esc
↑↓ move↵ openesc close
Connectors · Errors & on-call

Connect Datadog

Know when a Datadog monitor fires without living in the dashboard.

You need
API key and application key Organization Settings › API Keys, Personal Settings › Application Keys
The form asks
  • Connector name
  • Site
  • API key
  • Application key
You can watch
  • Monitors alerting
  • Incidents
  • Metric threshold
Access
GET requests only; it never mutes, resolves or edits
On this page

To connect Datadog to CoIsland you need two keys: an API key, which says which organization, and an application key, which says which user and carries that user’s permissions. CoIsland calls Datadog’s API straight from your Mac, with no CoIsland server in between, keeps both keys in your login Keychain, and only ever reads. This page covers the keys, the connector form, the three Datadog monitor kinds with queries you can paste, and the errors you may meet.

Get an API key and create an application key

Datadog runs several independent sites. Your site is in your browser’s address when you use Datadog: app.datadoghq.com is US1, us3.datadoghq.com US3, us5.datadoghq.com US5, app.datadoghq.eu EU, ap1.datadoghq.com AP1, ap2.datadoghq.com AP2 and app.ddog-gov.com US1-FED. Keys made on one site do not work on another.

API key. Open Organization Settings › API Keys. With the Standard role you can open an existing key and copy it; only an admin (the api_keys_write permission) can create a new one, so ask an admin if there is none you may use.

Application key. Open Personal Settings › Application Keys (or Organization Settings › Application Keys), select New Key, name it CoIsland, and copy it. The Standard role may create its own (the user_app_keys permission). The key acts as you, with your permissions. To narrow it, give it scopes: CoIsland needs monitors_read, incident_read and timeseries_query. On some sites Datadog shows an application key only once: copy it before you close the dialog.

An admin can remove user_app_keys from your role; Datadog then answers 403 Forbidden when you try to create a key, and you need an admin to create one for you.

Connect Datadog in CoIsland

Open Settings › Connectors, click +, and choose Datadog.

Field What to enter
Connector name What monitors call it: datadog. Letters, digits, _ and -.
Site Your Datadog site. Leave it on US1 if you sign in at app.datadoghq.com.
API key The API key you copied.
Application key The application key you created.

Test connector saves nothing. It checks the API key alone (GET /api/v1/validate), so a wrong site or API key says so, then both keys together (GET /api/v2/current_user), and reads Connected with your name, email and site. Add Connector writes the site to ~/Library/Application Support/CoIsland/connectors.json and both keys, as one Keychain item, to your login Keychain. They are only ever sent to your site’s API host, in the DD-API-KEY and DD-APPLICATION-KEY headers. Editing the connector with both key fields blank keeps both keys.

Choose what to watch: the three Datadog monitor kinds

Open Monitors, add a monitor and choose Datadog. A new-items monitor’s first check records what is already there and raises nothing.

Monitors alerting

A Datadog monitor alerts when it enters a state you pick: Alert and Warn unless you choose, or No data. A monitor going from Warn to Alert alerts again; one that recovers and fires again alerts again. Tags narrow it. Checks every minute by default.

state:alert,warn tag:env:prod

Incidents

An incident alerts when it is declared, and again when it is raised to a higher severity. Pick severities (sev-1 to sev-5, or unknown) and states (active and stable unless you choose, or resolved).

severity:sev-1,sev-2 state:active,stable

Metric threshold

Written the way a Datadog metric monitor’s query is: an aggregation over a window, a metric query, a comparison and a number. Each series over the threshold is a row, so with by {host} each host alerts on its own, and again after it recovers and crosses again. Checks every 5 minutes by default.

avg(last_5m):avg:system.cpu.user{env:prod} by {host} > 80

The aggregation is avg, min, max, sum or last, the window from last_1m to last_1d.

What a Datadog alert shows

The notch lists a monitor as Query alert · Alert · env:prod, an incident as SEV-2 #42 · Active · Ana Silva, a series as system.cpu.user · Over > 80 · host:web-1. Clicking one opens the alert in CoIsland: a monitor fills in with the groups alerting now, its priority and its message; an incident with its commander and customer impact; a series with its value now and whether it is still over. Open in Datadog goes to the monitor or the incident.

What a Datadog monitor’s watch file looks like

-- name: Production alerts
-- kind: datadog.monitors
-- connector: datadog
-- every: 1m
-- alert: new-rows

state:alert tag:env:prod

The kinds are datadog.monitors, datadog.incidents and datadog.metric. Watch files lists every header key.

Rate limits

Datadog does not publish fixed limits for these endpoints: each answer says what is left. A monitors check is one request per state and per 100 monitors, an incidents check one per 100 incidents, a metric check one request. When Datadog answers 429, CoIsland backs off until the time Datadog gives.

Troubleshooting Datadog connector errors

  • Datadog (US1) refused the API key. The API key was mistyped or revoked, or it belongs to another site: pick the site you sign in to.
  • Datadog (US1) refused the keys. The application key was mistyped or revoked, or the two keys come from different sites.
  • Not allowed: the application key needs the monitors_read permission. A scoped application key lacks that scope, or your role lacks the permission. The same message names incident_read or timeseries_query for the other kinds.
  • Datadog refused the query: then Datadog’s reasons, for a metric query it cannot read.
  • Rate limited; retry after 12s. The next check tries again.

Stuck? Open an issue on GitHub, or write to hello@coisland.app.

Docs