# Datadog

> Monitor conditions, service ownership and selected reliability objectives beside the component they explain.

Connect Datadog to the stratum for a component on your diagram. Use a host to explain telemetry reporting, a monitor to explain an evaluated condition, a catalog service to explain ownership and dependencies, or an SLO to show performance against an objective. Open the linked Datadog record for detailed investigation and operational changes.

## Connect

1. You need an Enterprise licence, edit access to the blueprint, and `continuum_integrations.manage` on the connection's organisation or team.
2. Create a dedicated Datadog service account with read permissions. Follow Datadog's [key setup](https://docs.datadoghq.com/account_management/api-app-keys/) or [Service Access Token guide](https://docs.datadoghq.com/account_management/service-access-tokens/).
3. In Blueprintr, open `Settings → Continuum` on the organisation or team, go to `Operational integrations`, choose `New integration`, select `Datadog` as the `Type`, enter a `Name`, and choose the `Datadog site`. If you use a custom Datadog domain, find the underlying site in `My Preferences`. See [Datadog sites](https://docs.datadoghq.com/getting_started/site/).
4. Under `Datadog credentials`, set `Credential type` to `API key and application key`, or to `Service Access Token` and fill that field. A Service Access Token pasted into the application-key box is rejected.
5. Review the information and audience settings, then choose `Connect & verify`. Blueprintr stores credentials encrypted and never displays them after saving.

Hosts and monitors require `hosts_read` and `monitors_read`. Enable optional capabilities only when needed:

| Capability | Additional permission | Information saved |
| --- | --- | --- |
| Service Definitions, schema v2.2 and earlier | `apm_service_catalog_read` | Service ownership and structured operating links |
| Software Catalog, schema v3 | `apm_service_catalog_read` | Supported catalog entities, owners and declared or discovered relationships |
| Reliability objectives | `slos_read` | Selected SLO target, performance, observation window and error budget |

Catalog versions use distinct APIs. Choose the one your account uses and verify availability on your site. Datadog sites are independent and product availability differs. The connection reads existing information; it does not create monitors, SLOs, public dashboards or new telemetry instrumentation. Your existing Datadog entitlements and API limits still apply.

## Choose the component's operational context

Save the blueprint, open its stratum, and choose `Continuum Link` from the `+ Add tab` menu. Search by host or monitor name, paste a Datadog monitor, SLO or infrastructure source link, or use one of these forms:

| Search | Use |
| --- | --- |
| `monitor:12345` | Select an exact monitor |
| `service:checkout env:production` | Find the catalog service for this deployment |
| `slo:0123456789abcdef0123456789abcdef` | Select an exact SLO |
| `slo-id:objective-id` | Explicitly select an SLO by its exact ID, including other supported ID formats |
| `slo:Checkout availability` | Find a named objective |

Review the connection, stable identity and source preview before linking. Catalog and SLO searches require the corresponding connection option.

Linking a Datadog `service` requires its exact `env` tag value, without spaces or wildcards. For other Catalog entity kinds the field reads `Environment (optional)` and may be left blank. The service identity and deployment environment serve different purposes; changing a deployment's `version` tag does not make it a new service. [Unified service tagging](https://docs.datadoghq.com/getting_started/tagging/unified_service_tagging/) explains Datadog's `service`, `env` and `version` relationships.

Add an explicitly selected SLO ID to a service and choose its window. Check that the objective describes this service and environment: a similar name is not proof of that relationship. Standalone SLO selection also lets you choose 7, 30 or 90 days, where supported by the objective.

For a multi-alert monitor, optionally copy the exact Datadog group string to show that group's state. Without a group, the panel describes the monitor's aggregate state. One monitor may cover many hosts or environments; its aggregate alert is not proof that every component is affected.

`Suggest integrations…` and `Scan for integrations` offer matches for review. Use manual search when you want to choose an environment, SLO or monitor group. Each connection has one managed tab per stratum; choosing a different object explicitly replaces its binding. Authored prose and diagram content stay intact.

## Read the saved information

Host reporting means whether Datadog received the expected metrics. Missing telemetry is not proof that a host is down. Hosts outside Datadog's available inventory window can become unavailable. Monitor panels retain distinct alert, warning, no-data and other provider states; these are evaluated conditions, not a general guarantee of system health.

Catalog v3 separates declared relationships from those Datadog discovers through APM or Universal Service Monitoring. If provenance cannot be established, it is labelled unknown. These relationships are catalog-wide; the selected monitor environment does not filter this topology. The earlier Service Definitions API supplies ownership and links, with no relationship retrieval. Catalog navigation opens your regional Software Catalog; use the displayed entity identity to locate the component. Structured operating links may include documentation, runbooks and dashboards recorded on the selected entity. Blueprintr does not discover every dashboard or publish dashboard contents.

SLO panels show the objective's target and calculated performance for the selected window. Error budgets retain their units and may be negative when the budget is exhausted. Blueprintr never substitutes 100% for an unavailable calculation. Datadog's own no-data rules still apply: monitor SLOs follow the underlying monitors' settings, and time-slice SLOs count no-data periods as uptime. The panel explains these limits. See Datadog's [SLO history](https://docs.datadoghq.com/api/latest/service-level-objectives/get-an-slos-history/) and [monitor details](https://docs.datadoghq.com/api/latest/monitors/get-a-monitors-details/).

Opening a tab displays its saved snapshot. Re-fetch with the circular-arrows icon on the linked row ("Re-fetch this integration's data"). Snapshots show their retrieval time and become due for refresh after five minutes; this is a freshness warning, not automatic polling. Incomplete retrieval is labelled partial. Counts from a partial list are lower bounds; an unavailable section does not mean zero. A failed refresh keeps the previous snapshot with a warning.

## Information and audience

New connections default to `Blueprint editors` and `Summary`. Summary retains the identity and operational measures while keeping monitor detail to a minimum. Detailed mode can include monitor names and approved tag values; new connections approve only `service`, `env` and `version` tag keys initially. Enter `none` to omit tags; clearing a configured list also omits tags on the next refresh. Monitor messages, notification recipients and raw telemetry are omitted.

Choose the reader-visible option, `All Blueprint readers`, whose full label adds "approved metadata", only after reviewing the information for that audience. A public blueprint can have anonymous readers who do not authenticate to Datadog. Host identities, service names, ownership, links and even selected tag values may be confidential.

> [!IMPORTANT]
> A connection created before these settings existed has no stored value for audience, saved detail or approved tag keys. Each absent value resolves to its legacy behaviour: blueprint readers, detailed, and every tag key up to 30, excluding keys whose name suggests a secret. Such a connection publishes monitor names and all tag values to everyone who can read the blueprint.
>
> Opening `Configure` and saving unchanged keeps that behaviour, because the form pre-selects the legacy values. Select `Blueprint editors` under `Datadog content audience`, choose `Summary` under `Saved detail`, set `Approved tag keys` or enter `none`, choose `Verify & save settings`, then refresh each linked tab.

Settings affect subsequent successful refreshes; they do not rewrite existing snapshots. Editor-only panels follow the shared reader, embed, viewer-export and search or AI audience controls. Editor exports and backups can retain the source data. Names in authored notes or link labels outside the managed panel need separate review.

Unlinking, reducing detail, revoking credentials or changing audience does not recall saved versions, templates, exports, AI answers or copies already shared.

## Recovery and disconnection

Verification checks the required reads and enabled optional capabilities. Host and monitor reads must pass. If an enabled Catalog or SLO check fails, the connection stays usable for hosts and monitors and the verification notice shows which optional access needs attention. After reloading settings, use `Verify` to recheck optional availability; the stored verified status alone does not establish it.

If access is denied, check the site's selection, credential expiry and exact read permissions. Scoped keys do not inherit extra permissions. Newly created keys can take a few seconds to propagate. For rate limits, wait for the stated retry interval before refreshing; see [Datadog's rate-limit guidance](https://docs.datadoghq.com/api/latest/rate-limits/).

Use `Rotate token`, then `Verify & replace`, for credentials. Replacing an application key while keeping the same API key preserves links. Changing the API key or Service Access Token requires reviewing and linking objects again, because Blueprintr cannot assume the new credential addresses the same account. Changing sites also requires relinking. Older bindings must be unlinked before these changes. A failed credential verification preserves the previous credential.

`Suspend` stops search and refresh while retaining snapshots, and `Resume` restarts it. The broken-link icon on the linked row removes the binding and its managed tab. Remove all bindings before deleting a connection. Remove its stored credential and revoke it in Datadog when access should end.

Before operational rollout, validate your site's permissions, known host and monitor groups, missing telemetry, large result sets, SLO calculations, optional Catalog availability and regional source links against your own account. Local fixtures do not establish live product availability or account entitlements.
