Official agent skill

Dd Logs

by DataDog in DataDog/pup

Log management - search, pipelines, archives, and cost control.

OfficialApache-2.0Auto-check passedBusiness, Finance & HR

Install Dd Logs

skills CLI
$ npx skills add DataDog/pup --skill dd-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DataDog/pup dd-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DataDog/pup.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dd-logs .claude/skills/dd-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dd-logs
GitHub stars
1k
Token cost
~1.3k tokens
SKILL.md length
313 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Log management - search, pipelines, archives, and cost control.

  • Tasks that involve Budgeting and forecasting
  • SKILL.md covers Prerequisites, Quick Start, Search Logs and Pipelines, plus 6 more sections
  • Calls cargo and jq

What it does

Dd Logs is an agent skill from DataDog/pup, published by the product's own GitHub organization. Log management - search, pipelines, archives, and cost control.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Budgeting and forecasting. It works with Datadog. The repository describes itself as: Give your AI agent a Pup — a CLI companion with 200+ commands across 33+ Datadog products. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Budgeting and forecasting

Example prompts

  • “/dd-logs”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 6a3c662. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.datadoghq.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dd Logs loads about 1.3k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 313 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~18
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DataDog/pup at commit 6a3c662, republished under its Apache-2.0 licence (© DataDog). 313 words, ~1,299 tokens.

Download SKILL.mdSave it as .claude/skills/dd-logs/SKILL.md (or your agent's skills folder).
name
dd-logs
description
Log management - search, pipelines, archives, and cost control.
metadata.version
1.0.0
metadata.author
datadog-labs
metadata.repository
https://github.com/datadog-labs/agent-skills
metadata.tags
datadog,logs,logging,search,dd-logs
metadata.globs
**/datadog*.yaml,**/*log*
metadata.alwaysApply
false

Datadog Logs

Search, process, and archive logs with cost awareness.

Prerequisites

Datadog Pup (dd-pup/pup) should already be installed:

bash
cargo install --git https://github.com/DataDog/pup

Quick Start

bash
pup auth login

Search Logs

bash
# Basic search
pup logs search --query="status:error" --from="1h"

# With filters
pup logs search --query="service:api status:error" --from="1h" --limit 100

# JSON output is the default
pup logs search --query="@http.status_code:>=500" --from="1h"
Search Syntax
QueryMeaning
errorFull-text search
status:errorTag equals
@http.status_code:500Attribute equals
@http.status_code:>=400Numeric range
service:api AND env:prodBoolean
@message:*timeout*Wildcard
Trace IDs in Log Results

Logs that show a linked trace in the Datadog UI may not include dd.trace_id / dd.span_id in API results. When a trace ID attribute is remapped for trace correlation (via JSON preprocessing or a Trace Remapper processor), the source attribute is removed and the value is stored as an internal attribute that the Logs Search API does not return. The UI's "trace" link reads that internal attribute, so UI and API results differ.

This is expected Datadog Log Management behavior, not a pup bug or an instrumentation problem. Do not retry queries or change instrumentation to "fix" it. Datadog is tracking making these values queryable (support reference FRLOGSS-4306).

Workarounds until then:

  • Emit the trace ID under a separate attribute that is not remapped (e.g. @custom.trace_id) and query that.
  • Pivot the other way: search spans by the log's service/time window via pup traces search, or use the trace link in the Datadog UI.

Pipelines

Process logs before indexing:

bash
# List pipelines
pup obs-pipelines list

# Create pipeline (JSON)
pup obs-pipelines create --file pipeline.json
Common Processors
json
{
  "name": "API Logs",
  "filter": {"query": "service:api"},
  "processors": [
    {
      "type": "grok-parser",
      "name": "Parse nginx",
      "source": "message",
      "grok": {"match_rules": "%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}"}
    },
    {
      "type": "status-remapper",
      "name": "Set severity",
      "sources": ["level", "severity"]
    },
    {
      "type": "attribute-remapper",
      "name": "Remap user_id",
      "sources": ["user_id"],
      "target": "usr.id"
    }
  ]
}

⚠️ Exclusion Filters (Cost Control)

Index only what matters:

json
{
  "name": "Drop debug logs",
  "filter": {"query": "status:debug"},
  "is_enabled": true
}
High-Volume Exclusions
bash
# Find noisiest log sources
pup logs search --query="*" --from="1h" | jq 'group_by(.service) | map({service: .[0].service, count: length}) | sort_by(-.count)[:10]'
ExcludeQuery
Health checks@http.url:"/health" OR @http.url:"/ready"
Debug logsstatus:debug
Static assets@http.url:*.css OR @http.url:*.js
Heartbeats@message:*heartbeat*

Archives

Store logs cheaply for compliance:

bash
# List archives
pup logs archives list

# Archive config (S3 example)
{
  "name": "compliance-archive",
  "query": "*",
  "destination": {
    "type": "s3",
    "bucket": "my-logs-archive",
    "path": "/datadog"
  },
  "rehydration_tags": ["team:platform"]
}

Log-Based Metrics

Inspect log-based metrics:

bash
# List existing log-based metrics
pup logs metrics list

⚠️ Cardinality warning: Group by bounded values only.

Sensitive Data

Scrubbing Rules
json
{
  "type": "hash-remapper",
  "name": "Hash emails",
  "sources": ["email", "@user.email"]
}
Never Log
python
# In your app - sanitize before sending
import re

def sanitize_log(message: str) -> str:
    # Remove credit cards
    message = re.sub(r'\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b', '[REDACTED]', message)
    # Remove SSNs
    message = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED]', message)
    return message

Troubleshooting

ProblemFix
Logs not appearingCheck agent, pipeline filters
High costsAdd exclusion filters
Search slowNarrow time range, use indexes
Missing attributesCheck grok parser
dd.trace_id missing but UI shows a traceExpected: remapped trace IDs become internal attributes (see Trace IDs in Log Results)

References/Documentation

© DataDog, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dd-logs of DataDog/pup.

Open the folder on GitHubat commit 6a3c662

Compare with similar skills

Dd Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dd Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dd Logs this skillDataDog/pup1k—~1.3kAutomated safety check: PassApache-2.0
Longbridge Researchhelsome/folio2693 repos~2.1kAutomated safety check: PassMIT
Bet SizingJoelLewis/finance_skills205—~2.5kAutomated safety check: PassMIT
Cash Flow ForecastWellApp-ai/Well345—~567Automated safety check: PassMIT
Cash Flow Snapshotsandbaseai/sandbase-skills201—~1.9kAutomated safety check: PassApache-2.0
Cre Asset Managementahacker-1/cre-agent-skills112—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Longbridge Research

    helsome/folio

    Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…

    269 GitHub starsUsed in 3 repos~2.1k tokens
    Business, Finance & HRAuto-check passed
  • Bet Sizing

    JoelLewis/finance_skills

    Determine how much capital to allocate to individual positions within a portfolio.

    205 GitHub stars~2.5k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Cash Flow Forecast

    WellApp-ai/Well

    Forecast cash flow and runway for a Well workspace from booked invoices and collected bank transactions.

    345 GitHub stars~567 tokensUpdated 7 days ago
    Business, Finance & HRAuto-check passed
  • Cash Flow Snapshot

    sandbaseai/sandbase-skills

    Create a 30/60/90-day cash-flow forecast from AR, AP, opening cash, payment timing, and fixed-cost data.

    201 GitHub stars~1.9k tokensUpdated 11 days ago
    Business, Finance & HRAuto-check passed
  • Cre Asset Management

    ahacker-1/cre-agent-skills

    CRE Asset Management analysis suite — 9 specialist skills for post-acquisition multifamily operations including annual budgeting, monthly variance analysis, rent collection, renewal decisions…

    112 GitHub stars~1.8k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Budget Cash Flow

    sickn33/agentic-awesome-skills

    Budget against actual by department, category and period, with budget and actual amounts, variance, percentage used and linked expenses.

    47k GitHub starsUsed in 1 repo~4.1k tokens
    Business, Finance & HRAuto-check passed

More from DataDog/pup

All 12 skills in this repo
  • Dd Idp

    DataDog/pup

    Official

    Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph.

    1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Dd Debugger

    DataDog/pup

    Official

    Live Debugger - inspect runtime argument/variable values in production by placing log probes on methods.

    1k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Dd Docs

    DataDog/pup

    Official

    Datadog docs lookup using docs.datadoghq.com/llms.txt and linked Markdown pages.

    1k GitHub starsUsed in 1 repo~558 tokens
    Auto-check passed
  • Pup

    DataDog/pup

    Official

    Datadog API CLI with 49 command groups, 300+ subcommands. An agent skill from DataDog/pup.

    1k GitHub stars~523 tokensUpdated today
    Auto-check passed
  • Official

    Load when investigating a specific flaky test. An agent skill from DataDog/pup.

    1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Dd Apm

    DataDog/pup

    Official

    APM - traces, services, dependencies, performance analysis. An agent skill from DataDog/pup.

    1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Dd Logs

What does Dd Logs do?

Log management - search, pipelines, archives, and cost control. Dd Logs is an agent skill from DataDog/pup, published by the product's own GitHub organization. Log management - search, pipelines, archives, and cost control.

When should I use Dd Logs?

Dd Logs fits situations like: tasks that involve Budgeting and forecasting.

How do I install Dd Logs in Claude Code?

Run `npx skills add DataDog/pup --skill dd-logs -a claude-code`. Or copy the skill folder (skills/dd-logs in DataDog/pup) into .claude/skills/dd-logs in your project. Claude Code loads it when a task matches its description.

How do I install Dd Logs in Codex?

Run `npx skills add DataDog/pup --skill dd-logs -a codex`. Or copy the skill folder (skills/dd-logs in DataDog/pup) into .agents/skills/dd-logs in your project. Codex loads it when a task matches its description.

Can I use Dd Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DataDog/pup --skill dd-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dd-logs, .gemini/skills/dd-logs, .github/skills/dd-logs and .opencode/skills/dd-logs in your project.

What does Dd Logs need to run?

Going by SKILL.md and its folder, Dd Logs needs the command-line tools its instructions call (cargo and jq). Our summary lists: Python 3.

Does Dd Logs access the network?

SKILL.md names 1 domain. As links in the text: docs.datadoghq.com. This is read from the text; nothing was executed.

Is Dd Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dd Logs use?

Dd Logs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dd Logs use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dd Logs?

Skills that share tags, products or a category with Dd Logs: Longbridge Research (helsome/folio, 269 stars), Bet Sizing (JoelLewis/finance_skills, 205 stars), Cash Flow Forecast (WellApp-ai/Well, 345 stars) and Cash Flow Snapshot (sandbaseai/sandbase-skills, 201 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dd Logs?

DataDog (a GitHub organization, an official publisher) maintains it in DataDog/pup, which has 1,026 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.

Source: DataDog/pup on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.