Capabilities
Query Tools
| Tool | What It Does |
|---|---|
| Query logs | Search logs by username, IP address, hostname, or custom query |
| Correlate activity | Cross-reference Datadog logs with other integrations |
What You Can Search
Hiro can query Datadog logs with flexible filtering:- Usernames — Filter by
@usr.namefield - IP addresses — Filter by
@network.client.ipfield - Hostnames — Filter by
hostfield - Custom queries — Full Datadog query syntax support
Action Tools
The Datadog integration is read-only. Hiro can query and analyze logs but cannot modify Datadog configuration, create monitors, or trigger alerts.Remediation actions based on Datadog findings are executed through other integrations (Okta, AWS, CrowdStrike, etc.).
Setup
Prerequisites
- Datadog account with log retention enabled
- Ability to create API and Application keys
Connection Steps
Create an API key
In Datadog:
- Go to Organization Settings > API Keys
- Click New Key
- Name it (e.g., “Hiro Security”)
- Copy the API key
Create an Application key
- Go to Organization Settings > Application Keys
- Click New Key
- Name it (e.g., “Hiro Security”)
- Copy the Application key
Connect in Hiro
In Hiro, go to Settings > Integrations:
- Click Connect next to Datadog
- Enter your API Key
- Enter your Application Key
- Select your Datadog site (e.g.,
datadoghq.comfor US1) - Click Connect
Datadog Sites
Select the site that matches your Datadog account:| Site | URL |
|---|---|
| US1 (default) | datadoghq.com |
| US3 | us3.datadoghq.com |
| US5 | us5.datadoghq.com |
| EU | datadoghq.eu |
| AP1 | ap1.datadoghq.com |
| US1-FED | ddog-gov.com |
Investigation Examples
Search for errors
Investigate a user
Search by IP
Correlate across systems
Troubleshooting
”Authentication failed”
- Verify both the API Key and Application Key are correct
- Check that the keys haven’t been revoked in Datadog
- Ensure you selected the correct Datadog site
”No logs found”
- Verify log retention is enabled in your Datadog plan
- Check that relevant log sources are configured and indexed
- Try expanding the time range
Rate limiting
Datadog has API rate limits. If you’re hitting limits, try narrowing your search queries or reducing the time range.Next Steps
Okta
Connect identity management.
AWS
Connect cloud infrastructure.