properties
EntityV3DatadogEvents
array
Events associations.
ObservabilityPipelineDatadogLogsDestination
object
The datadoglogs destination forwards logs to Datadog Log Management.
3 properties 3 required
IncidentIntegrationMetadataResponse
object
Response with an incident integration metadata.
2 properties 1 required
Team
object
A team
4 properties 3 required
ObservabilityPipelineAddEnvVarsProcessor
object
The addenvvars processor adds environment variable values to log events.
5 properties 5 required
MonitorNotificationRuleAttributes
object
Attributes of the monitor notification rule.
3 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorPattern
Pattern detection configuration for identifying sensitive data using either a custom regex or a library reference.
ObservabilityPipelineSensitiveDataScannerProcessorActionRedact
object
Configuration for completely redacting matched sensitive data.
2 properties 2 required
UserTeamIncluded
Included resources related to the team membership
ConfluentResourceRequest
object
The JSON:API request for updating a Confluent resource.
1 property 1 required
ApplicationSecurityWafExclusionFilterRulesTarget
object
Target WAF rules based either on an identifier or tags.
2 properties
MonitorTriggerWrapper
object
Schema for a Monitor-based trigger.
2 properties 1 required
LogsMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
DowntimeScope
string
The scope to which the downtime applies. Must follow the [common search syntax](https://docs.datadoghq.com/logs/explorer/searchsyntax/).
AWSAccountPartition
string
AWS partition your AWS account is scoped to. Defaults to aws. See [Partitions](https://docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/pa…
EntityData
object
Entity data.
5 properties
IncidentIntegrationMetadataPatchRequest
object
Patch request for an incident integration metadata.
1 property 1 required
ServiceDefinitionV2MSTeamsType
string
Contact type.
SensitiveDataScannerStandardPattern
object
Data containing the standard pattern id.
2 properties
ApplicationSecurityWafCustomRuleTagsCategory
string
The category of the WAF Rule, can be either businesslogic, attackattempt or securityresponse.
CustomDestinationForwardDestinationSplunk
object
The Splunk HTTP Event Collector (HEC) destination.
3 properties 3 required
IncidentTodoResponseIncludedItem
An object related to an incident todo that is included in the response.
ObservabilityPipelineSumoLogicSource
object
The sumologic source receives logs from Sumo Logic collectors.
2 properties 2 required
OutputSchemaParametersType
string
The definition of OutputSchemaParametersType object.
EntityV3APIVersion
string
The schema version of entity type. The field is known as schema-version in the previous version.
ObservabilityPipelineHttpClientSourceAuthStrategy
string
Optional authentication strategy for HTTP requests.
SecurityMonitoringSuppressionID
string
The ID of the suppression rule.
TeamLinkCreateRequest
object
Team link create request
1 property 1 required
ObservabilityPipelineOcsfMapperProcessorMapping
object
Defines how specific events are transformed to OCSF using a mapping configuration.
2 properties 2 required
MicrosoftSentinelDestinationType
string
The destination type. The value should always be microsoftsentinel.
ObservabilityPipelineQuotaProcessorLimit
object
The maximum amount of data or number of events allowed before the quota is enforced. Can be specified in bytes or events.
2 properties 2 required
ActionConnectionAttributes
object
The definition of ActionConnectionAttributes object.
2 properties 2 required
DataRelationshipsTeams
object
Associates teams with this schedule in a data structure.
1 property
ServiceDefinitionV2Dot1Integrations
object
Third party integrations that Datadog supports.
2 properties
OpsgenieServiceResponse
object
Response of an Opsgenie service.
1 property 1 required
RelationshipToIncidentImpacts
object
Relationship to impacts.
1 property 1 required
EntityToRelatedEntities
object
Entity to related entities relationship.
1 property
IncidentAttachmentPostmortemAttributes
object
The attributes object for a postmortem attachment.
2 properties 2 required
ComponentProperties
object
Properties of a UI component. Different component types can have their own additional unique properties. See the [components documentation](https://docs.datado…
2 properties
EscalationPolicyUser
object
Represents a user object in the context of an escalation policy, including their id, type, and basic attributes.
3 properties 1 required
SecurityMonitoringRuleCaseActionType
string
The action type.
UpdateRuleRequest
object
Request to update a scorecard rule.
1 property
ObservabilityPipelineSampleProcessor
object
The sample processor allows probabilistic sampling of logs at a fixed rate.
6 properties 4 required
ObservabilityPipelineData
object
Contains the pipeline’s ID, type, and configuration attributes.
3 properties 3 required
CaseUpdateStatusAttributes
object
Case update status attributes
1 property 1 required
ServiceDefinitionV2Dot1Version
string
Schema version being used.
CustomConnectionAttributes
object
The custom connection attributes.
2 properties
HTTPIntegration
object
The definition of HTTPIntegration object.
3 properties 3 required
AzureUCConfigPatchRequestType
string
Type of Azure config Patch Request.
RuleType
string
The JSON:API type for scorecard rules.
AnnotationDisplay
object
The definition of AnnotationDisplay object.
1 property
AWSCredentials
The definition of AWSCredentials object.
CustomDestinationForwardDestinationElasticsearchType
string
Type of the Elasticsearch destination.
ObservabilityPipelineDedupeProcessor
object
The dedupe processor removes duplicate fields in log events.
6 properties 6 required
DowntimeMuteFirstRecoveryNotification
boolean
If the first recovery notification during a downtime should be muted.
MSTeamsIntegrationMetadata
object
Incident integration metadata for the Microsoft Teams integration.
1 property 1 required
RelationshipToRuleData
object
Relationship data for a rule.
1 property
DowntimeMonitorIdentifier
Monitor identifier for the downtime.
LogsArchiveDestinationAzureType
string
Type of the Azure archive destination.
LogsArchiveIntegrationS3
object
The S3 Archive's integration destination.
2 properties 2 required
CloudWorkloadSecurityAgentRuleCreatorAttributes
object
The attributes of the user who created the Agent rule
2 properties
ObservabilityPipelineGeneratedMetricIncrementByOne
object
Strategy that increments a generated metric by one for each matching event.
1 property 1 required
SecurityMonitoringSignalRuleResponseQuery
object
Query for matching rule on signals.
9 properties
EntityV3APIKind
string
The definition of Entity V3 API Kind object.
UpdateAppResponseData
object
The data object containing the updated app definition.
3 properties 3 required
ObservabilityPipelineEnrichmentTableFileEncoding
object
File encoding format.
3 properties 3 required
UpdateAppRequestDataAttributes
object
App definition attributes to be updated, such as name, description, and components.
6 properties
UserResponse
object
Response containing information about a single user.
2 properties
EntityV3APIDatadog
object
Datadog product integrations for the API entity.
5 properties
ScorecardType
string
The JSON:API type for scorecard.
EscalationPolicyDataRelationships
object
Represents the relationships for an escalation policy, including references to steps and teams.
2 properties 1 required
ExternalUserNameType
object
The components of user's real name
1 property
RetentionFilterResponse
object
The retention filters definition.
1 property
DowntimeMonitorIncludedItem
object
Information about the monitor identified by the downtime.
3 properties
CloudWorkloadSecurityAgentPolicyUpdateData
object
Object for a single Agent policy
3 properties 2 required
DowntimeMonitorIdentifierTags
object
Object of the monitor tags.
1 property 1 required
NullableUserRelationshipData
object
Relationship to user object.
2 properties 2 required
UpdateAppResponse
object
The response object after an app is successfully updated.
4 properties
SlackIntegrationMetadataChannelItem
object
Item in the Slack integration metadata channel array.
4 properties 3 required
AWSIntegrationType
string
The definition of AWSIntegrationType object.
EntityV3DatadogCodeLocationItem
object
Code location item.
2 properties
ComponentPropertiesIsVisible
Whether the UI component is visible. If this is a string, it must be a valid JavaScript expression that evaluates to a boolean.
ServiceDefinitionV1Info
object
Basic information about a service.
4 properties 1 required
SensitiveDataScannerGroupUpdateRequest
object
Update group request.
2 properties 2 required
CustomFrameworkData
object
Contains type and attributes for custom frameworks.
2 properties 2 required
SecurityFilter
object
The security filter's properties.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactOptions
object
Configuration for fully redacting sensitive data.
1 property 1 required
WorkflowUserRelationship
object
The definition of WorkflowUserRelationship object.
1 property
RuleAttributes
object
Details of a rule.
9 properties
IncidentTypeType
string
Incident type resource type.
LogsMetricFilter
object
The log-based metric filter. Logs matching this filter will be aggregated in this metric.
1 property
ServiceDefinitionV2MSTeams
object
Service owner's Microsoft Teams.
3 properties 2 required
LogsMetricUpdateData
object
The new log-based metric properties.
2 properties 2 required
EscalationPolicyDataRelationshipsSteps
object
Defines the relationship to a collection of steps within an escalation policy. Contains an array of step data references.
1 property
Spec
object
The spec defines what the workflow does.
7 properties
AWSAuthConfigRole
object
AWS Authentication config to integrate your account using an IAM role.
2 properties 1 required
SecurityMonitoringRuleTypeRead
string
The rule type.
MonitorNotificationRuleRelationships
object
All relationships associated with monitor notification rule.
1 property
CloudWorkloadSecurityAgentRuleActionSet
object
The set action applied on the scope matching the rule
7 properties
ObservabilityPipelineHttpServerSourceAuthStrategy
string
HTTP authentication method.
ObservabilityPipelineFluentdSource
object
The fluentd source ingests logs from a Fluentd-compatible service.
3 properties 2 required
SecurityMonitoringRuleMaxSignalDuration
integer
A signal will "close" regardless of the query being matched once the time exceeds the maximum duration. This time is calculated from the first seen timestamp.
EntityRaw
string
Entity definition in raw JSON or YAML representation.
StateVariableType
string
The state variable type.
ObservabilityPipelineFluentBitSource
object
The fluentbit source ingests logs from Fluent Bit.
3 properties 2 required
IncidentIntegrationRelationships
object
The incident's integration relationships from a response.
2 properties
ServiceDefinitionV2Dot1LinkType
string
Link type.
MetricCustomAggregation
object
A time and space aggregation combination for use in query.
2 properties 2 required
ListTagsResponseData
object
The list tags response data.
3 properties
ScheduleDataAttributes
object
Provides core properties of a schedule object such as its name and time zone.
2 properties
SecurityMonitoringRuleResponse
Create a new rule.
AppTriggerWrapper
object
Schema for an App-based trigger.
2 properties 1 required
IncidentAttachmentType
string
The incident attachment resource type.
IncidentUserAttributes
object
Attributes of user object returned by the API.
5 properties
SpansMetricUpdateCompute
object
The compute rule to compute the span-based metric.
1 property
BudgetAttributes
object
The attributes of a budget.
11 properties
AzureUCConfigPatchRequestAttributes
object
Attributes for Azure config Patch Request.
1 property 1 required
WorkflowTriggerWrapper
object
Schema for a Workflow-based trigger.
2 properties 1 required
LayerAttributes
object
Describes key properties of a Layer, including rotation details, name, start/end times, and any restrictions.
6 properties
SensitiveDataScannerRuleUpdateRequest
object
Update rule request.
2 properties 2 required
ObservabilityPipelineKafkaSourceSasl
object
Specifies the SASL mechanism for authenticating with a Kafka cluster.
1 property
ObservabilityPipelineSplunkHecDestination
object
The splunkhec destination forwards logs to Splunk using the HTTP Event Collector (HEC).
7 properties 3 required
StepDisplay
object
The definition of StepDisplay object.
1 property
RelationshipToUserData
object
Relationship to user object.
2 properties 2 required
SecurityMonitoringStandardDataSource
string
Source of events, either logs, audit trail, or Datadog events.
ServiceDefinitionV1Version
string
Schema version being used.
DataRelationshipsTeamsDataItemsType
string
Teams resource type.
Query
A data query used by an app. This can take the form of an external action, a data transformation, or a state variable.
ActionQuerySpec
The definition of the action query.
ConnectionEnvEnv
string
The definition of ConnectionEnvEnv object.
IncidentAttachmentLinkAttributes
object
The attributes object for a link attachment.
3 properties 2 required
AWSAccountUpdateRequest
object
AWS Account Update Request body.
1 property 1 required
IncidentUserData
object
User object returned by the API.
3 properties
ObservabilityPipelineQuotaProcessorOverride
object
Defines a custom quota limit that applies to specific log events based on matching field values.
2 properties 2 required
AWSAssumeRoleType
string
The definition of AWSAssumeRoleType object.
AppBuilderEventName
string
The triggering action for the event.
CloudflareAccountUpdateRequestData
object
Data object for updating a Cloudflare account.
2 properties
EntityV3DatadogPerformance
object
Performance stats association.
1 property
AzureUCConfig
object
Azure config.
15 properties 9 required
SpansFilter
object
The spans filter used to index spans.
1 property
UpdateRuleResponse
object
The response from a rule update request.
1 property
RestrictionQueryUpdateAttributes
object
Attributes of the edited restriction query.
1 property
TeamReferenceAttributes
object
Encapsulates the basic attributes of a Team reference, such as name, handle, and an optional avatar or description.
4 properties
CustomDestinationResponseHttpDestinationAuthCustomHeaderType
string
Type of the custom header access authentication.
MonitorNotificationRuleData
object
Monitor notification rule data.
4 properties
ObservabilityPipelineAmazonS3Source
object
The amazons3 source ingests logs from an Amazon S3 bucket. It supports AWS authentication and TLS encryption.
5 properties 3 required
SecurityFilterExclusionFilter
object
Exclusion filter for the security filter.
2 properties 2 required
RumMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when aggregationtype is distribution.
RelationshipToUserTeamPermissionData
object
Related user team permission data
2 properties 2 required
TeamUpdate
object
Team update request
3 properties 2 required
AWSCredentialsUpdate
The definition of AWSCredentialsUpdate object.
CloudflareAccountResponse
object
The expected response schema when getting a Cloudflare account.
1 property
ConfluentResourceResponseAttributes
object
Model representation of a Confluent Cloud resource.
4 properties 1 required
ObservabilityPipelineAmazonS3Destination
object
The amazons3 destination sends your logs in Datadog-rehydratable format to an Amazon S3 bucket for archiving.
9 properties 6 required
MetricTagConfigurationUpdateRequest
object
Request object that includes the metric that you would like to edit the tag configuration on.
1 property 1 required
ServiceDefinitionV2Dot2Type
string
The type of service.
UpdateActionConnectionResponse
object
The response for an updated connection.
1 property
AWSNamespaceFiltersExcludeOnly
object
Exclude only these namespaces from metrics collection. Defaults to ["AWS/SQS", "AWS/ElasticMapReduce"]. AWS/SQS and AWS/ElasticMapReduce are excluded by defaul…
1 property 1 required
ObservabilityPipelineFieldValue
object
Represents a static key-value pair used in various processors.
2 properties 2 required
CaseResponse
object
Case response
1 property
ObservabilityPipelineDataAttributes
object
Defines the pipeline’s name and its components (sources, processors, and destinations).
2 properties 2 required
EntityV3Service
object
Schema for service entities.
7 properties 3 required
EntityResponseIncludedSchemaType
string
Schema type.
SpansMetricResponseGroupBy
object
A group by rule.
2 properties
ObservabilityPipelineDatadogAgentSourceType
string
The source type. The value should always be datadogagent.
TeamPermissionSettingResponse
object
Team permission setting response
1 property
IncidentResponseIncludedItem
An object related to an incident that is included in the response.
ObservabilityPipelineFluentBitSourceType
string
The source type. The value should always be fluentbit.
WorkflowDataType
string
The definition of WorkflowDataType object.
SecurityMonitoringRuleQuery
Query for matching rule.
RelationshipToTeamLinkData
object
Relationship between a link and a team
2 properties 2 required
RumMetricResponse
object
The rum-based metric object.
1 property
ActionQuerySpecInput
object
The inputs to the action query. See the [Actions Catalog](https://docs.datadoghq.com/actions/actionscatalog/) for more detail on each action and its inputs.
DowntimeNotifyEndTypes
array
Actions that will trigger a monitor notification if the downtime is in the notifyendtypes state.
RUMApplication
object
RUM application.
3 properties 3 required
ServiceDefinitionV1ResourceType
string
Link type.
DowntimeResourceType
string
Downtime resource type.
CaseStatus
string
Case status
IncidentUpdateRelationships
object
The incident's relationships for an update request.
3 properties
TeamLinkType
string
Team link type
DowntimeMonitorIdentifierId
object
Object of the monitor identifier.
1 property 1 required
ServiceDefinitionV2Dot2Contact
object
Service owner's contacts information.
3 properties 2 required
BudgetEntry
object
The entry of a budget.
3 properties
CustomDestinationHttpDestinationAuth
Authentication method of the HTTP requests.
MicrosoftTeamsWorkflowsWebhookHandleResponse
object
Response of a Workflows webhook handle.
1 property 1 required
FastlyServiceData
object
Data object for Fastly service requests.
3 properties 2 required
ConfluentAccountResponseAttributes
object
The attributes of a Confluent account.
3 properties 1 required
EntityV3ServiceKind
string
The definition of Entity V3 Service Kind object.
ObservabilityPipelineSensitiveDataScannerProcessorScopeAll
object
Applies scanning across all available fields.
1 property 1 required
DowntimeStatus
string
The current status of the downtime.
CloudWorkloadSecurityAgentRuleType
string
The type of the resource, must always be agentrule
EntityV3DatadogIntegrationPagerduty
object
A PagerDuty integration schema.
1 property 1 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeOptions
object
Fields to which the scope rule applies.
1 property 1 required
IncidentRelatedObject
string
Object related to an incident.
AWSMetricsConfig
object
AWS Metrics Collection config.
6 properties
ObservabilityPipelineSplunkHecDestinationEncoding
string
Encoding format for log events.
DowntimeRelationshipsMonitorData
object
Data for the monitor.
2 properties
UpdateWorkflowRequest
object
A request object for updating an existing workflow.
1 property 1 required
FastlyServiceResponse
object
The expected response schema when getting a Fastly service.
1 property
RelationshipToIncidentUserDefinedFields
object
Relationship to incident user defined fields.
1 property 1 required
DataTransform
object
A data transformer, which is custom JavaScript code that executes and transforms data when its inputs change.
4 properties 4 required
IncidentTeamUpdateAttributes
object
The incident team's attributes for an update request.
1 property 1 required
UserResponseIncludedItem
An object related to a user.
LayerType
string
Layers resource type.
ObservabilityPipelineRsyslogSourceType
string
The source type. The value should always be rsyslog.
ObservabilityPipelineOcsfMappingLibrary
string
Predefined library mappings for common log formats.
ActionQueryOnlyTriggerManually
Determines when this query is executed. If set to false, the query will run when the app loads and whenever any query arguments change. If set to true, the que…
CustomDestinationUpdateRequest
object
The custom destination.
1 property
GCPSTSServiceAccountUpdateRequest
object
Service account info.
1 property
EscalationPolicyUserAttributes
object
Provides basic user information for an escalation policy, including a name and email address.
3 properties
MicrosoftTeamsTenantBasedHandleResponse
object
Response of a tenant-based handle.
1 property 1 required
DowntimeMessage
string
A message to include with notifications for this downtime. Email notifications can be sent to specific users by using the same @username notation as events.
UpdateResourceEvaluationFiltersRequestData
object
The definition of UpdateResourceFilterRequestData object.
3 properties 2 required
TeamUpdateRelationships
object
Team update relationships
1 property
ActionConnectionDataType
string
The definition of ActionConnectionDataType object.
EscalationPolicyIncluded
Represents included related resources when retrieving an escalation policy, such as teams, steps, or targets.
ServiceDefinitionV2Version
string
Schema version being used.
SecurityMonitoringSignalRuleQuery
object
Query for matching rule on signals.
6 properties 1 required
SecurityTriggerWrapper
object
Schema for a Security-based trigger.
2 properties 1 required
CloudflareAccountResponseData
object
Data object of a Cloudflare account.
3 properties 3 required
ScheduleDataRelationships
object
Groups the relationships for a schedule object, referencing layers and teams.
2 properties
RelationshipToIncidentPostmortem
object
A relationship reference for postmortems.
1 property 1 required
IPAllowlistResponse
object
Response containing information about the IP allowlist.
1 property
TeamPermissionSettingValue
string
What type of user is allowed to perform the specified action
RumRetentionFilterResponse
object
The RUM retention filter object.
1 property
LogsRestrictionQueriesType
string
Restriction query resource type.
EntityAttributes
object
Entity attributes.
8 properties
ScheduleUpdateRequestData
object
Contains all data needed to update an existing schedule, including its attributes (such as name and time zone) and any relationships to teams.
4 properties 3 required
ServiceDefinitionV2Dot1MSTeamsType
string
Contact type.
APIErrorResponse
object
API error response.
1 property 1 required
ObservabilityPipelineAmazonOpenSearchDestination
object
The amazonopensearch destination writes logs to Amazon OpenSearch.
5 properties 4 required
LogsMetricID
string
The name of the log-based metric.
ActionQueryRequiresConfirmation
Whether to prompt the user to confirm this query before it runs.
ObservabilityPipelineEnrichmentTableGeoIp
object
Uses a GeoIP database to enrich logs based on an IP field.
3 properties 3 required
LayerRelationshipsMembersDataItemsType
string
Members resource type.
IncidentUpdateAttributes
object
The incident's attributes for an update request.
8 properties
OpenAPIFile
object
Object for API data in an OpenAPI format as a file.
1 property
RunRetentionFilterName
string
The name of a RUM retention filter.
IncidentResponseAttributes
object
The incident's attributes from a response.
24 properties 1 required
BudgetWithEntries
object
The definition of the BudgetWithEntries object.
1 property
EntityV3MetadataAdditionalOwnersItems
object
The definition of Entity V3 Metadata Additional Owners Items object.
2 properties 1 required
ApplicationSecurityWafCustomRuleActionParameters
object
The definition of ApplicationSecurityWafCustomRuleActionParameters object.
2 properties
ServiceDefinitionV2Dot1MSTeams
object
Service owner's Microsoft Teams.
3 properties 2 required
SensitiveDataScannerRuleType
string
Sensitive Data Scanner rule type.
DowntimeScheduleUpdateRequest
Schedule for the downtime.
AWSNamespaceFilters
AWS Metrics namespace filters. Defaults to excludeonly.
ReadinessGate
object
Used to merge multiple branches into a single branch.
1 property 1 required
AWSIntegrationUpdate
object
The definition of AWSIntegrationUpdate object.
2 properties 1 required
UpdateResourceEvaluationFiltersResponse
object
The definition of UpdateResourceEvaluationFiltersResponse object.
1 property 1 required
EntityV3DatadogPipelines
object
CI Pipelines association.
1 property
ConfluentAccountUpdateRequestAttributes
object
Attributes object for updating a Confluent account.
3 properties 2 required
EntityV3System
object
Schema for system entities.
7 properties 3 required
EscalationPolicyData
object
Represents the data for a single escalation policy, including its attributes, ID, relationships, and resource type.
4 properties 1 required
EntityV3MetadataLinksItems
object
The definition of Entity V3 Metadata Links Items object.
4 properties 3 required
RelationshipToOrganizations
object
Relationship to organizations.
1 property 1 required
UserTeamUserType
string
User team user type
MetricTagConfigurationUpdateData
object
Object for a single tag configuration to be edited.
3 properties 2 required
SecurityFilterType
string
The type of the resource. The value should always be securityfilters.
WorkflowUserRelationshipData
object
The definition of WorkflowUserRelationshipData object.
2 properties 2 required
NullableRelationshipToUser
object
Relationship to user.
1 property 1 required
IncidentTriggerWrapper
object
Schema for an Incident-based trigger.
2 properties 1 required
SecurityMonitoringRuleNewValueOptions
object
Options on new value detection method.
4 properties
DowntimeScheduleOneTimeResponse
object
A one-time downtime definition.
2 properties 1 required
SensitiveDataScannerRule
object
Rule item included in the group.
2 properties
ServiceDefinitionV1
object
Deprecated - Service definition V1 for providing additional service metadata and integrations.
8 properties 2 required
HTTPToken
object
The definition of HTTPToken object.
3 properties 3 required
ObservabilityPipelineSumoLogicDestinationEncoding
string
The output encoding format.
LogsArchiveCreateRequestAttributes
object
The attributes associated with the archive.
6 properties 3 required
AWSAccountConfigID
string
Unique Datadog ID of the AWS Account Integration Config. To get the config ID for an account, use the [List all AWS integrations](https://docs.datadoghq.com/ap…
FastlyServiceAttributes
object
Attributes object for Fastly service requests.
1 property
ExternalUserGroupMeta
object
Metadata associated with a group.
4 properties
CustomDestinationForwardDestinationHttp
object
The HTTP destination.
3 properties 3 required
DataTransformType
string
The data transform type.
ExternalUserGroupMembersItems
object
The definition of a member belonging to a group.
4 properties
IPAllowlistEntryAttributes
object
Attributes of the IP allowlist entry.
4 properties
IncidentAttachmentRelatedObject
string
The object related to an incident attachment.
RumMetricUpdateRequest
object
The new rum-based metric body.
1 property 1 required
JSONAPIErrorItem
object
API error response body
5 properties
CustomDestinationResponseHttpDestinationAuthCustomHeader
object
Custom header access authentication.
2 properties 2 required
DowntimeScheduleResponse
The schedule that defines when the monitor starts, stops, and recurs. There are two types of schedules: one-time and recurring. Recurring schedules may have up…
MetricCustomAggregations
array
Deprecated. You no longer need to configure specific time and space aggregations for Metrics Without Limits.
RetentionFilterUpdateData
object
The body of the retention filter to be updated.
3 properties 3 required
SecurityMonitoringStandardRuleQuery
object
Query for matching rule.
9 properties
DowntimeIncludedMonitorType
string
Monitor resource type.
ScheduleMemberRelationshipsUser
object
Wraps the user data reference for a schedule member.
1 property 1 required
OrgConfigWrite
object
An Org Config write operation.
2 properties 2 required
MetricCustomSpaceAggregation
string
A space aggregation for use in query.
EntityV3MetadataContactsItems
object
The definition of Entity V3 Metadata Contacts Items object.
3 properties 2 required
DowntimeDisplayTimezone
string
The timezone in which to display the downtime's start and end times in Datadog applications. This is not used as an offset for scheduling.
ObservabilityPipelineElasticsearchDestination
object
The elasticsearch destination writes logs to an Elasticsearch cluster.
5 properties 3 required
SpansMetricUpdateRequest
object
The new span-based metric body.
1 property 1 required
AwsCURConfigPatchRequest
object
AWS CUR config Patch Request.
1 property 1 required
IncidentIntegrationMetadataPatchData
object
Incident integration metadata data for a patch request.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternType
string
Indicates a custom regular expression is used for matching.
ObservabilityPipelineGcpAuth
object
GCP credentials used to authenticate with Google Cloud Storage.
1 property 1 required
ObservabilityPipelineRenameFieldsProcessor
object
The renamefields processor changes field names.
5 properties 5 required
IncidentTeamIncludedItems
An object related to an incident team which is present in the included payload.
ObservabilityPipelineThrottleProcessorType
string
The processor type. The value should always be throttle.
ApplicationSecurityWafExclusionFilterUpdateData
object
Object for updating a single WAF exclusion filter.
2 properties 2 required
CustomDestinationUpdateRequestDefinition
object
The definition of a custom destination.
3 properties 2 required
ObservabilityPipelineSampleProcessorType
string
The processor type. The value should always be sample.
ObservabilityPipelineEnrichmentTableProcessorType
string
The processor type. The value should always be enrichmenttable.
RelationshipArray
array
Relationships.
SecurityMonitoringRuleSeverity
string
Severity of the Security Signal.
ObservabilityPipelineSyslogSourceMode
string
Protocol used by the syslog source to receive messages.
SensitiveDataScannerGroupUpdate
object
Data related to the update of a group.
4 properties
OpsgenieServiceResponseAttributes
object
The attributes from an Opsgenie service response.
3 properties
ObservabilityPipelineSplunkHecDestinationType
string
The destination type. Always splunkhec.
SensitiveDataScannerGroupData
object
A scanning group data.
1 property
RumRetentionFilterQuery
string
The query string for a RUM retention filter.
SensitiveDataScannerGroupAttributes
object
Attributes of the Sensitive Data Scanner group.
5 properties
IncidentAttachmentUpdateData
object
A single incident attachment.
3 properties 1 required
ServiceDefinitionV2Dot1Email
object
Service owner's email.
3 properties 2 required
SensitiveDataScannerRuleRelationships
object
Relationships of a scanning rule.
2 properties
IncidentTeamUpdateRequest
object
Update request with an incident team payload.
1 property 1 required
RUMApplicationUpdateAttributes
object
RUM application update attributes.
2 properties
RoleResponseRelationships
object
Relationships of the role object returned by the API.
1 property
EntityV3ServiceSpec
object
The definition of Entity V3 Service Spec object.
6 properties
IncidentTypePatchData
object
Incident type data for a patch request.
3 properties 3 required
InputSchemaParameters
object
The definition of InputSchemaParameters object.
5 properties 2 required
ObservabilityPipelineAddEnvVarsProcessorVariable
object
Defines a mapping between an environment variable and a log field.
2 properties 2 required
EntityV3Queue
object
Schema for queue entities.
7 properties 3 required
SecurityFilterExclusionFilterResponse
object
A single exclusion filter.
2 properties
IncidentRespondersType
string
The incident responders type.
ApmRetentionFilterType
string
The type of the resource.
RelationshipToIncidentAttachmentData
object
The attachment relationship data.
2 properties 2 required
ObservabilityPipelineQuotaProcessorType
string
The processor type. The value should always be quota.
ApplicationSecurityWafExclusionFilterType
string
Type of the resource. The value should always be exclusionfilter.
JiraIssue
object
Jira issue attached to case
2 properties
ConfluentResourceRequestAttributes
object
Attributes object for updating a Confluent resource.
3 properties 1 required
ObservabilityPipelineReduceProcessorType
string
The processor type. The value should always be reduce.
DowntimeRelationshipsMonitor
object
The monitor identified by the downtime.
1 property
EscalationPolicyDataAttributes
object
Defines the main attributes of an escalation policy, such as its name and behavior on policy end.
3 properties 1 required
ObservabilityPipelineTls
object
Configuration for enabling TLS encryption between the pipeline component and external services.
3 properties 1 required
EntityRelationships
object
Entity relationships.
5 properties
ServiceDefinitionV2Dot1Contact
Service owner's contacts information.
LogsArchiveDestinationS3
object
The S3 archive destination.
6 properties 3 required
ObservabilityPipelineEnrichmentTableFileSchemaItemsType
string
Declares allowed data types for enrichment table columns.
ObservabilityPipelineRenameFieldsProcessorField
object
Defines how to rename a field in log events.
3 properties 3 required
MetricTagConfiguration
object
Object for a single metric tag configuration.
3 properties
IncidentServiceResponse
object
Response with an incident service payload.
2 properties 1 required
SecurityMonitoringRuleNewValueOptionsLearningMethod
string
The learning method used to determine when signals should be generated for values that weren't learned.
SensitiveDataScannerGroupRelationships
object
Relationships of the group.
2 properties
ServiceDefinitionV2Dot2Link
object
Service's external links.
4 properties 3 required
GCPSTSServiceAccountResponse
object
The account creation response.
1 property
LogsArchiveOrder
object
A ordered list of archive IDs.
1 property
ObservabilityPipelineOcsfMapperProcessor
object
The ocsfmapper processor transforms logs into the OCSF schema using a predefined mapping configuration.
5 properties 5 required
UpdateCustomFrameworkRequest
object
Request object to update a custom framework.
1 property 1 required
UpdateResourceEvaluationFiltersResponseData
object
The definition of UpdateResourceFilterResponseData object.
3 properties 2 required
RumRetentionFilterData
object
The RUM retention filter.
3 properties
MicrosoftTeamsUpdateWorkflowsWebhookHandleRequestData
object
Workflows Webhook handle data from a response.
2 properties 2 required
RelationshipToPermissions
object
Relationship to multiple permissions objects.
1 property
IncidentTeamRelationships
object
The incident team's relationships.
2 properties
ObservabilityPipelineGoogleCloudStorageDestinationStorageClass
string
Storage class used for objects stored in GCS.
PowerpackRelationships
object
Powerpack relationship object.
1 property
ObservabilityPipelineRemoveFieldsProcessorType
string
The processor type. The value should always be removefields.
SensitiveDataScannerConfiguration
object
A Sensitive Data Scanner configuration.
2 properties
AwsCURConfigType
string
Type of AWS CUR config.
CasePriority
string
Case priority
LogsArchiveDestination
object
An archive's destination.
ActionQueryShowToastOnError
Whether to display a toast to the user when the query returns an error.
FastlyAccountUpdateRequestAttributes
object
Attributes object for updating a Fastly account.
2 properties
EntityV3DatadogEventItem
object
Events association item.
2 properties
IncidentTodoPatchData
object
Incident todo data for a patch request.
2 properties 2 required
IncidentAttachmentRelationships
object
The incident attachment's relationships.
1 property
ActionConnectionAttributesUpdate
object
The definition of ActionConnectionAttributesUpdate object.
2 properties
RumMetricType
string
The type of the resource. The value should always be rummetrics.
SecurityMonitoringRuleThirdPartyOptions
object
Options on third party detection method.
4 properties
RestrictionPolicyAttributes
object
Restriction policy attributes.
1 property 1 required
CaseAttributes
object
Case attributes
12 properties
RumMetricComputeAggregationType
string
The type of aggregation to use.
EntityV3ServiceDatadog
object
Datadog product integrations for the service entity.
5 properties
RelationshipToIncidentResponderData
object
Relationship to impact object.
2 properties 2 required
ApplicationSecurityWafCustomRuleConditionOperator
string
Operator to use for the WAF Condition.
OrgConfigWriteRequest
object
A request to update an Org Config.
1 property 1 required
ScheduleMemberRelationships
object
Defines relationships for a schedule member, primarily referencing a single user.
1 property
UpsertCatalogEntityRequest
Create or update entity request.
IPAllowlistUpdateRequest
object
Update the IP allowlist.
1 property 1 required
EscalationPolicyUpdateRequest
object
Represents a request to update an existing escalation policy, including the updated policy data.
1 property 1 required
CustomDestinationResponseHttpDestinationAuth
Authentication method of the HTTP requests.
FastlyService
object
The schema representation of a Fastly service.
2 properties 1 required
OrgConfigType
string
Data type of an Org Config.
ServiceDefinitionMeta
object
Metadata about a service definition.
7 properties
SecurityMonitoringUser
object
A user.
2 properties
EscalationPolicyDataRelationshipsStepsDataItemsType
string
Indicates that the resource is of type steps.
OktaAccount
object
Schema for an Okta account.
3 properties 2 required
MetricTagConfigurationAttributes
object
Object containing the definition of a metric tag configuration attributes.
7 properties
UserTeamType
string
Team membership type
ScheduleTarget
object
Represents a schedule target for an escalation policy step, including its ID and resource type.
2 properties 2 required
LogsArchiveOrderDefinition
object
The definition of an archive order.
2 properties 2 required
SensitiveDataScannerProduct
string
Datadog product onto which Sensitive Data Scanner can be activated.
ObservabilityPipelineSensitiveDataScannerProcessorScopeExcludeTarget
string
Excludes specific fields from processing.
ServiceDefinitionV2Email
object
Service owner's email.
3 properties 2 required
IncidentFieldAttributesSingleValue
object
A field with a single value selected.
2 properties
ServiceDefinitionCreateResponse
object
Create service definitions response.
1 property
EscalationTargets
object
A list of escalation targets for a step
1 property
DowntimeMonitorIncludedAttributes
object
Attributes of the monitor identified by the downtime.
1 property
RoleUpdateData
object
Data related to the update of a role.
4 properties 3 required
WorkflowDataRelationships
object
The definition of WorkflowDataRelationships object.
2 properties
ApplicationSecurityWafCustomRuleMetadata
object
Metadata associated with the WAF Custom Rule.
6 properties
CloudflareAccountUpdateRequest
object
Payload schema when updating a Cloudflare account.
1 property 1 required
UserResponseRelationships
object
Relationships of the user object returned by the API.
4 properties
ConfluentResourceResponse
object
Response schema when interacting with a Confluent resource.
1 property
UserTeamResponse
object
Team membership response
2 properties
RumMetricGroupBy
object
A group by rule.
2 properties 1 required
MonitorNotificationRuleFilterTags
object
Filter monitors by tags. Monitors must match all tags.
1 property 1 required
RetentionFilterUpdateAttributes
object
The object describing the configuration of the retention filter to create/update.
6 properties 5 required
Parameter
object
The definition of Parameter object.
2 properties 2 required
TeamPermissionSettingUpdate
object
Team permission setting update
2 properties 1 required
ApplicationSecurityWafCustomRuleUpdateRequest
object
Request object that includes the Custom Rule to update.
1 property 1 required
ActionConnectionData
object
Data related to the connection.
3 properties 2 required
ObservabilityPipelineSyslogNgDestination
object
The syslogng destination forwards logs to an external syslog-ng server over TCP or UDP using the syslog protocol.
5 properties 3 required
ObservabilityPipelineEnrichmentTableFileKeyItems
object
Defines how to map log fields to enrichment table columns during lookups.
3 properties 3 required
EntityV3APISpecInterface
The API definition.
CustomDestinationResponseHttpDestinationAuthBasicType
string
Type of the basic access authentication.
SecurityMonitoringRuleImpossibleTravelOptionsBaselineUserLocations
boolean
If true, signals are suppressed for the first 24 hours. In that time, Datadog learns the user's regular access locations. This can be helpful to reduce noise a…
ObservabilityPipelineDatadogAgentSource
object
The datadogagent source collects logs from the Datadog Agent.
3 properties 2 required
RelationshipToUsers
object
Relationship to users.
1 property 1 required
ActionConnectionIntegration
The definition of ActionConnectionIntegration object.
ChangeEventTriggerWrapper
object
Schema for a Change Event-based trigger.
2 properties 1 required
CloudWorkloadSecurityAgentRuleResponse
object
Response object that includes an Agent rule
1 property
AppMeta
object
Metadata of an app.
9 properties
PermissionsType
string
Permissions resource type.
RelationshipItem
object
Relationship entry.
2 properties
ComponentGridType
string
The grid component type.
CustomFrameworkRequirement
object
Framework Requirement.
2 properties 2 required
MetricTagConfigurationResponse
object
Response object which includes a single metric's tag configuration.
1 property
IncidentTypePatchRequest
object
Patch request for an incident type.
1 property 1 required
IncidentServiceResponseData
object
Incident Service data from responses.
4 properties 2 required
DowntimeUpdateRequestAttributes
object
Attributes of the downtime to update.
8 properties
StateVariable
object
A variable, which can be set and read by other components in the app.
4 properties 4 required
SpansMetricComputeIncludePercentiles
boolean
Toggle to include or exclude percentile aggregations for distribution metrics. Only present when the aggregationtype is distribution.
AWSLogsConfig
object
AWS Logs Collection config.
1 property
CloudWorkloadSecurityAgentPolicyUpdateRequest
object
Request object that includes the Agent policy with the attributes to update
1 property 1 required
LogsMetricResponseAttributes
object
The object describing a Datadog log-based metric.
3 properties
IncidentPostmortemType
string
Incident postmortem resource type.
SensitiveDataScannerIncludedKeywordConfiguration
object
Object defining a set of keywords and a number of characters that help reduce noise. You can provide a list of keywords you would like to check within a define…
3 properties 2 required
IPAllowlistType
string
IP allowlist type.
EscalationTarget
Represents an escalation target, which can be a team, user, or schedule.
ApplicationSecurityWafCustomRuleCondition
object
One condition of the WAF Custom Rule.
2 properties 2 required
ObservabilityPipelineOpenSearchDestinationType
string
The destination type. The value should always be opensearch.
CustomConnection
object
A custom connection used by an app.
3 properties
AppDefinitionType
string
The app definition type.
IncidentTodoAssignee
A todo assignee.
SensitiveDataScannerMetaVersionOnly
object
Meta payload containing information about the API.
1 property
ResourceFilterRequestType
string
Constant string to identify the request type.
IncidentTodoAssigneeArray
array
Array of todo assignees.
MicrosoftTeamsWorkflowsWebhookHandleResponseData
object
Workflows Webhook handle data from a response.
3 properties
CustomDestinationResponseHttpDestinationAuthBasic
object
Basic access authentication.
1 property 1 required
DatabaseMonitoringTriggerWrapper
object
Schema for a Database Monitoring-based trigger.
2 properties 1 required
RUMApplicationResponse
object
RUM application response.
1 property
ActionQueryMockedOutputsEnabled
Whether to enable the mocked outputs for testing.
ObservabilityPipelineSumoLogicDestination
object
The sumologic destination forwards logs to Sumo Logic.
8 properties 3 required
EntityResponseIncludedSchemaAttributes
object
Included schema.
1 property
MonitorNotificationRuleResponse
object
A monitor notification rule.
2 properties
SensitiveDataScannerConfigurationType
string
Sensitive Data Scanner configuration type.
CaseRelationships
object
Resources related to a case
4 properties
Schedule
object
Top-level container for a schedule object, including both the data payload and any related included resources (such as teams, layers, or members).
2 properties
EntityToIncidents
object
Entity to incidents relationship.
1 property
LogsArchiveCreateRequestDestination
An archive's destination.
IncidentUpdateRequest
object
Update request for an incident.
1 property 1 required
ObservabilityPipelineRemoveFieldsProcessor
object
The removefields processor deletes specified fields from logs.
5 properties 5 required
DowntimeScheduleRecurrenceDuration
string
The length of the downtime. Must begin with an integer and end with one of 'm', 'h', d', or 'w'.
AnnotationMarkdownTextAnnotation
object
The definition of AnnotationMarkdownTextAnnotation object.
1 property
OutputSchemaParameters
object
The definition of OutputSchemaParameters object.
6 properties 2 required
RumMetricResponseGroupBy
object
A group by rule.
2 properties
EntityV3QueueSpec
object
The definition of Entity V3 Queue Spec object.
4 properties
DowntimeUpdateRequestData
object
Object to update a downtime.
3 properties 3 required
UserTeamAttributes
object
Team membership attributes
3 properties
ServiceDefinitionV1Pagerduty
string
PagerDuty service URL for the service.
UserTeam
object
A user's relationship with a team
4 properties 2 required
ObservabilityPipelineAddFieldsProcessor
object
The addfields processor adds static key-value fields to logs.
5 properties 5 required
ObservabilityPipelineLogstashSource
object
The logstash source ingests logs from a Logstash forwarder.
3 properties 2 required
CloudWorkloadSecurityAgentPolicyResponse
object
Response object that includes an Agent policy
1 property
CustomFrameworkControl
object
Framework Control.
2 properties 2 required
ScheduleUserType
string
Users resource type.
UpdateOpenAPIResponseAttributes
object
Attributes for UpdateOpenAPI.
1 property
ObservabilityPipelineAddFieldsProcessorType
string
The processor type. The value should always be addfields.
AppRelationship
object
The app's publication relationship and custom connections.
2 properties
ServiceDefinitionV2Doc
object
Service documents.
3 properties 2 required
MicrosoftTeamsTenantBasedHandleResponseData
object
Tenant-based handle data from a response.
3 properties
FastlyAccountUpdateRequestData
object
Data object for updating a Fastly account.
2 properties
ObservabilityPipelineEnrichmentTableProcessor
object
The enrichmenttable processor enriches logs using a static CSV file or GeoIP database.
7 properties 5 required
SpansMetricID
string
The name of the span-based metric.
IncidentTeamUpdateData
object
Incident Team data for an update request.
4 properties 1 required
ServiceDefinitionV2Repo
object
Service code repositories.
3 properties 2 required
ServiceDefinitionV1Resource
object
Service's external links.
3 properties 3 required
IncidentImpactsType
string
The incident impacts type.
RelationshipToRoleData
object
Relationship to role object.
2 properties
UpdateOpenAPIResponseData
object
Data envelope for UpdateOpenAPIResponse.
2 properties
RumRetentionFilterUpdateData
object
The new RUM retention filter properties to update.
3 properties 3 required
EntityV3SystemDatadog
object
Datadog product integrations for the service entity.
4 properties
ConfluentAccountType
string
The JSON:API type for this API. Should always be confluent-cloud-accounts.
ExternalUser
object
Definition of a user.
8 properties
FastlyAccountType
string
The JSON:API type for this API. Should always be fastly-accounts.
ObservabilityPipelineAmazonOpenSearchDestinationAuth
object
Authentication settings for the Amazon OpenSearch destination. The strategy field determines whether basic or AWS-based authentication is used.
5 properties 1 required
SpansMetricResponseData
object
The span-based metric properties.
3 properties
AWSTracesConfig
object
AWS Traces Collection config.
1 property
CloudWorkloadSecurityAgentPolicyUpdaterAttributes
object
The attributes of the user who last updated the policy
2 properties
AWSRegionsIncludeOnly
object
Include only these regions.
1 property 1 required
SensitiveDataScannerRuleData
object
Rules included in the group.
1 property
UrlParamUpdate
object
The definition of UrlParamUpdate object.
3 properties 1 required
CustomDestinationResponseForwardDestinationSplunk
object
The Splunk HTTP Event Collector (HEC) destination.
2 properties 2 required
TokenName
string
Name for tokens.
SensitiveDataScannerGroupType
string
Sensitive Data Scanner group type.
PowerpackResponse
object
Response object which includes a single powerpack configuration.
2 properties
OktaAccountUpdateRequestAttributes
object
Attributes object for updating an Okta account.
5 properties 2 required
ServiceDefinitionRaw
string
Service Definition in raw JSON/YAML representation.
DowntimeResponse
object
Downtiming gives you greater control over monitor notifications by allowing you to globally exclude scopes from alerting. Downtime settings, which can be sched…
2 properties
RelationshipToUserTeamUserData
object
A user's relationship with a team
2 properties 2 required
ServiceDefinitionV2Dot1Opsgenie
object
Opsgenie integration for the service.
2 properties 1 required
ActionQueryProperties
object
The properties of the action query.
9 properties 1 required
AppDeploymentType
string
The deployment type.
SecurityMonitoringStandardRuleResponse
object
Rule.
24 properties
EscalationPolicyUpdateRequestData
object
Represents the data for updating an existing escalation policy, including its ID, attributes, relationships, and resource type.
4 properties 3 required
PowerpackInnerWidgets
object
Powerpack group widget definition of individual widgets.
2 properties 1 required
SecurityMonitoringRuleDetectionMethod
string
The detection method.
SecurityMonitoringSuppressionUpdateData
object
The new suppression properties; partial updates are supported.
2 properties 2 required
ObservabilityPipelineQuotaProcessor
object
The Quota Processor measures logging traffic for logs that match a specified filter. When the configured daily quota is met, the processor can drop or alert.
11 properties 7 required
UserTargetType
string
Indicates that the resource is of type users.
Annotation
object
A list of annotations used in the workflow. These are like sticky notes for your workflow!
3 properties 3 required
SecurityMonitoringRuleNewValueOptionsLearningThreshold
integer
A number of occurrences after which signals will be generated for values that weren't learned.
RUMApplicationUpdateType
string
RUM application update type.
RelationshipToIncidentPostmortemData
object
The postmortem relationship data.
2 properties 2 required
EntityV3
Entity schema v3.
ComponentType
string
The UI component type.
GithubWebhookTrigger
object
Trigger a workflow from a GitHub webhook. To trigger a workflow from GitHub, you must set a webhookSecret. In your GitHub Webhook Settings, set the Payload URL…
1 property
IncidentIntegrationMetadataType
string
Integration metadata resource type.
TeamLink
object
Team link
3 properties 3 required
DeploymentAttributes
object
The attributes object containing the version ID of the published app.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorRule
object
Defines a rule for detecting sensitive data, including matching pattern, scope, and the action to take.
6 properties 5 required
DeploymentRelationship
object
Information pointing to the app's publication status.
2 properties
DowntimeScheduleRecurrenceRrule
string
The RRULE standard for defining recurring events. For example, to have a recurring event on the first day of each month, set the type to rrule and set the FREQ…
UserAttributesStatus
string
The user's status.
WidgetLiveSpan
string
The available timeframes depend on the widget you are using.
MonitorNotificationRuleUpdateRequestData
object
Object to update a monitor notification rule.
3 properties 2 required
EscalationPolicyStepAttributesAssignment
string
Specifies how this escalation step will assign targets (example default or round-robin).
SecurityMonitoringRuleDecreaseCriticalityBasedOnEnv
boolean
If true, signals in non-production environments have a lower severity than what is defined by the rule case, which can reduce signal noise. The severity is dec…
JiraIntegrationMetadataIssuesItem
object
Item in the Jira integration metadata issue array.
5 properties 2 required
ApplicationSecurityWafCustomRuleConditionInputAddress
string
Input from the request on which the condition should apply.
EscalationPolicyUserType
string
Users resource type.
RelationshipToUser
object
Relationship to user.
1 property 1 required
AWSAccountID
string
AWS Account ID.
ObservabilityPipelineGeneratedMetricIncrementByFieldStrategy
string
Uses a numeric field in the log event as the metric increment.
IncidentFieldAttributesSingleValueType
string
Type of the single value field definitions.
SensitiveDataScannerStandardPatternData
object
A standard pattern.
1 property
ComponentGridProperties
object
Properties of a grid component.
3 properties
CloudWorkloadSecurityAgentPolicyUpdateAttributes
object
Update an existing Cloud Workload Security Agent policy
5 properties
TriggerRateLimit
object
Defines a rate limit for a trigger.
2 properties
ObservabilityPipelineAmazonDataFirehoseSource
object
The amazondatafirehose source ingests logs from AWS Data Firehose.
4 properties 2 required
SpansMetricResponseCompute
object
The compute rule to compute the span-based metric.
3 properties
ObservabilityPipelineRsyslogDestination
object
The rsyslog destination forwards logs to an external rsyslog server over TCP or UDP using the syslog protocol.
5 properties 3 required
ObservabilityPipelineSensitiveDataScannerProcessorActionHash
object
Configuration for hashing matched sensitive values.
2 properties 1 required
ServiceDefinitionV2Dot2Version
string
Schema version being used.
EscalationPolicy
object
Represents a complete escalation policy response, including policy data and optionally included related resources.
2 properties
ObservabilityPipelineSensitiveDataScannerProcessorKeywordOptions
object
Configuration for keywords used to reinforce sensitive data pattern detection.
2 properties 2 required
ObservabilityPipelineSumoLogicSourceType
string
The source type. The value should always be sumologic.
SpansMetricResponseFilter
object
The span-based metric filter. Spans matching this filter will be aggregated in this metric.
1 property
ApplicationSecurityWafCustomRuleConditionInput
object
Input from the request on which the condition should apply.
2 properties 1 required
FastlyAccounResponseAttributes
object
Attributes object of a Fastly account.
2 properties 1 required
ObservabilityPipelineSentinelOneDestinationType
string
The destination type. The value should always be sentinelone.
ApplicationSecurityWafCustomRuleScope
object
The scope of the WAF custom rule.
2 properties 2 required
ActionQuerySpecConnectionGroup
object
The connection group to use for an action query.
2 properties
SecurityMonitoringThirdPartyRuleCase
object
Case when signal is generated by a third party rule.
4 properties
MonitorNotificationRuleResponseIncludedItem
An object related to a monitor notification rule.
AWSAuthConfigKeys
object
AWS Authentication config to integrate your account using an access key pair.
2 properties 1 required
XRayServicesList
AWS X-Ray services to collect traces from. Defaults to includeonly.
HTTPCredentialsUpdate
The definition of HTTPCredentialsUpdate object.
OpsgenieServiceType
string
Opsgenie service resource type.
IncidentFieldAttributes
Dynamic fields for which selections can be made, with field names as keys.
RestrictionPolicyBinding
object
Specifies which principals are associated with a relation.
2 properties 2 required
APITriggerWrapper
object
Schema for an API-based trigger.
2 properties 1 required
ObservabilityPipelineSumoLogicDestinationHeaderCustomFieldsItem
object
Single key-value pair used as a custom log header for Sumo Logic.
2 properties 2 required
RuleId
string
The unique ID for a scorecard rule.
HTTPTokenAuthType
string
The definition of HTTPTokenAuthType object.
TeamRelationshipsLinks
object
Links attributes.
1 property
TeamPermissionSettingUpdateRequest
object
Team permission setting update request
1 property 1 required
AWSResourcesConfig
object
AWS Resources Collection config.
2 properties
AWSAccountResponseAttributes
object
AWS Account response attributes.
11 properties 1 required
CompletionGate
object
Used to create conditions before running subsequent actions.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeAllTarget
string
Applies the rule to all fields.
ApplicationSecurityWafCustomRuleType
string
The type of the resource. The value should always be customrule.
RUMApplicationUpdateRequest
object
RUM application update request.
1 property 1 required
LogsMetricResponseFilter
object
The log-based metric filter. Logs matching this filter will be aggregated in this metric.
1 property
PowerpackTemplateVariable
object
Powerpack template variables.
4 properties 1 required
RestrictionQueryWithoutRelationships
object
Restriction query object returned by the API.
3 properties
ObservabilityPipelineRsyslogSource
object
The rsyslog source listens for logs over TCP or UDP from an rsyslog server using the syslog protocol.
4 properties 3 required
APITrigger
object
Trigger a workflow from an API request. The workflow must be published.
1 property
IncidentAttachmentAttributes
The attributes object for an attachment.
DowntimeRelationshipsCreatedByData
object
Data for the user who created the downtime.
2 properties
CaseUpdatePriorityAttributes
object
Case update priority attributes
1 property 1 required
ServiceDefinitionSchema
Service definition schema.
SensitiveDataScannerRuleAttributes
object
Attributes of the Sensitive Data Scanner rule.
10 properties
ActionQuerySpecInputs
The inputs to the action query. These are the values that are passed to the action when it is triggered.
MonitorNotificationRuleId
string
The ID of the monitor notification rule.
IncidentTodoAnonymousAssigneeSource
string
The source of the anonymous assignee.
MetricTagConfigurationType
string
The metric tag configuration resource type.
StepDisplayBounds
object
The definition of StepDisplayBounds object.
2 properties
ApiID
string
API identifier.
ObservabilityPipelineEnrichmentTableFileKeyItemsComparison
string
Defines how to compare key fields for enrichment table lookups.
SecurityMonitoringSignalRuleResponse
object
Rule.
18 properties
EntityV3APISpecInterfaceDefinition
object
The definition of EntityV3APISpecInterfaceDefinition object.
1 property
ObservabilityPipelineParseGrokProcessorRuleMatchRule
object
Defines a Grok parsing rule, which extracts structured fields from log content using named Grok patterns. Each rule must have a unique name and a valid Datadog…
2 properties 2 required
CaseUpdateStatusRequest
object
Case update status request
1 property 1 required
RoleUpdateAttributes
object
Attributes of the role.
4 properties
AWSLambdaForwarderConfig
object
Log Autosubscription configuration for Datadog Forwarder Lambda functions. Automatically set up triggers for existing and new logs for some services, ensuring…
2 properties
ObservabilityPipelineParseJSONProcessor
object
The parsejson processor extracts JSON from a specified field and flattens it into the event. This is useful when logs contain embedded JSON as a string.
5 properties 5 required
IPAllowlistEntryType
string
IP allowlist Entry type.
UpdateOpenAPIResponse
object
Response for UpdateOpenAPI.
1 property
RelationshipToOrganization
object
Relationship to an organization.
1 property 1 required
IncidentAttachmentLinkAttachmentType
string
The type of link attachment attributes.
ComponentGridPropertiesIsVisible
Whether the grid component and its children are visible. If a string, it must be a valid JavaScript expression that evaluates to a boolean.
IncidentTodoRelationships
object
The incident's relationships from a response.
2 properties
ObservabilityPipelineReduceProcessorMergeStrategy
object
Defines how a specific field should be merged across grouped events.
2 properties 2 required
ServiceDefinitionV2Integrations
object
Third party integrations that Datadog supports.
2 properties
FastlyAccountUpdateRequest
object
Payload schema when updating a Fastly account.
1 property 1 required
AwsCURConfigsResponse
object
List of AWS CUR configs.
1 property
ObservabilityPipelineAmazonDataFirehoseSourceType
string
The source type. The value should always be amazondatafirehose.
AWSAssumeRoleUpdate
object
The definition of AWSAssumeRoleUpdate object.
4 properties 1 required
EntityResponseData
array
List of entity data.
DashboardListItemResponse
object
A dashboard within a list.
2 properties 2 required
SecurityMonitoringRuleKeepAlive
integer
Once a signal is generated, the signal will remain "open" if a case is matched at least once within this keep alive window. For third party detection method, t…
ReadinessGateThresholdType
string
The definition of ReadinessGateThresholdType object.
CaseResourceType
string
Case resource type
ObservabilityPipelineDedupeProcessorType
string
The processor type. The value should always be dedupe.
ServiceDefinitionV2Dot2Pagerduty
object
PagerDuty integration for the service.
1 property
ObservabilityPipelineSentinelOneDestinationRegion
string
The SentinelOne region to send logs to.
AzureUCConfigPatchData
object
Azure config Patch data.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptions
object
Controls how partial redaction is applied, including character count and direction.
2 properties 2 required
ObservabilityPipelineGeneratedMetricIncrementByField
object
Strategy that increments a generated metric based on the value of a log field.
2 properties 2 required
Weekday
string
A day of the week.
RestrictionQueryUpdatePayload
object
Update a restriction query.
1 property
DashboardType
string
The type of the dashboard.
DataTransformProperties
object
The properties of the data transformer.
1 property
EscalationPolicyStepRelationships
object
Represents the relationship of an escalation policy step to its targets.
1 property
IncidentFieldAttributesMultipleValue
object
A field with potentially multiple values selected.
2 properties
LogsMetricGroupBy
object
A group by rule.
2 properties 1 required
ObservabilityPipelineGeneratedMetricMetricType
string
Type of metric to create.
OrgConfigWriteAttributes
object
Writable attributes of an Org Config.
1 property 1 required
DowntimeScheduleRecurrencesUpdateRequest
object
A recurring downtime schedule definition.
2 properties
CustomDestinationResponseForwardDestination
A custom destination's location to forward logs.
RelationshipToRule
object
Scorecard create rule response relationship.
1 property
SecurityMonitoringRuleImpossibleTravelOptions
object
Options on impossible travel detection method.
1 property
OktaAccountAttributes
object
Attributes object for an Okta account.
6 properties 3 required
AzureUCConfigPairType
string
Type of Azure config pair.
CustomDestinationForwardDestination
A custom destination's location to forward logs.
Case3rdPartyTicketStatus
string
Case status
UserTeamTeamType
string
User team team type
TeamAttributes
object
Team attributes
12 properties 2 required
Role
object
Role object returned by the API.
4 properties 1 required
CloudConfigurationComplianceRuleOptions
object
Options for cloudconfiguration rules. Fields resourceType and regoRule are mandatory when managing custom cloudconfiguration rules.
3 properties
CustomDestinationResponseElasticsearchDestinationAuth
object
Basic access authentication.
ServiceDefinitionV2Dot1Pagerduty
object
PagerDuty integration for the service.
1 property
OutboundEdge
object
The definition of OutboundEdge object.
2 properties 2 required
ScheduleRequestDataAttributesLayersItemsMembersItems
object
Defines a single member within a schedule layer, including the reference to the underlying user.
1 property
IncidentServiceIncludedItems
An object related to an incident service which is present in the included payload.
UserUpdateAttributes
object
Attributes of the edited user.
3 properties
MonitorNotificationRuleRecipients
array
A list of recipients to notify. Uses the same format as the monitor message field. Must not start with an '@'.
ObservabilityPipelineSensitiveDataScannerProcessorCustomPatternOptions
object
Options for defining a custom regex pattern.
1 property 1 required
CloudflareAccountType
string
The JSON:API type for this API. Should always be cloudflare-accounts.
ObservabilityPipelineAwsAuth
object
AWS authentication credentials used for accessing AWS services such as S3. If omitted, the system’s default credentials are used (for example, the IAM role and…
3 properties
ObservabilityPipelineConfigProcessorItem
A processor for the pipeline.
ConfluentAccountUpdateRequestData
object
Data object for updating a Confluent account.
2 properties 2 required
IncidentAttachmentUpdateAttributes
Incident attachment attributes.
CustomDestinationResponseDefinition
object
The definition of a custom destination.
3 properties
ServiceDefinitionV2LinkType
string
Link type.
ObservabilityPipelineReduceProcessor
object
The reduce processor aggregates and merges logs based on matching keys and merge strategies.
6 properties 6 required
RumMetricResponseFilter
object
The rum-based metric filter. RUM events matching this filter will be aggregated in this metric.
1 property
IncidentAttachmentsResponseIncludedItem
An object related to an attachment that is included in the response.
CustomConnectionType
string
The custom connection type.
ConfluentAccountResponse
object
The expected response schema when getting a Confluent account.
1 property
SecurityMonitoringFilter
object
The rule's suppression filter.
2 properties
UpdateAppRequest
object
A request object for updating an existing app.
1 property
RumMetricUpdateCompute
object
The compute rule to compute the rum-based metric.
1 property
EscalationPolicyUpdateRequestDataRelationships
object
Represents relationships in an escalation policy update request, including references to teams.
1 property
JiraIssueResult
object
Jira issue information
4 properties
LogsArchiveDestinationGCSType
string
Type of the GCS archive destination.
UpdateCustomFrameworkResponse
object
Response object to update a custom framework.
1 property 1 required
ScheduleRequestDataAttributesLayersItemsMembersItemsUser
object
Identifies the user participating in this layer as a single object with an id.
1 property
TeamLinkAttributes
object
Team link attributes
4 properties 2 required
ActionQuery
object
An action query. This query type is used to trigger an action, such as sending a HTTP request.
5 properties 4 required
PermissionAttributes
object
Attributes of a permission.
7 properties
ActionQueryPollingIntervalInMs
If specified, the app will poll the query at the specified interval in milliseconds. The minimum polling interval is 15 seconds. The query will only poll when…
LogsMetricResponse
object
The log-based metric object.
1 property
ApplicationSecurityWafExclusionFilterResponse
object
Response object for a single WAF exclusion filter.
1 property
SlackIntegrationMetadata
object
Incident integration metadata for the Slack integration.
1 property 1 required
IncidentServiceUpdateData
object
Incident Service payload for update requests.
4 properties 1 required
SecurityFilterUpdateRequest
object
The new security filter body.
1 property 1 required
IncidentTodoResponseData
object
Incident todo response data.
4 properties 2 required
SensitiveDataScannerTextReplacement
object
Object describing how the scanned event will be replaced.
3 properties
ApplicationSecurityWafCustomRuleUpdateData
object
Object for a single WAF Custom Rule.
2 properties 2 required
RelationshipToIncidentIntegrationMetadataData
object
A relationship reference for an integration metadata object.
2 properties 2 required
CloudWorkloadSecurityAgentRuleData
object
Object for a single Agent rule
3 properties
AWSAccountResponseData
object
AWS Account response data.
3 properties 2 required
MonitorNotificationRuleRelationshipsCreatedBy
object
The user who created the monitor notification rule.
1 property
LayerRelationshipsMembers
object
Holds an array of references to the members of a Layer, each containing member IDs.
1 property
LogsMetricUpdateAttributes
object
The log-based metric properties that will be updated.
3 properties
JSONAPIErrorItemSource
object
References to the source of the error.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorScopeInclude
object
Includes only specific fields for sensitive data scanning.
2 properties 2 required
EntityV3Datastore
object
Schema for datastore entities.
7 properties 3 required
IncidentServiceType
string
Incident service resource type.
GCPSTSServiceAccountUpdateRequestData
object
Data on your service account.
3 properties
EntityResponseMeta
object
Entity metadata.
2 properties
LogsArchiveCreateRequestDefinition
object
The definition of an archive.
2 properties 1 required
SecurityTrigger
object
Trigger a workflow from a Security Signal or Finding. For automatic triggering a handle must be configured and the workflow must be published.
1 property
AwsCURConfigAttributes
object
Attributes for An AWS CUR config.
12 properties 6 required
IncidentServiceUpdateAttributes
object
The incident service's attributes for an update request.
1 property 1 required
CloudflareAccountUpdateRequestAttributes
object
Attributes object for updating a Cloudflare account.
5 properties 1 required
ServiceDefinitionV2Dot1EmailType
string
Contact type.
TeamPermissionSettingType
string
Team permission setting type
IncidentTodoResponse
object
Response with an incident todo.
2 properties 1 required
ObservabilityPipelineEnrichmentTableFileSchemaItems
object
Describes a single column and its type in an enrichment table schema.
2 properties 2 required
ObservabilityPipelineNewRelicDestinationType
string
The destination type. The value should always be newrelic.
CloudWorkloadSecurityAgentRuleID
string
The ID of the Agent rule
HTTPCredentials
The definition of HTTPCredentials object.
ConnectionEnv
object
A list of connections or connection groups used in the workflow.
3 properties 1 required
AzureUCConfigPatchRequest
object
Azure config Patch Request.
1 property 1 required
RumMetricResponseCompute
object
The compute rule to compute the rum-based metric.
3 properties
RestrictionPolicy
object
Restriction policy object.
3 properties 3 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactAction
string
Action type that redacts part of the sensitive data while preserving a configurable number of characters, typically used for masking purposes (e.g., show last…
ExternalUserMeta
object
Metadata associated with a user.
4 properties
CustomFrameworkDataAttributes
object
Framework Data Attributes.
6 properties 4 required
ExternalUserGroup
object
Definition of a group.
6 properties
CustomDestinationResponseForwardDestinationHttpType
string
Type of the HTTP destination.
ConfluentResourceResponseData
object
Confluent Cloud resource data.
3 properties 3 required
OktaAccountResponse
object
Response object for an Okta account.
1 property
LogsMetricResponseComputeAggregationType
string
The type of aggregation to use.
EntityToSchema
object
Entity to detail schema relationship.
1 property
SecurityMonitoringSignalRuleType
string
The rule type.
CloudWorkloadSecurityAgentRuleUpdateRequest
object
Request object that includes the Agent rule with the attributes to update
1 property 1 required
RumRetentionFilterUpdateAttributes
object
The object describing attributes of a RUM retention filter to update.
5 properties
IncidentTodoAnonymousAssignee
object
Anonymous assignee entity.
4 properties 4 required
UserResourceType
string
User resource type.
CustomDestinationType
string
The type of the resource. The value should always be customdestination.
PowerpackInnerWidgetLayout
object
Powerpack inner widget layout.
4 properties 4 required
EntityV3APISpec
object
The definition of Entity V3 API Spec object.
5 properties
IncidentAttachmentData
object
A single incident attachment.
4 properties 4 required
CaseType
string
Case type
RetryStrategy
object
The definition of RetryStrategy object.
2 properties 1 required
RetryStrategyKind
string
The definition of RetryStrategyKind object.
MonitorNotificationRuleRelationshipsCreatedByData
object
Data for the user who created the monitor notification rule.
2 properties
SecurityFilterResponse
object
Response object which includes a single security filter.
2 properties
AWSAccountTags
array
Tags to apply to all hosts and metrics reporting for this account. Defaults to [].
ObservabilityPipelineGoogleCloudStorageDestination
object
The googlecloudstorage destination stores logs in a Google Cloud Storage (GCS) bucket. It requires a bucket name, GCP authentication, and metadata fields.
9 properties 7 required
IncidentTypeUpdateAttributes
object
Incident type's attributes for updates.
8 properties
ServiceDefinitionV1Integrations
object
Third party integrations that Datadog supports.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorCustomPattern
object
Defines a custom regex-based pattern for identifying sensitive data in logs.
2 properties 2 required
CloudWorkloadSecurityAgentRuleKill
object
Kill system call applied on the container matching the rule
1 property
ConfluentAccountUpdateRequest
object
The JSON:API request for updating a Confluent account.
1 property 1 required
UpdateActionConnectionRequest
object
Request used to update an action connection.
1 property 1 required
UserAttributes
object
Attributes of user object returned by the API.
12 properties
ApplicationSecurityWafCustomRuleConditionParameters
object
The scope of the WAF custom rule.
6 properties 1 required
SensitiveDataScannerTextReplacementType
string
Type of the replacement text. None means no replacement. hash means the data will be stubbed. replacementstring means that one can chose a text to replace the…
IncidentType
string
Incident resource type.
Component
object
[Definition of a UI component in the app](https://docs.datadoghq.com/servicemanagement/appbuilder/components/)
5 properties 3 required
SpansMetricFilter
object
The span-based metric filter. Spans matching this filter will be aggregated in this metric.
1 property
EntityV3DatadogIntegrationOpsgenie
object
An Opsgenie integration schema.
2 properties 1 required
IncidentIntegrationMetadataResponseData
object
Incident integration metadata from a response.
4 properties 2 required
InputSchema
object
A list of input parameters for the workflow. These can be used as dynamic runtime values in your workflow.
1 property
UserTarget
object
Represents a user target for an escalation policy step, including the user's ID and resource type.
2 properties 2 required
SecurityMonitoringSuppressionResponse
object
Response object containing a single suppression rule.
1 property
SecurityFilterMeta
object
Optional metadata associated to the response.
1 property
AwsCURConfigPatchRequestAttributes
object
Attributes for AWS CUR config Patch Request.
2 properties
RoleAttributes
object
Attributes of the role.
4 properties
LogsArchiveIntegrationAzure
object
The Azure archive's integration destination.
2 properties 2 required
IncidentUpdateData
object
Incident data for an update request.
4 properties 2 required
User
object
User object returned by the API.
4 properties
EntityV3DatastoreKind
string
The definition of Entity V3 Datastore Kind object.
ObservabilityPipelineSensitiveDataScannerProcessor
object
The sensitivedatascanner processor detects and optionally redacts sensitive data in log events.
5 properties 5 required
CaseUpdateStatus
object
Case update status
2 properties 2 required
ObservabilityPipelineDatadogLogsDestinationType
string
The destination type. The value should always be datadoglogs.
RelationshipToIncidentAttachment
object
A relationship reference for attachments.
1 property 1 required
UserTeamRole
string
The user's role within the team
ActionQueryMockedOutputs
The mocked outputs of the action query. This is useful for testing the app without actually running the action.
EntityV3Integrations
object
A base schema for defining third-party integrations.
2 properties
Powerpack
object
Powerpacks are templated groups of dashboard widgets you can save from an existing dashboard and turn into reusable packs in the widget tray.
1 property
TeamUpdateRequest
object
Team update request
1 property 1 required
HTTPIntegrationType
string
The definition of HTTPIntegrationType object.
ConfluentAccountResponseData
object
An API key and API secret pair that represents a Confluent account.
3 properties 3 required
EmailTypeType
string
The type of email.
ObservabilityPipelineGenerateMetricsProcessor
object
The generatedatadogmetrics processor creates custom metrics from logs and sends them to Datadog. Metrics can be counters, gauges, or distributions and optional…
5 properties 5 required
EntityMeta
object
Entity metadata.
4 properties
ScheduleTriggerWrapper
object
Schema for a Schedule-based trigger.
2 properties 1 required
IncidentResponseData
object
Incident data from a response.
4 properties 2 required
PowerpackData
object
Powerpack data object.
4 properties
DeploymentRelationshipData
object
Data object containing the deployment ID.
2 properties
IncidentUserDefinedFieldType
string
The incident user defined fields type.
MonitorNotificationRuleResourceType
string
Monitor notification rule resource type.
OrganizationsType
string
Organizations resource type.
ServiceDefinitionV2OpsgenieRegion
string
Opsgenie instance region.
ApplicationSecurityWafCustomRuleConditionOptions
object
Options for the operator of this condition.
2 properties
CaseTriggerWrapper
object
Schema for a Case-based trigger.
2 properties 1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedactOptionsDirection
string
Indicates whether to redact characters from the first or last part of the matched value.
EntityResponseIncludedSchema
object
Included detail entity schema.
3 properties
UserUpdateData
object
Object to update a user.
3 properties 3 required
RumMetricResponseUniqueness
object
The rule to count updatable events. Is only set if eventtype is session or view.
1 property
ObservabilityPipelineElasticsearchDestinationApiVersion
string
The Elasticsearch API version to use. Set to auto to auto-detect.
ServiceDefinitionV2Contact
Service owner's contacts information.
WorkflowUserRelationshipType
string
The definition of WorkflowUserRelationshipType object.
IncidentTodoPatchRequest
object
Patch request for an incident todo.
1 property 1 required
ObservabilityPipelinePipelineKafkaSourceSaslMechanism
string
SASL mechanism used for Kafka authentication.
DowntimeUpdateRequest
object
Request for editing a downtime.
1 property 1 required
RelationshipToOrganizationData
object
Relationship to organization object.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPattern
object
Specifies a pattern from Datadog’s sensitive data detection library to match known sensitive data types.
2 properties 2 required
DashboardTriggerWrapper
object
Schema for a Dashboard-based trigger.
2 properties 1 required
XRayServicesIncludeOnly
object
Include only these services. Defaults to [].
1 property 1 required
OrgConfigGetResponse
object
A response with a single Org Config.
1 property 1 required
PowerpackGroupWidget
object
Powerpack group widget definition object.
3 properties 1 required
CustomDestinationResponseAttributes
object
The attributes associated with the custom destination.
7 properties
SecurityFilterFilteredDataType
string
The filtered data type.
OpsgenieServiceRegionType
string
The region for the Opsgenie service.
CustomDestinationResponseForwardDestinationSplunkType
string
Type of the Splunk HTTP Event Collector (HEC) destination.
ProjectResourceType
string
Project resource type
RUMApplicationAttributes
object
RUM application attributes.
11 properties 9 required
ObservabilityPipelineGooglePubSubSource
object
The googlepubsub source ingests logs from a Google Cloud Pub/Sub subscription.
7 properties 6 required
OpsgenieServiceUpdateRequest
object
Update request for an Opsgenie service.
1 property 1 required
RoleUpdateResponse
object
Response containing information about an updated role.
1 property
PowerpackGroupWidgetLayout
object
Powerpack group widget layout.
4 properties 4 required
OpsgenieServiceUpdateData
object
Opsgenie service for an update request.
3 properties 3 required
ObservabilityPipelineOcsfMapperProcessorType
string
The processor type. The value should always be ocsfmapper.
IncidentAttachmentsPostmortemAttributesAttachmentObject
object
The postmortem attachment.
2 properties 2 required
ObservabilityPipelineKafkaSourceLibrdkafkaOption
object
Represents a key-value pair used to configure low-level librdkafka client options for Kafka sources, such as timeouts, buffer sizes, and security settings.
2 properties 2 required
LayerRelationships
object
Holds references to objects related to the Layer entity, such as its members.
1 property
DowntimeNotifyEndStateTypes
string
State that will trigger a monitor notification when the notifyendtypes action occurs.
DowntimeScheduleRecurrencesResponse
object
A recurring downtime schedule definition.
3 properties 1 required
SpansMetricResponse
object
The span-based metric object.
1 property
UserTeamUpdateRequest
object
Team membership request
1 property 1 required
UpdateAppRequestData
object
The data object containing the new app definition. Any fields not included in the request remain unchanged.
3 properties 1 required
ExternalUserEmailType
object
Email address for the user.
3 properties
TagFilter
object
Tag filter for the budget's entries.
2 properties
UpsertCatalogEntityResponse
object
Upsert entity response.
3 properties
SecurityMonitoringRuleEvaluationWindow
integer
A time window is specified to match when at least one of the cases matches true. This is a sliding window and evaluates in real time. For third party detection…
RUMApplicationUpdate
object
RUM application update.
3 properties 2 required
UserTeamRelationships
object
Relationship between membership and a user
2 properties
ObservabilityPipelineRenameFieldsProcessorType
string
The processor type. The value should always be renamefields.
ObservabilityPipelineHttpClientSourceType
string
The source type. The value should always be httpclient.
SecurityMonitoringFilterAction
string
The type of filtering action.
JSONAPIErrorResponse
object
API error response.
1 property 1 required
CaseTrigger
object
Trigger a workflow from a Case. For automatic triggering a handle must be configured and the workflow must be published.
1 property
IncidentNotificationHandle
object
A notification handle that will be notified at incident creation.
2 properties
CustomDestinationForwardDestinationHttpType
string
Type of the HTTP destination.
ActionQueryType
string
The action query type.
ScheduleDataRelationshipsLayersDataItems
object
Relates a layer to this schedule, identified by id and type (must be layers).
2 properties 2 required
MicrosoftTeamsUpdateTenantBasedHandleRequestData
object
Tenant-based handle data from a response.
2 properties 2 required
ApplicationSecurityWafExclusionFilterOnMatch
string
The action taken when the exclusion filter matches. When set to monitor, security traces are emitted but the requests are not blocked. By default, security tra…
ServiceDefinitionV2Link
object
Service's external links.
3 properties 3 required
ScheduleDataRelationshipsLayersDataItemsType
string
Layers resource type.
RelationshipToPermissionData
object
Relationship to permission object.
2 properties
AwsCURConfig
object
AWS CUR config.
3 properties 2 required
SpansFilterCreate
object
The spans filter. Spans matching this filter will be indexed and stored.
1 property 1 required
IPAllowlistEntry
object
IP allowlist entry object.
1 property 1 required
CloudWorkloadSecurityAgentRuleAction
object
The action the rule can perform if triggered
4 properties
HTTPTokenAuthUpdate
object
The definition of HTTPTokenAuthUpdate object.
5 properties 1 required
AppBuilderEventType
string
The response to the event.
SecurityMonitoringRuleCaseActionOptions
object
Options for the rule action
2 properties
TeamLinkCreate
object
Team link create
2 properties 2 required
TeamUpdateAttributes
object
Team update attributes
7 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorScopeIncludeTarget
string
Applies the rule only to included fields.
RoleRelationships
object
Relationships of the role object.
1 property
ConfluentResourceRequestData
object
JSON:API request for updating a Confluent resource.
3 properties 3 required
JiraIntegrationMetadata
object
Incident integration metadata for the Jira integration.
1 property 1 required
ObservabilityPipelineFilterProcessor
object
The filter processor allows conditional processing of logs based on a Datadog search query. Logs that match the include query are passed through; others are di…
4 properties 4 required
DeploymentMetadata
object
Metadata object containing the publication creation information.
4 properties
TeamPermissionSetting
object
Team permission setting
3 properties 2 required
EscalationPolicyStepTarget
object
Defines a single escalation target within a step for an escalation policy creation request. Contains id and type.
2 properties
IncidentTypeAttributes
object
Incident type's attributes.
8 properties 1 required
ObservabilityPipelineParseGrokProcessor
object
The parsegrok processor extracts structured fields from unstructured log messages using Grok patterns.
6 properties 5 required
ObservabilityPipelineSumoLogicDestinationType
string
The destination type. The value should always be sumologic.
SecurityMonitoringReferenceTable
object
Reference tables used in the queries.
5 properties
ServiceDefinitionDataAttributes
object
Service definition attributes.
2 properties
DowntimeScheduleRecurrenceResponse
object
An RRULE-based recurring downtime.
3 properties
ProjectRelationshipData
object
Relationship to project object
2 properties 2 required
IncidentResponse
object
Response with an incident.
2 properties 1 required
RUMApplicationType
string
RUM application response type.
ObservabilityPipelineElasticsearchDestinationType
string
The destination type. The value should always be elasticsearch.
RumRetentionFilterType
string
The type of the resource. The value should always be retentionfilters.
ObservabilityPipelineSplunkHecSource
object
The splunkhec source implements the Splunk HTTP Event Collector (HEC) API.
3 properties 2 required
ObservabilityPipelineAmazonS3SourceType
string
The source type. Always amazons3.
IncidentTodoAttributes
object
Incident todo's attributes.
7 properties 2 required
RumMetricEventType
string
The type of RUM events to filter on.
TeamResponse
object
Response with a team
1 property
CloudConfigurationRuleComplianceSignalOptions
object
How to generate compliance signals. Useful for cloudconfiguration rules only.
4 properties
DowntimeRelationships
object
All relationships associated with downtime.
2 properties
CustomDestinationForwardDestinationSplunkType
string
Type of the Splunk HTTP Event Collector (HEC) destination.
StateVariableProperties
object
The properties of the state variable.
1 property
LogsArchiveDestinationGCS
object
The GCS archive destination.
4 properties 3 required
ObservabilityPipelineThrottleProcessor
object
The throttle processor limits the number of events that pass through over a given time window.
7 properties 6 required
RumRetentionFilterEnabled
boolean
Whether the retention filter is enabled.
IncidentTodoType
string
Todo resource type.
NullableUserRelationship
object
Relationship to user.
1 property 1 required
LogsMetricResponseData
object
The log-based metric properties.
3 properties
UpsertCatalogEntityResponseIncludedItem
Upsert entity response included item.
ObservabilityPipelineQuotaProcessorOverflowAction
string
The action to take when the quota is exceeded. Options: - drop: Drop the event. - noaction: Let the event pass through. - overflowrouting: Route to an overflow…
CloudWorkloadSecurityAgentPolicyAttributes
object
A Cloud Workload Security Agent policy returned by the API
15 properties
ObservabilityPipelineSplunkHecSourceType
string
The source type. Always splunkhec.
LogsMetricType
string
The type of the resource. The value should always be logsmetrics.
EntityV3Metadata
object
The definition of Entity V3 Metadata object.
12 properties 1 required
Step
object
A Step is a sub-component of a workflow. Each Step performs an action.
9 properties 2 required
ScheduleTrigger
object
Trigger a workflow from a Schedule. The workflow must be published.
1 property 1 required
MicrosoftTeamsUpdateWorkflowsWebhookHandleRequest
object
Update Workflows webhook handle request.
1 property 1 required
SensitiveDataScannerGroupUpdateResponse
object
Update group response.
1 property
SecurityMonitoringRuleNewValueOptionsForgetAfter
integer
The duration in days after which a learned value is forgotten.
ObservabilityPipelineLogstashSourceType
string
The source type. The value should always be logstash.
SecurityFilterUpdateData
object
The new security filter properties.
2 properties 2 required
RelationshipToUserTeamPermission
object
Relationship between a user team permission and a team
2 properties
FastlyAccountResponse
object
The expected response schema when getting a Fastly account.
1 property
IncidentResponseRelationships
object
The incident's relationships from a response.
8 properties
RestrictionPolicyUpdateRequest
object
Update request for a restriction policy.
1 property 1 required
CustomDestinationAttributeTagsRestrictionListType
string
How forwardtagsrestrictionlist parameter should be interpreted. If ALLOWLIST, then only tags whose keys on the forwarded logs match the ones on the restriction…
ServiceDefinitionV2EmailType
string
Contact type.
RetentionFilterAllAttributes
object
The attributes of the retention filter.
12 properties
EscalationPolicyStepType
string
Indicates that the resource is of type steps.
AWSAccountResponse
object
AWS Account response body.
1 property 1 required
EntityV3APISpecInterfaceFileRef
object
The definition of EntityV3APISpecInterfaceFileRef object.
1 property
AwsCURConfigPatchData
object
AWS CUR config Patch data.
2 properties 2 required
LogsArchiveOrderAttributes
object
The attributes associated with the archive order.
1 property 1 required
LogsArchiveCreateRequest
object
The logs archive.
1 property
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternType
string
Indicates that a predefined library pattern is used.
CloudWorkloadSecurityAgentRuleUpdateAttributes
object
Update an existing Cloud Workload Security Agent rule
9 properties
Trigger
One of the triggers that can start the execution of a workflow.
DowntimeResponseAttributes
object
Downtime details.
12 properties
ServiceDefinitionV2SlackType
string
Contact type.
ScheduleDataRelationshipsLayers
object
Associates layers with this schedule in a data structure.
1 property
ObservabilityPipelineHttpClientSource
object
The httpclient source scrapes logs from HTTP endpoints at regular intervals.
7 properties 3 required
EscalationPolicyDataType
string
Indicates that the resource is of type policies.
ServiceDefinitionV2Dot2Integrations
object
Third party integrations that Datadog supports.
2 properties
ScheduleUpdateRequestDataType
string
Schedules resource type.
ServiceDefinitionMetaWarnings
object
Schema validation warnings.
3 properties
AWSIntegration
object
The definition of AWSIntegration object.
2 properties 2 required
SecurityMonitoringRuleOptions
object
Options.
10 properties
LogsArchiveDestinationS3Type
string
Type of the S3 archive destination.
OrgConfigRead
object
A single Org Config.
3 properties 3 required
IncidentAttachmentLinkAttributesAttachmentObject
object
The link attachment.
2 properties 2 required
ConnectionGroup
object
The definition of ConnectionGroup object.
3 properties 3 required
ComponentGrid
object
A grid component. The grid component is the root canvas for an app and contains all other components.
5 properties 3 required
ScheduleMember
object
Represents a single member entry in a schedule, referencing a specific user.
3 properties 1 required
IPAllowlistData
object
IP allowlist data.
3 properties 1 required
OktaAccountUpdateRequest
object
Payload schema when updating an Okta account.
1 property 1 required
ObservabilityPipelineAddEnvVarsProcessorType
string
The processor type. The value should always be addenvvars.
ApplicationSecurityWafExclusionFilterResource
object
A JSON:API resource for an WAF exclusion filter.
3 properties
SensitiveDataScannerRuleUpdate
object
Data related to the update of a rule.
4 properties
DowntimeRelationshipsCreatedBy
object
The user who created the downtime.
1 property
ObservabilityPipelineGeneratedMetricIncrementByOneStrategy
string
Increments the metric by 1 for each matching event.
AzureUCConfigPairAttributes
object
Attributes for Azure config pair.
2 properties 1 required
SecurityMonitoringSuppressionType
string
The type of the resource. The value should always be suppressions.
ObservabilityPipelineSyslogNgSource
object
The syslogng source listens for logs over TCP or UDP from a syslog-ng server using the syslog protocol.
4 properties 3 required
SecurityMonitoringSuppressionAttributes
object
The attributes of the suppression rule.
14 properties
HTTPHeaderUpdate
object
The definition of HTTPHeaderUpdate object.
3 properties 1 required
RelationshipToUserTeamTeam
object
Relationship between team membership and team
1 property 1 required
CloudWorkloadSecurityAgentPolicyData
object
Object for a single Agent policy
3 properties
RetryStrategyLinear
object
The definition of RetryStrategyLinear object.
2 properties 2 required
RumMetricResponseAttributes
object
The object describing a Datadog rum-based metric.
5 properties
RumRetentionFilterSampleRate
integer
The sample rate for a RUM retention filter, between 0 and 100.
CompletionCondition
object
The definition of CompletionCondition object.
3 properties 2 required
ApplicationSecurityWafExclusionFilterUpdateRequest
object
Request object for updating a single WAF exclusion filter.
1 property 1 required
ServiceDefinitionV2Dot1OpsgenieRegion
string
Opsgenie instance region.
ProjectRelationship
object
Relationship to project
1 property 1 required
RumRetentionFilterID
string
ID of retention filter in UUID.
IncidentTeamResponse
object
Response with an incident team payload.
2 properties 1 required
ObservabilityPipelineSensitiveDataScannerProcessorScope
Determines which parts of the log the pattern-matching rule should be applied to.
UrlParam
object
The definition of UrlParam object.
2 properties 2 required
CloudWorkloadSecurityAgentPolicyID
string
The ID of the Agent policy
OpsgenieServiceResponseData
object
Opsgenie service data from a response.
3 properties 3 required
ApplicationSecurityWafCustomRuleAttributes
object
A WAF custom rule.
9 properties 5 required
ObservabilityPipelineParseJSONProcessorType
string
The processor type. The value should always be parsejson.
MetricName
string
The metric name for this resource.
ServiceDefinitionV2Dot2Opsgenie
object
Opsgenie integration for the service.
2 properties 1 required
RelationshipToRoles
object
Relationship to roles.
1 property
NotebookTriggerWrapper
object
Schema for a Notebook-based trigger.
2 properties 1 required
TeamPermissionSettingAttributes
object
Team permission setting attributes
5 properties
EntityV3SystemKind
string
The definition of Entity V3 System Kind object.
ObservabilityPipelineSyslogNgSourceType
string
The source type. The value should always be syslogng.
SecurityMonitoringRuleCaseAction
object
Action to perform when a signal is triggered. Only available for Application Security rule type.
2 properties
ObservabilityPipelineGenerateMetricsProcessorType
string
The processor type. Always generatedatadogmetrics.
ScheduleMemberType
string
Schedule Members resource type.
GCPSTSServiceAccount
object
Info on your service account.
4 properties
ObservabilityPipelineParseGrokProcessorRuleSupportRule
object
The Grok helper rule referenced in the parsing rules.
2 properties 2 required
MetricTagConfigurationUpdateAttributes
object
Object containing the definition of a metric tag configuration to be updated.
4 properties
SecurityMonitoringRuleCase
object
Case when signal is generated.
5 properties
IncidentAttachmentPostmortemAttachmentType
string
The type of postmortem attachment attributes.
EntityV3QueueKind
string
The definition of Entity V3 Queue Kind object.
ObservabilityPipelineSplunkTcpSourceType
string
The source type. Always splunktcp.
EscalationPolicyDataRelationshipsStepsDataItems
object
Defines a relationship to a single step within an escalation policy. Contains the step's id and type.
2 properties 2 required
HTTPTokenUpdate
object
The definition of HTTPTokenUpdate object.
4 properties 3 required
LogsArchiveEncryptionS3Type
string
Type of S3 encryption for a destination.
CaseUpdatePriorityRequest
object
Case update priority request
1 property 1 required
SpansMetricType
string
The type of resource. The value should always be spansmetrics.
RolesType
string
Roles type.
MetricCustomTimeAggregation
string
A time aggregation for use in query.
ObservabilityPipelineKafkaSourceType
string
The source type. The value should always be kafka.
CustomDestinationForwardDestinationElasticsearch
object
The Elasticsearch destination.
5 properties 4 required
ObservabilityPipelineConfig
object
Specifies the pipeline's configuration, including its sources, processors, and destinations.
3 properties 2 required
UserTeamUpdate
object
A user's relationship with a team
2 properties 1 required
UsersType
string
Users resource type.
ServiceDefinitionV1Org
object
Org related information about the service.
2 properties
WorkflowDataUpdate
object
Data related to the workflow being updated.
4 properties 2 required
StartStepNames
array
A list of steps that run first after a trigger fires.
EntityToRawSchema
object
Entity to raw schema relationship.
1 property
CustomDestinationElasticsearchDestinationAuth
object
Basic access authentication.
2 properties 2 required
ApplicationSecurityWafCustomRuleUpdateAttributes
object
Update a WAF custom rule.
8 properties 5 required
ResourceFilterAttributes
object
Attributes of a resource filter.
2 properties 1 required
CloudWorkloadSecurityAgentRuleUpdateData
object
Object for a single Agent rule
3 properties 2 required
SpansMetricResponseAttributes
object
The object describing a Datadog span-based metric.
3 properties
RumRetentionFilterAttributes
object
The object describing attributes of a RUM retention filter.
5 properties
RestrictionPolicyResponse
object
Response containing information about a single restriction policy.
1 property 1 required
IncidentIntegrationMetadataResponseIncludedItem
An object related to an incident integration metadata that is included in the response.
GithubWebhookTriggerWrapper
object
Schema for a GitHub webhook-based trigger.
2 properties 1 required
MetricTagConfigurationMetricTypes
string
The metric's type.
UpdateWorkflowResponse
object
The response object after updating a workflow.
1 property
TeamLinkResponse
object
Team link response
1 property
IncidentServiceUpdateRequest
object
Update request with an incident service payload.
1 property 1 required
CustomDestinationHttpDestinationAuthCustomHeaderType
string
Type of the custom header access authentication.
EntityV3API
object
Schema for API entities.
7 properties 3 required
TimeRestriction
object
Defines a single time restriction rule with start and end times and the applicable weekdays.
4 properties
DashboardListItemRequest
object
A dashboard within a list.
2 properties 2 required
ApplicationSecurityWafCustomRuleActionAction
string
Override the default action to take when the WAF custom rule would block.
EntityV3SystemSpec
object
The definition of Entity V3 System Spec object.
3 properties
ScheduleDataIncludedItem
Any additional resources related to this schedule, such as teams and layers.
ObservabilityPipelineGoogleCloudStorageDestinationAcl
string
Access control list setting for objects written to the bucket.
LogsArchiveAttributes
object
The attributes associated with the archive.
7 properties 3 required
ObservabilityPipelineGoogleChronicleDestinationType
string
The destination type. The value should always be googlechronicle.
RoleUpdateResponseData
object
Role object returned by the API.
4 properties 1 required
ObservabilityPipelineAmazonS3DestinationType
string
The destination type. Always amazons3.
ObservabilityPipelineGoogleChronicleDestinationEncoding
string
The encoding format for the logs sent to Chronicle.
SensitiveDataScannerRuleUpdateResponse
object
Update rule response.
1 property
RelationshipToIncidentUserDefinedFieldData
object
Relationship to impact object.
2 properties 2 required
ObservabilityPipelineFilterProcessorType
string
The processor type. The value should always be filter.
MicrosoftTeamsTenantBasedHandleAttributes
object
Tenant-based handle attributes.
4 properties
ApplicationSecurityWafExclusionFilterRulesTargetTags
object
Target multiple WAF rules based on their tags.
2 properties
ObservabilityPipelineParseGrokProcessorRule
object
A Grok parsing rule used in the parsegrok processor. Each rule defines how to extract structured fields from a specific log field using Grok patterns.
3 properties 3 required
CustomDestinationResponse
object
The custom destination.
1 property
SensitiveDataScannerFilter
object
Filter for the Scanning Group.
1 property
ServiceNowTicketResult
object
ServiceNow ticket information
1 property
MonitorNotificationRuleName
string
The name of the monitor notification rule.
ObservabilityPipelineNewRelicDestinationRegion
string
The New Relic region.
SpansMetricUpdateData
object
The new span-based metric properties.
2 properties 2 required
SpansMetricUpdateAttributes
object
The span-based metric properties that will be updated.
3 properties
DowntimeResponseData
object
Downtime data.
4 properties
GCPServiceAccountType
string
The type of account.
LogsMetricUpdateRequest
object
The new log-based metric body.
1 property 1 required
IncidentIntegrationMetadataMetadata
Incident integration metadata's metadata attribute.
ScheduleTargetType
string
Indicates that the resource is of type schedules.
ActionQuerySpecObject
object
The action query spec object.
4 properties 1 required
GCPServiceAccountMeta
object
Additional information related to your service account.
1 property
ServiceDefinitionV2Dot2OpsgenieRegion
string
Opsgenie instance region.
UpsertCatalogEntityResponseIncluded
array
Upsert entity response included.
HTTPTokenAuth
object
The definition of HTTPTokenAuth object.
5 properties 1 required
CustomFrameworkDataHandleAndVersion
object
Framework Handle and Version.
2 properties
CustomDestinationHttpDestinationAuthBasicType
string
Type of the basic access authentication.
ServiceDefinitionV2Slack
object
Service owner's Slack channel.
3 properties 2 required
ApplicationSecurityWafExclusionFilterAttributes
object
Attributes describing a WAF exclusion filter.
11 properties
RumMetricUniquenessWhen
string
When to count updatable events. match when the event is first seen, or end when the event is complete.
LogsMetricResponseCompute
object
The compute rule to compute the log-based metric.
3 properties
InputSchemaParametersType
string
The definition of InputSchemaParametersType object.
MicrosoftTeamsUpdateTenantBasedHandleRequest
object
Update tenant-based handle request.
1 property 1 required
ApplicationSecurityWafExclusionFilterMetadata
object
Extra information about the exclusion filter.
6 properties
ScheduleData
object
Represents the primary data object for a schedule, linking attributes and relationships.
4 properties 1 required
Organization
object
Organization object.
3 properties 1 required
RumMetricResponseData
object
The rum-based metric properties.
3 properties
IncidentAttachmentUpdateResponse
object
The response object containing the created or updated incident attachments.
2 properties 1 required
ObservabilityPipelineHttpServerSourceType
string
The source type. The value should always be httpserver.
CaseUpdatePriority
object
Case priority status
2 properties 2 required
CloudWorkloadSecurityAgentRuleAttributes
object
A Cloud Workload Security Agent rule returned by the API
21 properties
RestrictionQueryWithoutRelationshipsResponse
object
Response containing information about a single restriction query.
1 property
NullableRelationshipToUserData
object
Relationship to user object.
2 properties 2 required
ObservabilityPipelineSensitiveDataScannerProcessorLibraryPatternOptions
object
Options for selecting a predefined library pattern and enabling keyword support.
2 properties 1 required
ObservabilityPipelineAmazonS3DestinationStorageClass
string
S3 storage class.
ObservabilityPipelineDecoding
string
The decoding format used to interpret incoming logs.
EntityV3DatadogCodeLocations
array
Schema for mapping source code locations to an entity.
ServiceDefinitionV1Contact
object
Contact information about the service.
2 properties
CloudWorkloadSecurityAgentPolicyType
string
The type of the resource, must always be policy
ServiceDefinitionV2Dot1Link
object
Service's external links.
4 properties 3 required
RumMetricFilter
object
The rum-based metric filter. Events matching this filter will be aggregated in this metric.
1 property 1 required
MicrosoftTeamsWorkflowsWebhookResponseAttributes
object
Workflows Webhook handle attributes.
1 property
ObservabilityPipeline
object
Top-level schema representing a pipeline.
1 property 1 required
EscalationPolicyUpdateRequestDataAttributesStepsItems
object
Defines a single escalation step within an escalation policy update request. Contains assignment strategy, escalation timeout, an optional step ID, and a list…
4 properties 1 required
IncidentIntegrationMetadataAttributes
object
Incident integration metadata's attributes for a create request.
6 properties 2 required
ObservabilityPipelineConfigDestinationItem
A destination for the pipeline.
SensitiveDataScannerGroup
object
A scanning group.
2 properties
HTTPIntegrationUpdate
object
The definition of HTTPIntegrationUpdate object.
3 properties 1 required
SecurityMonitoringSuppressionUpdateRequest
object
Request object containing the fields to update on the suppression rule.
1 property 1 required
RestrictionPolicyType
string
Restriction policy type.
EntityV3DatastoreSpec
object
The definition of Entity V3 Datastore Spec object.
4 properties
ObservabilityPipelineConfigSourceItem
A data source for the pipeline.
IncidentTeamType
string
Incident Team resource type.
ObservabilityPipelineSensitiveDataScannerProcessorAction
Defines what action to take when sensitive data is matched.
SoftwareCatalogTriggerWrapper
object
Schema for a Software Catalog-based trigger.
2 properties 1 required
UpdateRuleRequestData
object
Data for the request to update a scorecard rule.
2 properties
ObservabilityPipelineNewRelicDestination
object
The newrelic destination sends logs to the New Relic platform.
4 properties 4 required
ApplicationSecurityWafCustomRuleAction
object
The definition of ApplicationSecurityWafCustomRuleAction object.
2 properties
DowntimeScheduleCurrentDowntimeResponse
object
The most recent actual start and end dates for a recurring downtime. For a canceled downtime, this is the previously occurring downtime. For active downtimes,…
2 properties
ApplicationSecurityWafCustomRuleResponse
object
Response object that includes a single WAF custom rule.
1 property
ScheduleMemberRelationshipsUserData
object
Points to the user data associated with this schedule member, including an ID and type.
2 properties 2 required
EntityV3DatadogLogItem
object
Log association item.
2 properties
DowntimeScheduleRecurrenceCreateUpdateRequest
object
An object defining the recurrence of the downtime.
3 properties 2 required
SecurityMonitoringRuleQueryAggregation
string
The aggregation type.
UserUpdateRequest
object
Update a user.
1 property 1 required
AzureStorageDestination
object
The azurestorage destination forwards logs to an Azure Blob Storage container.
5 properties 4 required
MonitorNotificationRuleResponseAttributes
object
Attributes of the monitor notification rule.
5 properties
HTTPBody
object
The definition of HTTPBody object.
2 properties
ObservabilityPipelineHttpServerSource
object
The httpserver source collects logs over HTTP POST from external services.
5 properties 4 required
RumMetricUpdateData
object
The new rum-based metric properties.
3 properties 2 required
OktaAccountType
string
Account type for an Okta account.
EscalationPolicyStep
object
Represents a single step in an escalation policy, including its attributes, relationships, and resource type.
4 properties 1 required
ServiceDefinitionData
object
Service definition data.
3 properties
ObservabilityPipelineSensitiveDataScannerProcessorType
string
The processor type. The value should always be sensitivedatascanner.
IncidentFieldAttributesValueType
string
Type of the multiple value field definitions.
IncidentServiceRelationships
object
The incident service's relationships.
2 properties
RelationshipToIncidentIntegrationMetadatas
object
A relationship reference for multiple integration metadata objects.
1 property 1 required
SecurityMonitoringRuleHardcodedEvaluatorType
string
Hardcoded evaluator type.
ObservabilityPipelineGooglePubSubSourceType
string
The source type. The value should always be googlepubsub.
GCPMetricNamespaceConfig
object
Configuration for a GCP metric namespace.
2 properties
TeamTargetType
string
Indicates that the resource is of type teams.
TeamPermissionSettingValues
array
Possible values for action
CloudWorkloadSecurityAgentRuleActions
array
The array of actions the rule can perform if triggered
ObservabilityPipelineSensitiveDataScannerProcessorActionPartialRedact
object
Configuration for partially redacting matched sensitive data.
2 properties 2 required
ObservabilityPipelineMetricValue
Specifies how the value of the generated metric is computed.
ScheduleUser
object
Represents a user object in the context of a schedule, including their id, type, and basic attributes.
3 properties 1 required
AWSAccountUpdateRequestData
object
AWS Account Update Request data.
3 properties 2 required
SecurityFilterID
string
The ID of the security filter.
IncidentTrigger
object
Trigger a workflow from an Incident. For automatic triggering a handle must be configured and the workflow must be published.
1 property
LogsArchive
object
The logs archive.
1 property
UpdateResourceEvaluationFiltersRequest
object
Request object to update a resource filter.
1 property 1 required
RumMetricID
string
The name of the rum-based metric.
SelfServiceTriggerWrapper
object
Schema for a Self Service-based trigger.
2 properties 1 required
RestrictionQueryUpdateData
object
Data related to the update of a restriction query.
2 properties
MonitorTrigger
object
Trigger a workflow from a Monitor. For automatic triggering a handle must be configured and the workflow must be published.
1 property
OpsgenieServiceUpdateAttributes
object
The Opsgenie service attributes for an update request.
4 properties
AWSNamespaceFiltersIncludeOnly
object
Include only these namespaces.
1 property 1 required
EntityV3DatadogLogs
array
Logs association.
SecurityMonitoringSuppression
object
The suppression rule's properties.
3 properties
ServiceDefinitionV2Dot1
object
Service definition v2.1 for providing service metadata and integrations.
12 properties 2 required
RelationshipToIncidentResponders
object
Relationship to incident responders.
1 property 1 required
RetentionFilterAllType
string
The type of retention filter.
CloudflareAccountResponseAttributes
object
Attributes object of a Cloudflare account.
4 properties 1 required
ObservabilityPipelineEnrichmentTableFile
object
Defines a static enrichment table loaded from a CSV file.
4 properties 4 required
CloudWorkloadSecurityAgentRuleActionMetadata
object
The metadata action applied on the scope matching the rule
3 properties
Layer
object
Encapsulates a layer resource, holding attributes like rotation details, plus relationships to the members covering that layer.
4 properties 1 required
RumRetentionFilterEventType
string
The type of RUM events to filter on.
ApplicationSecurityWafCustomRuleTags
object
Tags associated with the WAF Custom Rule. The concatenation of category and type will form the security activity field associated with the traces.
2 properties 2 required
IPAllowlistEntryData
object
Data of the IP allowlist entry object.
3 properties 1 required
HTTPHeader
object
The definition of HTTPHeader object.
2 properties 2 required
OktaAccountUpdateRequestData
object
Data object for updating an Okta account.
2 properties
OutputSchema
object
A list of output parameters for the workflow.
1 property
LogsArchiveDefinition
object
The definition of an archive.
3 properties 1 required
AWSAssumeRole
object
The definition of AWSAssumeRole object.
5 properties 3 required
IncidentServiceResponseAttributes
object
The incident service's attributes from a response.
3 properties
ServiceDefinitionV2Dot1Slack
object
Service owner's Slack channel.
3 properties 2 required
RelationshipToIncidentImpactData
object
Relationship to impact object.
2 properties 2 required
FastlyAccountResponseData
object
Data object of a Fastly account.
3 properties 3 required
CustomDestinationResponseForwardDestinationElasticsearch
object
The Elasticsearch destination.
5 properties 4 required
CustomDestinationResponseForwardDestinationElasticsearchType
string
Type of the Elasticsearch destination.
RelationshipToUserTeamUser
object
Relationship between team membership and user
1 property 1 required
ObservabilityPipelineSensitiveDataScannerProcessorActionRedactAction
string
Action type that completely replaces the matched sensitive data with a fixed replacement string to remove all visibility.
AWSAccountType
string
AWS Account resource type.
LayerRelationshipsMembersDataItems
object
Represents a single member object in a layer's members array, referencing a unique Datadog user ID.
2 properties 2 required
SecurityMonitoringSuppressionUpdateAttributes
object
The suppression rule properties to be updated.
9 properties
ObservabilityPipelineReduceProcessorMergeStrategyStrategy
string
The merge strategy to apply.
EscalationPolicyUpdateRequestDataType
string
Indicates that the resource is of type policies.
MonitorNotificationRuleUpdateRequest
object
Request for updating a monitor notification rule.
1 property 1 required
SensitiveDataScannerStandardPatternType
string
Sensitive Data Scanner standard pattern type.
SecurityMonitoringThirdPartyRootQuery
object
A query to be combined with the third party case query.
2 properties
RumMetricUpdateAttributes
object
The rum-based metric properties that will be updated.
3 properties
CustomDestinationResponseForwardDestinationHttp
object
The HTTP destination.
3 properties 3 required
SecurityMonitoringRuleUpdatePayload
object
Update an existing rule.
14 properties
FastlyServiceRequest
object
Payload schema for Fastly service requests.
1 property 1 required
AWSAccountUpdateRequestAttributes
object
The AWS Account Integration Config to be updated.
9 properties 1 required
EscalationPolicyUpdateRequestDataAttributes
object
Defines the attributes that can be updated for an escalation policy, such as description, name, resolution behavior, retries, and steps.
4 properties 2 required
IncidentSeverity
string
The incident severity.
EscalationPolicyStepAttributes
object
Defines attributes for an escalation policy step, such as assignment strategy and escalation timeout.
2 properties
UpdateAppResponseDataAttributes
object
The updated app definition attributes, such as name, description, and components.
7 properties
ApplicationSecurityWafExclusionFilterID
string
The identifier of the WAF exclusion filter.
ObservabilityPipelineOpenSearchDestination
object
The opensearch destination writes logs to an OpenSearch cluster.
4 properties 3 required
DowntimeResponseIncludedItem
An object related to a downtime.
AWSAuthConfig
AWS Authentication config.
SecurityFilterAttributes
object
The object describing a security filter.
7 properties
SpansMetricComputeAggregationType
string
The type of aggregation to use.
TeamReferenceType
string
Teams resource type.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

datadog-update-api-openapi.yml Raw ↑

Other APIs Datadog publishes across the network.

Datadog Dashboards API
Datadog Synthetics API
Datadog Service Level Objectives API
Datadog Security Monitoring API
Datadog Service Definition API
Datadog Software Catalog API
Datadog Users API
Datadog Roles API
Datadog Key Management API
Datadog Organizations API
Datadog Downtimes API
Datadog RUM API
Where this information came from

This is an independent, third-party profile of Datadog Update API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.