Skip to content

Guides

Ledger records in Datadog

Every ledger record as an OCSF log at your Datadog site, with one API key checked live.

Datadog’s OAuth is open only to approved Datadog Technology Partners (Datadog), so this is one API key.

  1. In Datadog, Organization settings, API keys, make a key (an API key, not an application key).
  2. On the Datadog card, pick your site (US1, US3, US5, EU1, AP1, AP2, UK1, US1-FED, US2-FED) and paste the key. It is checked with GET https://api.<site>/api/v1/validate before it is kept.

Records go to https://http-intake.logs.<site>/api/v2/logs in batches of up to 100, as the same OCSF 1.3 events the SIEM export carries, with ddsource:immiscible and tags workspace:<id> and kind:<ledger kind>. You can limit the kinds sent with events (PATCH /api/w/:wid/alerting/datadog). Retries and the delivery log are as for PagerDuty.

Sources: send logs, validate API key, sites.