Datadog
Connect
Connect Datadog from the terminal. Pass --help for the flags Datadog accepts.
polylane integration connect --type datadogAPI key and application key for your Datadog site.
Connect Datadog so agents can query your logs, metrics, monitors, and dashboards during investigations.
Setup
- Select your Datadog site (US1, US3, US5, EU1, AP1, and so on). Check your Datadog URL:
app.datadoghq.comis US1,app.datadoghq.euis EU1. - Enter your API key from Organization Settings → API Keys.
- Enter your Application key from Organization Settings → Application Keys.
- Polylane validates both keys and connects.
An application key without scopes has the same access as your user and works as is. If you scope the key, include user_app_keys (required to connect) plus logs_read_data, timeseries_query, metrics_read, monitors_read, monitors_write, monitors_downtime, dashboards_read, slos_read, hosts_read, events_read, incident_read, apm_read, aws_configuration_read, and create_webhooks. Your keys are encrypted before they are stored, and the agent never sees them.
Connecting creates a webhook named polylane in Datadog and subscribes every monitor to it, so alerts land in Polylane and get triaged as they fire.
What agents can do
- Search and filter logs with Datadog query syntax
- Read metric values and trends over time
- Check which monitors are alerting and their status
- Reference dashboard data in investigations
Disconnecting
Disconnect Datadog in Polylane, then revoke the application and API keys in Datadog.
Register Datadog alerts to Polylane alongside your Terraform-managed resources.
Polylane subscribes a monitor by appending the @webhook-polylane mention to its message and adding the polylane:managed tag. A recurring sync applies both to every monitor, so a Terraform-managed monitor shows drift until its Terraform config carries them too. Add both to each monitor:
resource "datadog_monitor" "high_error_rate" {
name = "High error rate on checkout"
type = "metric alert"
query = "sum(last_5m):sum:trace.http.request.errors{service:checkout}.as_count() > 50"
message = <<-EOT
{{#is_alert}}Error rate on checkout is above threshold.{{/is_alert}}
@webhook-polylane
EOT
tags = concat(var.tags, ["polylane:managed"])
}
The simplest setup keeps the webhook itself managed by Polylane and puts only the mention and tag in Terraform. If you also manage webhooks in Terraform, import the existing one instead of creating it, since Datadog webhook names are unique. Add the resource block first, then import:
resource "datadog_webhook" "polylane" {
name = "polylane"
url = "https://sinks.polylane.com/v1/datadog"
encode_as = "json"
custom_headers = jsonencode({
"x-polylane-telemetry-token" = var.polylane_telemetry_token
})
payload = jsonencode({
alert_id = "$ALERT_ID"
alert_metric = "$ALERT_METRIC"
alert_query = "$ALERT_QUERY"
alert_scope = "$ALERT_SCOPE"
alert_status = "$ALERT_STATUS"
alert_title = "$ALERT_TITLE"
alert_transition = "$ALERT_TRANSITION"
alert_type = "$ALERT_TYPE"
date = "$DATE_POSIX"
event_msg = "$EVENT_MSG"
event_title = "$EVENT_TITLE"
event_type = "$EVENT_TYPE"
hostname = "$HOSTNAME"
id = "$ID"
link = "$LINK"
logs_sample = "$LOGS_SAMPLE"
org_id = "$ORG_ID"
org_name = "$ORG_NAME"
priority = "$PRIORITY"
snapshot = "$SNAPSHOT"
tags = "$TAGS"
user = "$USER"
username = "$USERNAME"
})
}
terraform import datadog_webhook.polylane polylane
The telemetry token authenticates alert deliveries to your workspace. Find it in Polylane under Settings → Telemetry tokens (the token named datadog-integration), or create a new token on the same page. Reconnecting the integration recreates the webhook with a fresh token, so an imported webhook needs its token variable updated afterwards.
Disconnect
Disconnecting stops every sync and check and deletes the credentials Polylane held. Polylane removes what Datadog's API lets it remove. The following stays until you remove it yourself:
- @webhook-polylane appended to every monitor message
- polylane:managed tag on every monitor
polylane integration disconnect <id>Tools
12Operations agents can perform in threads.