> ## Documentation Index
> Fetch the complete documentation index at: https://docs.summation.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Datadog

> Import filtered logs, metrics, monitors, and log aggregates as typed Summation tables.

The Datadog data connector creates read-only snapshots of selected Datadog queries as typed Summation tables. Use them in reports, dashboards, and joins with your other data. No raw JSON table or follow-up calculation table is required.

<Note>
  This connector is available to enabled workspaces during rollout. If Datadog
  is not listed under data sources, contact your Summation administrator.
</Note>

## What you'll need

* Your organization's Datadog site, such as `datadoghq.com`, `us3.datadoghq.com`, or `datadoghq.eu`.
* An API key and an application key for the same Datadog organization.
* Read permissions for each dataset you plan to import.

In Datadog, open **Organization Settings**, then **API Keys** and **Application Keys** to create or obtain the keys. Prefer a dedicated service account and scope its application key to the permissions below. The key owner must also have those permissions. See Datadog's [key management instructions](https://docs.datadoghq.com/account_management/api-app-keys/).

| Dataset        | Required application-key permission                                                                                 |
| -------------- | ------------------------------------------------------------------------------------------------------------------- |
| Logs           | [`logs_read_data`](https://docs.datadoghq.com/api/latest/logs/search-logs/)                                         |
| Log aggregates | [`logs_read_data`](https://docs.datadoghq.com/api/latest/logs/aggregate-events/)                                    |
| Metrics        | [`timeseries_query`](https://docs.datadoghq.com/api/latest/metrics/query-timeseries-data-across-multiple-products/) |
| Monitors       | [`monitors_read`](https://docs.datadoghq.com/api/latest/monitors/monitors-search/)                                  |

Summation stores both keys as connector secrets. Do not enter keys in dataset names or queries. This connector does not request write permissions or use an OAuth sign-in flow.

## Connect Datadog

1. Open **Connectors**, select **New connection**, and choose **Datadog**.
2. Enter a connection name and select the **Datadog site** that matches your organization.
3. Enter the **API key** and **Application key**.
4. Optionally enable **Scheduled snapshots** and choose a cadence.
5. Select **Test connection**, then **Continue**.
6. Select **Add Dataset**. Choose a dataset first; Summation fills in its default name. You can rename it before saving.
7. Set the query and, where available, time range. Add other datasets as needed, then select **Create connector**.

The initial import starts automatically. Tables become available when their first snapshots finish. A successful connection test validates the key pair, not access to every dataset; the first import also checks that dataset's permissions.

## Choose a dataset

| Dataset        | What each row represents                              | Main columns                                                                 |
| -------------- | ----------------------------------------------------- | ---------------------------------------------------------------------------- |
| Logs           | One matching log event                                | `id`, `timestamp`, `service`, `status`, `host`, `message`, `trace_id`, `env` |
| Metrics        | One timestamped point for a returned metric series    | `series_id`, `timestamp`, `value`, `query`, `scope`, `unit`                  |
| Monitors       | One matching monitor's current summary                | `id`, `name`, `type`, `status`                                               |
| Log aggregates | One computed value per time bucket and optional group | `timestamp`, `value`, `aggregation`, `measure`, `group_by`, `group_value`    |

### Logs

Enter a Datadog log search query, such as `env:production service:checkout status:error`. Choose a narrow time range to start. The table contains the listed common fields, not every custom log attribute.

### Metrics

Enter a metric query, for example `avg:system.cpu.user{env:production} by {host}`. The table contains the points returned by Datadog, with their series, scope, and unit. This is not a download of every metric in your organization.

### Monitors

Enter a monitor search query, such as `type:metric status:alert`, or leave it blank for accessible monitors. This dataset is current monitor inventory, not alert history, so it has no time-range control.

### Log aggregates

Enter a log search query and select **Count**, **Sum**, **Average**, **Minimum**, **Maximum**, or **95th percentile**. Other than Count, these aggregations require a numeric **Measure**, such as `@duration`, available in your logs. Optionally group by a facet such as `service`, and choose an hourly or daily bucket interval.

For example, count `env:production status:error` by `service` over the last 24 hours with hourly buckets to report error volume without importing individual events.

## Time ranges and refreshes

Logs, Metrics, and Log aggregates support **Last hour**, **Last 24 hours**, **Last 7 days**, **Last 30 days**, or a **Custom range**. Custom From and To values are in UTC and must define a positive range of at most 31 days.

* Relative ranges are evaluated when a refresh starts. Retries retain that refresh's time window.
* Custom ranges stay fixed until you edit them. Repeating a refresh does not advance the dates.
* Every successful refresh replaces the table's contents with the selected query result. Incremental append is not supported.
* If a refresh fails, the previously materialized table remains available. A successful query with no matches produces an empty table.
* Use the dataset's refresh control for a manual update, or enable **Scheduled snapshots** for recurring updates.

<Warning>
  A daily refresh of Last 24 hours maintains a rolling window, not a growing
  historical archive. Data outside that window is removed from the current table
  after a successful refresh. Availability also depends on Datadog retention and
  the connected account's access.
</Warning>

Start with a narrow query and a short window. Large exports or Datadog throttling can make refreshes take longer; avoid scheduling frequent full exports of high-volume logs. Prefer log aggregates when you only need counts or trends.

## Snapshots or MCP?

Use this data connector for repeatable reporting and cross-source analysis on a defined subset of telemetry. Use an [app or MCP connection](/features/connectors/apps) with appropriate live-query tools for occasional investigations where you only read a small fraction of the source data. You do not need to mirror all Datadog data into Summation.

Raw APM trace/span search and service dependency exploration are not datasets in this version of the data connector. They require a separate supported integration; the four datasets above are the current scope.

## Common problems

| Symptom                               | What to check                                                                                                                          |
| ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| Test connection rejects the keys      | Check the Datadog site, organization, and both keys. Newly created keys may need a few seconds to propagate.                           |
| Test passes but a dataset returns 403 | Check that the application key and its owner have the dataset permission listed above and access to the requested data.                |
| No rows match                         | Try the same query and time window in Datadog. Check filters, retention, and access restrictions.                                      |
| Refresh is delayed or rate-limited    | Use a narrower time window or fewer groups. Other tools may share your Datadog API quota.                                              |
| A large aggregate query fails         | Reduce the time range or grouping cardinality. Incomplete responses are rejected rather than replacing the table with partial results. |
| You need to change the Datadog site   | A site cannot change while datasets are attached. Create a separate connection for another site.                                       |
| Stored key fields look blank          | Saved secrets are not displayed. Leave them blank to keep existing values, or enter replacement keys in Edit.                          |
