Datadog
The Datadog integration connects your Datadog organization to Oneleet. Oneleet reads your Datadog users for access reviews, checks that they use multi-factor authentication (MFA), and checks that your Datadog monitors alert someone when your infrastructure has a problem.
Connect Datadog
Section titled “Connect Datadog”You’ll need your Datadog site, an API key and an application key.
- In Oneleet, go to Integrations > Add integration > Datadog.
- Enter your Site. It’s the domain in the URL you use to sign in to Datadog, such as
datadoghq.com,us5.datadoghq.comordatadoghq.eu. - In Datadog, go to Organization Settings > API Keys, then create or copy an API key.
- Go to Organization Settings > Application Keys and create an application key with the scopes below.
- Enter both keys in Oneleet and submit.
Application key scopes
Section titled “Application key scopes”| Scope | Required | What it’s for |
|---|---|---|
user_access_read |
Yes | Reads your Datadog users for access reviews and the MFA check |
monitors_read |
Yes | Checks that your monitors alert someone |
org_management |
No | Reads your SAML settings, so users who sign in through SAML strict mode pass the MFA check |
The user who owns the application key also needs these permissions in their Datadog role, because a key can’t use a permission its owner doesn’t have. If monitors_read is missing, the alerting check fails and tells you which scope to add.
Oneleet reads only the Datadog organization the application key belongs to, even if the key’s owner belongs to other organizations.
What Oneleet checks
Section titled “What Oneleet checks”- Multi-factor authentication: each active Datadog user has MFA turned on. Datadog doesn’t report MFA for users who sign in only through SAML. If your organization uses SAML strict mode, those users pass, because your identity provider enforces MFA.
- Alerting: your Datadog monitors alert someone when your infrastructure has a problem. A monitor alerts someone when its message has an
@handle, such as@[email protected]or@slack-alerts, or when a notification rule whose filter matches the monitor’s tags adds recipients. A handle that’s only inside a{{#is_recovery}}block doesn’t count, because it only hears about the alert once it resolves. Draft monitors and monitors muted with no end date don’t count, and neither do monitors that don’t watch infrastructure, such as log or RUM monitors. - Monitors as evidence: each infrastructure monitor shows up in Datadog monitors have notifications configured. A monitor fails if it has no notifications configured, or if it has been muted with no end date for 60 days or more, the threshold Datadog’s Monitor Quality page uses. Drafts and monitors muted for less than 60 days are marked not applicable, with the reason.
Both checks count toward the Infrastructure performance monitored control.
Use Datadog in place of CloudWatch alarms
Section titled “Use Datadog in place of CloudWatch alarms”The Infrastructure performance monitored control also includes AWS checks that look for CloudWatch alarms. If you alert from Datadog instead, turn off the AWS checks you don’t use, with a reason such as “We monitor infrastructure with Datadog.” A turned-off check doesn’t fail the control.