dd-logs
datadog-labs/agent-skills
Search, process, and archive logs in Datadog with cost-aware filtering and metrics.
What is dd-logs?
Manage logs in Datadog using the pup CLI tool. Search logs with flexible query syntax, configure pipelines and processors, set up exclusion filters to control costs, archive logs for compliance, and create log-based metrics. Use this when you need to find, filter, or optimize log storage and analysis.
- Search logs with boolean queries, tag filters, attribute ranges, and wildcards
- Configure log pipelines with grok parsers, status remappers, and attribute remappers
- Set exclusion filters to drop low-value logs and reduce indexing costs
- List and manage log archives for long-term compliance storage
- Create and list log-based metrics from log data
- Hash or redact sensitive data like emails, credit cards, and SSNs
How to install dd-logs
npx skills add https://github.com/datadog-labs/agent-skills --skill dd-logs- Datadog Pup CLI installed and configured
- Datadog account with log management access
- Authentication via `pup auth login`
How to use dd-logs
- 1.Run `pup auth login` to authenticate with Datadog
- 2.Use `pup logs search --query="your-filter" --from="1h"` to find logs
- 3.List existing archives with `pup logs archives list` or metrics with `pup logs metrics list`
- 4.Define exclusion filters in JSON to drop unwanted logs and control costs
- 5.Add processors (grok, status-remapper, attribute-remapper) to parse and enrich logs
- 6.Configure archive destinations (S3, GCS) for long-term compliance storage
Use cases
- Find error logs across services in the last hour to diagnose production issues
- Exclude health-check and debug logs to reduce monthly log indexing costs
- Archive all logs to S3 for compliance while keeping recent logs indexed
- Parse nginx logs with grok patterns to extract client IP, method, and status code
- Create a metric counting API errors per service without indexing every error log
- DevOps engineers managing log infrastructure and costs
- SREs investigating production incidents and performance
- Platform teams setting up log pipelines and data governance
- Security teams implementing log retention and sensitive data redaction
dd-logs FAQ
Use `pup logs search --query="service:api status:error" --from="1h"` to find error logs from the api service in the last hour.
Add exclusion filters for high-volume, low-value logs like health checks (`@http.url:"/health"`), debug logs (`status:debug`), and static assets (`@http.url:*.css`).
The pup CLI does not have a rehydrate command in version 0.42.0; use the Datadog UI or API for rehydration workflows.
Use a grok-parser processor with a match rule like `%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}` to extract fields.
Use hash-remapper processors for emails and implement application-level sanitization for credit cards, SSNs, and other PII before logs reach Datadog.
Full instructions (SKILL.md)
Source of truth, from datadog-labs/agent-skills.
name: dd-logs description: Log management - search, archives, metrics, and cost control. metadata: version: "1.0.1" author: datadog-labs repository: https://github.com/datadog-labs/agent-skills tags: datadog,logs,logging,search,dd-logs globs: "/datadog*.yaml,/log" alwaysApply: "false"
Datadog Logs
Search, process, and archive logs with cost awareness.
Prerequisites
Datadog Pup should already be installed. See Setup Pup if not.
Command Execution Order (Token-Efficient)
For scoped commands, use this order:
- Check context first (prior outputs, conversation, saved values).
- If a required value is missing, run a discovery command first.
- If still ambiguous, ask the user to confirm.
- Then run the target command.
- Avoid speculative commands likely to fail.
Quick Start
pup auth login
Search Logs
# Basic search
pup logs search --query="status:error" --from="1h"
# With filters
pup logs search --query="service:api status:error" --from="1h" --limit 100
# JSON output
pup logs search --query="@http.status_code:>=500" --from="1h"
Search Syntax
| Query | Meaning |
|---|---|
error | Full-text search |
status:error | Tag equals |
@http.status_code:500 | Attribute equals |
@http.status_code:>=400 | Numeric range |
service:api AND env:prod | Boolean |
@message:*timeout* | Wildcard |
Configuration APIs
Available log configuration commands in pup 0.42.0:
# List log archives
pup logs archives list
# List log restriction queries
pup logs restriction-queries list
# List custom log destinations
pup logs custom-destinations list
Common Processors
{
"name": "API Logs",
"filter": {"query": "service:api"},
"processors": [
{
"type": "grok-parser",
"name": "Parse nginx",
"source": "message",
"grok": {"match_rules": "%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}"}
},
{
"type": "status-remapper",
"name": "Set severity",
"sources": ["level", "severity"]
},
{
"type": "attribute-remapper",
"name": "Remap user_id",
"sources": ["user_id"],
"target": "usr.id"
}
]
}
Exclusion Filters (Cost Control)
Index only what matters:
{
"name": "Drop debug logs",
"filter": {"query": "status:debug"},
"is_enabled": true
}
High-Volume Exclusions
# Find noisiest log sources
pup logs search --query="*" --from="1h" | jq 'group_by(.service) | map({service: .[0].service, count: length}) | sort_by(-.count)[:10]'
| Exclude | Query |
|---|---|
| Health checks | @http.url:"/health" OR @http.url:"/ready" |
| Debug logs | status:debug |
| Static assets | @http.url:*.css OR @http.url:*.js |
| Heartbeats | @message:*heartbeat* |
Archives
Store logs cheaply for compliance:
# List archives
pup logs archives list
# Archive config (S3 example)
{
"name": "compliance-archive",
"query": "*",
"destination": {
"type": "s3",
"bucket": "my-logs-archive",
"path": "/datadog"
},
"rehydration_tags": ["team:platform"]
}
Rehydrate (Restore)
# No `pup logs rehydrate` command in pup 0.42.0.
# Use Datadog UI/API for rehydration workflows.
Log-Based Metrics
Create metrics from logs (cheaper than indexing):
# List log-based metrics
pup logs metrics list
# Get one metric by ID
pup logs metrics get api.errors.count
Cardinality warning: Group by bounded values only.
Sensitive Data
Scrubbing Rules
{
"type": "hash-remapper",
"name": "Hash emails",
"sources": ["email", "@user.email"]
}
Never Log
# In your app - sanitize before sending
import re
def sanitize_log(message: str) -> str:
# Remove credit cards
message = re.sub(r'\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b', '[REDACTED]', message)
# Remove SSNs
message = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED]', message)
return message
Troubleshooting
| Problem | Fix |
|---|---|
| Logs not appearing | Check agent, pipeline filters |
| High costs | Add exclusion filters |
| Search slow | Narrow time range, use indexes |
| Missing attributes | Check grok parser |
References/Documentation
Related skills
More from datadog-labs/agent-skills and the wider catalog.

dd-monitors
Create and manage Datadog monitors with alerting best practices and file-based workflows.

dd-pup
Datadog CLI with OAuth2 auth for logs, monitors, metrics, traces, incidents, dashboards, and more.

agent-skills
Datadog monitoring, logging, tracing, and observability skills for AI agents.

agent-install
Install Datadog Agent on Linux with Single Step Instrumentation (SSI) for automatic APM without code changes.

warranty-tracker
Track and manage construction warranties. Monitor expiration dates, claims, and manufacturer documentation.

reflection
MUST use this skill when user provides feedback / ask to do things in certain way, or when a tool call fails - for self-improvement - to learn user preferences and store them in AGENT.md / CLAUDE.md, and to propose improvements to skills.