Skip to main content

Overview

Datadog is a robust and comprehensive monitoring service for cloud-scale applications, providing full visibility into IT infrastructure. The service combines metrics and events from servers, databases, applications, tools, and services to present a unified view of an entire stack. Datadog is capable of ingesting, analyzing, and visualizing logs from a variety of sources, including servers. This feature is a part of Datadog’s Log Management solution, which provides essential capabilities such as real-time log tailing and filtering, log analytics, and detailed visualizations. It can handle a wide range of log formats, including but not limited to, JSON, syslog, and common application logs. Datadog offers capabilities for log retention and archiving, enabling compliance with various regulatory standards. It also supports role-based access controls to secure your logs and control who can access what information. Follow the steps below to configure log shipping to Datadog.

Step 1 - Credential Procurement

An API key is required to ship logs to Datadog. Follow these steps to obtain the API key, store it as an Opaque Secret, and configure external logging.
  1. From the Datadog dashboard, hover over your username at the bottom of the left menu and click Organization Settings.
  2. In the middle menu, click API Keys.
  3. Click the New Key button in the upper right corner, enter a key name, and click Create Key.
  4. Click the Copy Key button. This will copy the key to your clipboard. Click the X to close the modal.
  5. From the Control Plane Console UI, click Secrets from the left menu.
  6. Click the New button.
  7. Enter a Name for the secret, and select Opaque from the Secret Type list.
  8. Paste the string from step #4 into the content text box and click Create.
  9. This secret will be used when configuring logging using the UI Console or CLI.

Step 2 - Configure External Logging

External logging can be configured by using either the UI Console or CLI.

Enable Logging using the UI Console

  1. From the Control Plane Console UI, click on Org in the left menu.
  2. Click External Logs in the middle context menu.
  3. Select Datadog and fill out the required fields.
  4. Select the Opaque secret created to authenticate to Datadog. Refer to the credential procurement section to obtain and configure the necessary credentials.
  5. Click Save.
  6. After the configuration is complete, log entries will be available at Datadog within a few minutes.
The hostname will be similar to the domain name that resolves when using the Datadog dashboard. (i.e., The host http-intake.logs.us3.datadoghq.com maps to the dashboard domain us3.datadoghq.com)

Enable Logging using the CLI

The external logging configuration can be created / updated using the CLI’s cpln org patch ORG_NAME -f FILE.yaml command. Below is an example of an Org manifest (in YAML). Edit and save the YAML as a file and use it as an input to the CLI’s cpln org patch ORG_NAME -f FILE.yaml command. Refer to the credential procurement section to obtain and configure the necessary credentials.
  • Substitute: ORG_NAME, OPAQUE_SECRET, and possibly the host.
Use the host URL that matches your Datadog account. The host will be a similar domain name that resolves when using the Datadog dashboard.
YAML

Metrics and Traces

Control Plane ships logs to Datadog natively. Metrics and traces take a different route: you run an OpenTelemetry Collector workload that holds your Datadog API key and forwards both signals.
  • Metrics — the collector scrapes your org’s Prometheus-compatible federation endpoint at metrics.cpln.io.
  • Traces — the GVC’s OpenTelemetry tracing provider sends spans to the collector over cpln.local.
spec.tracing.provider.otel accepts an endpoint only. It carries no headers or credentials, so traces cannot be sent directly to a Datadog intake, which requires an API key. The collector holds the key and adds it when forwarding.

Create the Secrets

  1. Store your Datadog API key as an Opaque Secret, as described in Credential Procurement. The examples below call it datadog-api-key.
  2. Follow the Export Metrics to Prometheus guide to create a service account, generate a key, and grant the service account readMetrics with a policy.
  3. Store that service account key as a second Opaque Secret. The examples below call it cpln-metrics-token.

Deploy the Collector

The manifest below creates the collector configuration (as an Opaque Secret), an identity and policy that let the workload reveal its secrets, and the collector workload.
  • Substitute: ORG_NAME, GVC_NAME, and the Datadog site for your account (datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, or datadoghq.eu).
  • If your account is on datadoghq.eu, replace *.datadoghq.com with *.datadoghq.eu in the firewall.
  • Adjust the match[] selector to the series you need.
YAML
Save the manifest as a file and apply it with cpln apply --file FILE.yaml --org ORG_NAME. See cpln apply.
Every replica scrapes the federation endpoint. If the GVC has more than one location, each location runs a replica and metrics are sent to Datadog once per location. To avoid duplicates, run the prometheus receiver in a separate collector in a single-location GVC, and keep only the otlp receiver in the collector that receives traces.
Egress charges apply to metrics scraped from Control Plane, and Datadog bills each federated series as a custom metric. Narrow the match[] selector to the series you need.

Point Tracing at the Collector

Set the GVC’s tracing provider to OpenTelemetry with the collector’s internal address, as described in the OpenTelemetry tracing provider reference. Apply it with cpln gvc patch GVC_NAME -f FILE.yaml. Changing the tracing configuration restarts all workloads in the GVC.
YAML
sampling is the percentage of requests that are traced. Metrics appear in Datadog’s Metrics Explorer and traces in APM within a few minutes. If nothing arrives, check the collector workload’s logs for exporter or scrape errors.
The OTel Collector template also deploys a collector you can point tracing at. Its advanced mode accepts a full collector configuration, including the datadog exporter, but it does not inject environment variables, so the API key would have to be written into the configuration itself.