Datadog Integrations Core

repository·master·Indexed 22 days ago

https://github.com/datadog/integrations-core

Source code for official Datadog integrations used by the Datadog Agent to collect metrics and data from various services. Includes documentation and configuration guides for integrations such as Active Directory, ActiveMQ, ActiveMQ XML, Adyen, and Aerospike.

Tokens
694.4K
Snippets
1.3K
Records
2.6K
Agent score
78%

What's inside integrations-core

  1. Overview of the HAProxy Integration

    master

    The HAProxy integration allows you to capture HAProxy activity in Datadog. This enables you to:

    • Visualize HAProxy load-balancing performance.
    • Monitor server availability and detect when a server goes down.
    • Correlate HAProxy performance metrics with the rest of your application stack.

    Minimum Agent version required: 6.0.0

  2. Overview of Palo Alto Networks Cortex XSOAR integration

    master

    The Palo Alto Networks Cortex XSOAR integration parses and ingests logs and metrics to provide visibility into security orchestration and incident response activities.

    Logs Collected

    • Audit Logs: Administrative user activities within Cortex XSOAR.
    • Incidents: Incident details including severity, status, type, and ownership.

    Metrics Collected

    • Automation Insight Metrics: Playbook, task, and command execution activity (counts, failures, and duration).
    • API Execution Metrics: API activity (total calls and rate-limited requests).
    • SLA Metrics: Incident response timelines (mean time to detection, triage, containment, and resolution; counts of items within/outside SLA thresholds).

    Features

    • Dashboards: Out-of-the-box dashboards for visualizing logs and metrics.
    • Cloud SIEM: Includes detection rules to monitor and respond to security threats.
  3. Overview of data collected by the Have I Been Pwned integration

    master

    The Have I Been Pwned integration ingests and forwards data to Datadog for security analysis.

    Logs

    • Breach Logs: Refers to security incidents where data from a system has been exposed to unauthorized parties.

    These logs are parsed and enriched using Datadog's built-in pipeline, enabling searching and analysis. The integration includes Dashboards and Cloud SIEM detection rules to help monitor message logs and improve security posture.

    Metrics

    • This integration does not collect any metrics.

    Events

    • This integration does not collect any events.
  4. What is DynamicD

    master

    DynamicD is an AI-powered tool that generates realistic fake telemetry data for Datadog integrations. It uses Claude (Anthropic) to analyze an integration's metrics, service checks, and dashboards to produce a Python script that simulates scenario-aware data.

    Generated telemetry includes:

    • Metrics: Dashboard metrics with correlated values.
    • Logs: Scenario-appropriate messages (INFO/WARN/ERROR).
    • Service Checks: Health status matching the selected scenario.
    • Events: Significant state changes (e.g., incidents, recoveries).

    All generated telemetry is automatically tagged with env:dynamicd for easy filtering in Datadog.

  5. Overview of the MongoDB integration

    master

    The MongoDB integration allows you to connect MongoDB to Datadog to visualize key metrics and correlate MongoDB performance with your application stack.

    Key capabilities include:

    • Standard Metrics: Visualization of core MongoDB performance metrics.
    • Custom Metrics: Ability to create custom metrics using find, count, and aggregate queries.
    • Database Monitoring (DBM): For enhanced insights, you can enable Database Monitoring to access live and historical query snapshots, slow query metrics, database load, operation execution plans, and collection insights.

    Compatibility Requirements:

    • MongoDB Version: v3.0 or higher is required.
    • MongoDB Atlas: Requires M10+ clusters.
    • Supported Managed Services: Supports Alibaba ApsaraDB and Amazon DocumentDB Instance-Based clusters.
    • Unsupported: DocumentDB Elastic clusters are not supported (as they only expose cluster/mongos endpoints).
    • Datadog Agent: Minimum version 6.0.0 is required.
  6. Overview of Palo Alto Networks Firewall Log Integration

    master

    The Palo Alto Networks Firewall Log integration enables Datadog to ingest, parse, and analyze logs from Palo Alto Networks firewalls. This integration utilizes the HTTPS log templating and forwarding capabilities of PAN-OS (the Palo Alto operating system) to collect various log events.

    Supported Log Types

    • Threat logs: Context on detected threats, filterable by severity, type, origin IPs, and countries.
    • Traffic logs: Data on traffic and sessions passing through the firewall, useful for monitoring throughput and anomalous patterns.
    • Authentication logs: Details on user authentication events, useful for monitoring spikes in authentication traffic by protocol, user, or location.
  7. Overview of the SNMP Check

    master

    The SNMP (Simple Network Management Protocol) check is used to monitor network-connected devices such as routers, switches, servers, and firewalls. It collects metrics from these devices using OIDs (Object Identifiers) and sysObjectIDs (System Object Identifiers).

    Key concepts:

    • OIDs: Hierarchical identifiers for managed objects (e.g., 1.3.6.1.1 for MIB-II standard information like uptime and interfaces, or 1.3.6.1.4.1 for vendor-specific information).
    • MIB (Management Information Base): Acts as a translator between numeric OIDs and human-readable names.

    Minimum Agent version required: 6.0.0

  8. Overview of Trellix Endpoint Security Data Collection

    master

    The Trellix Endpoint Security integration ingests security logs to provide enrichment, visualization, and out-of-the-box detection rules.

    Logs

    The integration collects and forwards logs related to:

    • Threat Events: Details about threat prevention, web control, firewall, and adaptive threat protection.

    Metrics

    No metrics are collected by this integration.

    Events

    No events are collected by this integration.

  9. Overview of WMI Check Integration

    master

    The WMI Check allows you to map rows and columns from Windows Management Instrumentation (WMI) class datasets to Datadog metrics and tags. It supports joining two WMI class datasets to allow for correlations between datasets.

    Important Recommendations:

    • Use Windows Performance Counters instead: For collecting Windows Performance Counters, it is recommended to use the dedicated Windows Performance Counters integration as it is more efficient. Avoid using Win32_PerfFormattedData_XYZ WMI classes for this purpose.
    • Performance Caution: Certain WMI classes like Win32_Product or Win32_UserAccount can be slow or cause high CPU usage. Always test performance in a production environment before use.

    Minimum Agent version: 6.0.0

  10. Overview of data collected by Agent Metrics

    master

    The Agent Metrics integration provides visibility into the Datadog Agent's internal performance.

    • Metrics: Collects internal metrics as defined in the agent_stats.yaml.example configuration file. Note that the specific list of metrics may change between minor Agent versions.
    • Events: No events are collected by this integration.
    • Service Checks: No service checks are collected by this integration.
  11. Overview of ECS Fargate Integration

    master

    The ECS Fargate integration allows you to collect metrics from all containers running in your ECS Fargate tasks.

    Key capabilities include:

    • Monitoring CPU and Memory usage relative to limits.
    • Monitoring applications using Datadog integrations or custom metrics.

    Mechanism: The Datadog Agent retrieves metrics by querying the ECS task metadata endpoint from within the task. Because this endpoint is only accessible from within the task itself, the Datadog Agent must be deployed as a sidecar container within every task definition you wish to monitor.

  12. Overview of Versa SD-WAN monitoring capabilities

    master

    The Versa integration provides deep visibility into Versa SD-WAN environments by collecting metrics from controllers, appliances, tunnels, and links. It focuses on three main areas:

    • WAN edge and controller health: Monitors device availability, CPU, memory, disk usage, and uptime for branch and data center deployments.
    • Link, tunnel, and path SLA monitoring: Tracks latency, jitter, packet loss, utilization, and error rates to verify SLA compliance and troubleshoot connectivity.
    • Application, user, and QoS visibility: Identifies top applications and users by site, tracks Direct Internet Access (DIA) usage, and analyzes QoS metrics like traffic volume and drop rates to understand congestion and prioritization.