Agent skill

Dt Obs Azure

by Dynatrace in Dynatrace/dynatrace-for-ai

Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault.

Apache-2.0Auto-check passedDevOps & Cloud

Install Dt Obs Azure

skills CLI
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-obs-azure .claude/skills/dt-obs-azure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dt-obs-azure
GitHub stars
163
Token cost
~6.3k tokens
SKILL.md length
1,730 words
Files
15 (incl. references)
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault.

  • Works in 4 steps: Filter early by subscription, resource… → Use specific entity types (avoid… → Limit results with | limit N for… → …
  • Tasks that involve Cloud networking
  • SKILL.md covers When to Use This Skill, Core Concepts, Query Patterns and Reference Guide, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dt Obs Azure is an agent skill from Dynatrace/dynatrace-for-ai. Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault. Monitor Azure infrastructure, analyze resource usage, audit security posture, and manage organizational hierarchy across subscriptions and resource groups.

Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `references/README.md`, `references/capacity-planning.md` and `references/cost-optimization.md`).

It sits in DevOps & Cloud, covering Cloud networking and Secrets management. It works with Microsoft Azure, Azure Event Hubs and SQL. The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking
  • Tasks that involve Secrets management

Example prompts

  • “/dt-obs-azure”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Filter early by subscription, resource group, and region
  2. Use specific entity types (avoid "AZURE_*" wildcards when possible)
  3. Limit results with | limit N for exploration
  4. Use isNotNull() checks before accessing nested fields

What it can do on your machine

Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are dql-template, dql-snippet, dql and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dt Obs Azure loads about 6.3k tokens when it runs, and up to ~45k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,730 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~6.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~45k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 1,730 words, ~6,295 tokens.

Download SKILL.mdSave it as .claude/skills/dt-obs-azure/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
dt-obs-azure
description
Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault. Monitor Azure infrastructure, analyze resource usage, audit security posture, and manage organizational hierarchy across subscriptions and resource groups.
license
Apache-2.0

Azure Cloud Infrastructure

Monitor and analyze Azure resources using Dynatrace Smartscape and DQL. Query Azure services, audit security, manage organizational hierarchy, and plan capacity across your Azure infrastructure.

When to Use This Skill

Use this skill when the user needs to work with Azure resources in Dynatrace. Load the reference file for the task type:

TaskFile to load
Inventory and topology queries(no additional file — use core patterns below)
Query Azure metric timeseries (CPU, latency, throughput)Load references/metrics-performance.md
VNet topology, subnets, NSGs, public IPs, VPN, peeringLoad references/vnet-networking-security.md
Azure SQL, Cosmos DB, PostgreSQL, Redis investigationLoad references/database-monitoring.md
Functions, App Service, AKS infrastructure, Container AppsLoad references/serverless-containers.md
Azure LB, Application Gateway, Front Door, API ManagementLoad references/load-balancing-api.md
WAF rule analysis, false-positive investigationLoad references/load-balancing-api.md
Event Hubs, Service Bus, Event GridLoad references/messaging-integration.md
Storage Accounts, Blob, File, Queue, TableLoad references/storage-monitoring.md
Unattached resources, tag compliance, lifecycleLoad references/resource-management.md
Cost savings, unused resources, SKU analysisLoad references/cost-optimization.md
Capacity headroom, VMSS scaling, quotasLoad references/capacity-planning.md
Security audit, encryption, public access, Key VaultLoad references/security-compliance.md
NSG rule analysis (0.0.0.0/0, open ports)Load references/security-compliance.md
Storage account encryption/public access auditLoad references/security-compliance.md
Cost allocation, chargeback, ownershipLoad references/resource-ownership.md
Determine orchestration context (AKS, VMSS, standalone)Load references/workload-detection.md

Core Concepts

Entity Types

Azure resources use the AZURE_* prefix and can be queried using the smartscapeNodes function. All Azure entities are automatically discovered and modeled in Dynatrace Smartscape. Entity type names are derived from the ARM resource provider path: /Microsoft.Compute/virtualMachines becomes AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES. Sub-resources append with underscores: /Microsoft.Sql/servers/databases becomes AZURE_MICROSOFT_SQL_SERVERS_DATABASES.

Compute: AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES, AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS, AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS_VIRTUALMACHINES, AZURE_MICROSOFT_COMPUTE_DISKS, AZURE_MICROSOFT_COMPUTE_SSHPUBLICKEYS, AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES_EXTENSIONS Networking: AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS, AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS_SUBNETS, AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS, AZURE_MICROSOFT_NETWORK_PUBLICIPADDRESSES, AZURE_MICROSOFT_NETWORK_NETWORKINTERFACES, AZURE_MICROSOFT_NETWORK_LOADBALANCERS, AZURE_MICROSOFT_NETWORK_APPLICATIONGATEWAYS, AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKGATEWAYS, AZURE_MICROSOFT_NETWORK_CONNECTIONS, AZURE_MICROSOFT_NETWORK_EXPRESSROUTECIRCUITS Database: AZURE_MICROSOFT_SQL_SERVERS, AZURE_MICROSOFT_SQL_SERVERS_DATABASES, AZURE_MICROSOFT_CACHE_REDIS, AZURE_MICROSOFT_CACHE_REDISENTERPRISE, AZURE_MICROSOFT_DOCUMENTDB_DATABASEACCOUNTS Storage: AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_BLOBSERVICES_CONTAINERS, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_FILESERVICES_SHARES, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_QUEUESERVICES_QUEUES, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_TABLESERVICES_TABLES Kubernetes/Containers: AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS, AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS_AGENTPOOLS, AZURE_MICROSOFT_CONTAINERREGISTRY_REGISTRIES, AZURE_MICROSOFT_APP_CONTAINERAPPS, AZURE_MICROSOFT_APP_MANAGEDENVIRONMENTS, AZURE_MICROSOFT_APP_JOBS App Service: AZURE_MICROSOFT_WEB_SITES, AZURE_MICROSOFT_WEB_SERVERFARMS, AZURE_MICROSOFT_WEB_SITES_FUNCTIONS Messaging: AZURE_MICROSOFT_EVENTHUB_NAMESPACES, AZURE_MICROSOFT_EVENTHUB_NAMESPACES_EVENTHUBS, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_QUEUES, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS_SUBSCRIPTIONS Security/Identity: AZURE_MICROSOFT_KEYVAULT_VAULTS, AZURE_MICROSOFT_MANAGEDIDENTITY_USERASSIGNEDIDENTITIES Monitoring: AZURE_MICROSOFT_OPERATIONALINSIGHTS_WORKSPACES, AZURE_MICROSOFT_INSIGHTS_COMPONENTS API Management: AZURE_MICROSOFT_APIMANAGEMENT_SERVICE

Azure Organizational Hierarchy

Azure organizes resources in a three-level hierarchy: Tenant > Subscription > Resource Group. Every resource belongs to exactly one resource group within one subscription. Use these fields to scope queries:

dql-snippet
filter azure.subscription == "08b9810e-..."
dql-snippet
filter azure.resource.group == "my-rg"
dql-snippet
filter azure.location == "eastus"

Combine these filters for precise scoping:

dql-template
smartscapeNodes "AZURE_*"
| filter azure.subscription == "<SUBSCRIPTION_ID>"
    and azure.resource.group == "<RESOURCE_GROUP>"
    and azure.location == "<REGION>"
| summarize count = count(), by: {type}
| sort count desc

To see the organizational breakdown across your environment:

dql
smartscapeNodes "AZURE_*"
| summarize resource_count = count(), by: {azure.subscription, azure.resource.group}
| sort resource_count desc
Common Azure Fields

All Azure entities include:

  • azure.subscription — Azure subscription GUID
  • azure.resource.group — Resource group name
  • azure.location — Azure region (e.g., eastus, polandcentral)
  • azure.resourceType — ARM resource type (e.g., microsoft.compute/virtualmachines)
  • azure.provisioning_state — Provisioning state (e.g., Succeeded)
  • azure.object — Full ARM resource JSON (see Configuration Parsing)
  • cloud.provider — Always azure
  • tags — Resource tags (use tags[`key`])

Some entity types also have:

  • azure.resourceId — Full ARM resource ID (VMs and some others)
  • azure.resourceName — Resource name (VMs and some others)
  • azure.availabilityZones — Availability zone list (VMs)
Relationship Types

Azure entity relationships can be traversed using traverse. The dt.traverse.relationship field is not populated for Azure entities, so you must use "*" as the relationship name in all traversal commands.

Key traversal pairs:

  • VM → Disks: traverse "*", "AZURE_MICROSOFT_COMPUTE_DISKS"
  • VM → NICs: traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKINTERFACES"
  • VM → VMSS: traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS"
  • VM → Availability Zones: traverse "*", "AZURE_MICROSOFT_RESOURCES_LOCATIONS_AVAILABILITYZONES"
  • VM ← Extensions: traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES_EXTENSIONS", direction:backward
  • VMSS → AKS Clusters: traverse "*", "AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS"
  • VMSS → Subnets: traverse "*", "AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS_SUBNETS"
  • VMSS → NSGs: traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS"
  • VMSS → LB Backend Pools: traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_BACKENDADDRESSPOOLS"
  • Subnet → VNet: traverse "*", "AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS"
  • Subnet → NSG: traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS"
  • Subnet ← VMSS: traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS", direction:backward
  • NSG ← NICs: traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKINTERFACES", direction:backward
  • NSG ← Subnets: traverse "*", "AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS_SUBNETS", direction:backward
  • LB → Backend Pools: traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_BACKENDADDRESSPOOLS"
  • LB → Frontend IPs: traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_FRONTENDIPCONFIGURATIONS"
  • LB → LB Rules: traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_LOADBALANCINGRULES"
  • SQL Server ← SQL Databases: traverse "*", "AZURE_MICROSOFT_SQL_SERVERS_DATABASES", direction:backward
  • Storage Account ← Blob Containers: traverse "*", "AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_BLOBSERVICES_CONTAINERS", direction:backward
  • Storage Account ← File Shares: traverse "*", "AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_FILESERVICES_SHARES", direction:backward
  • AKS ← VMSS: traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS", direction:backward
  • AKS ← Agent Pools: traverse "*", "AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS_AGENTPOOLS", direction:backward
  • AKS ← NSGs: traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS", direction:backward
  • AKS ← Public IPs: traverse "*", "AZURE_MICROSOFT_NETWORK_PUBLICIPADDRESSES", direction:backward
  • AKS → Public IPs: traverse "*", "AZURE_MICROSOFT_NETWORK_PUBLICIPADDRESSES"
  • Web Site → App Service Plan: traverse "*", "AZURE_MICROSOFT_WEB_SERVERFARMS"
  • Web Site ← Functions: traverse "*", "AZURE_MICROSOFT_WEB_SITES_FUNCTIONS", direction:backward
  • Container App → Managed Environment: traverse "*", "AZURE_MICROSOFT_APP_MANAGEDENVIRONMENTS"
  • EventHub Namespace ← Event Hubs: traverse "*", "AZURE_MICROSOFT_EVENTHUB_NAMESPACES_EVENTHUBS", direction:backward
  • ServiceBus Namespace ← Queues: traverse "*", "AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_QUEUES", direction:backward
  • ServiceBus Namespace ← Topics: traverse "*", "AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS", direction:backward
  • ServiceBus Topic ← Subscriptions: traverse "*", "AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS_SUBSCRIPTIONS", direction:backward
  • Use fieldsKeep:{field1, field2} to carry fields through multi-hop traversals
  • After a single-hop traverse, use dt.traverse.history[0][id] to get the source entity ID, then lookup to resolve the source entity name:
    dql-snippet
    | fieldsAdd sourceId = dt.traverse.history[0][id]
    | lookup [smartscapeNodes "SOURCE_TYPE" | fields name, id], sourceField: sourceId, lookupField: id, prefix: "src."
  • After multi-hop traversals, dt.traverse.history[-N] works for fields carried via fieldsKeep
Azure Metric Naming Convention

Dynatrace ingests Azure Monitor metrics and exposes them using this naming pattern:

cloud.azure.<provider_namespace>.<resource_type>.<MetricName>

The <provider_namespace> uses underscores within the namespace (e.g., microsoft_compute) and <resource_type> is lowercase (e.g., virtualmachines). Hierarchy levels are dot-separated: microsoft_sql.servers.databases. <MetricName> is the Azure Monitor metric name.

Examples:

Azure Monitor metricDynatrace metric key
VM Percentage CPUcloud.azure.microsoft_compute.virtualmachines.PercentageCPU
SQL DB cpu_percentcloud.azure.microsoft_sql.servers.databases.cpu_percent
Storage Ingresscloud.azure.microsoft_storage.storageaccounts.Ingress
Event Hub IncomingMessagescloud.azure.microsoft_eventhub.namespaces.IncomingMessages
Service Bus IncomingMessagescloud.azure.microsoft_servicebus.namespaces.IncomingMessages
App Service HttpResponseTimecloud.azure.microsoft_web.sites.HttpResponseTime
Load Balancer ByteCountcloud.azure.microsoft_network.loadbalancers.ByteCount
AKS node_cpu_usage_percentagecloud.azure.microsoft_containerservice.managedclusters.node_cpu_usage_percentage
Cosmos DB TotalRequestUnitscloud.azure.microsoft_documentdb.databaseaccounts.TotalRequestUnits
Redis serverLoadcloud.azure.microsoft_cache.redis.serverLoad
App Gateway TotalRequestscloud.azure.microsoft_network.applicationgateways.TotalRequests

To query a metric:

dql-template
timeseries cpu = avg(cloud.azure.microsoft_compute.virtualmachines.PercentageCPU),
           by: {dt.smartscape_source.id},
  from: now()-1h
| limit 10

Important: Never refer to these as "Azure Monitor alerts" or "Azure Monitor metrics" in output. Dynatrace monitors Azure resources natively through its Azure integration — these are Dynatrace metrics ingested from Azure.

Configuration Parsing with azure.object

The azure.object field contains the full ARM resource JSON. Parse it with the azjson alias:

dql-snippet
parse azure.object, "JSON:azjson"

The JSON is wrapped in a configuration key:

json
{
  "configuration": {
    "id": "<ARM resource ID>",
    "name": "<resource name>",
    "type": "<ARM resource type>",
    "location": "<region>",
    "sku": { ... },
    "properties": { ... },
    "zones": [...]
  },
  "tags": { ... }
}

Access patterns:

  • Properties: azjson[configuration][properties][field]
  • SKU: azjson[configuration][sku][name]
  • Kind: azjson[configuration][kind]
  • Zones: azjson[configuration][zones]

Common configuration fields by service:

  • VM: properties.hardwareProfile.vmSize, properties.storageProfile.imageReference.offer, properties.storageProfile.osDisk.osType, properties.extended.instanceView.powerState.displayStatus
  • VMSS: sku.name (VM size), sku.capacity (instance count), tags.aks-managed-poolName
  • NSG: properties.securityRules[] (custom rules array), properties.securityRules[].properties.direction, properties.securityRules[].properties.access, properties.securityRules[].properties.sourceAddressPrefix
  • Storage Account: kind (e.g., StorageV2), sku.name, properties.accessTier, properties.supportsHttpsTrafficOnly, properties.allowBlobPublicAccess, properties.encryption.keySource
  • SQL Server: properties.fullyQualifiedDomainName, properties.publicNetworkAccess, properties.minimalTlsVersion
  • SQL Database: sku.name (tier), sku.capacity (DTU/vCore), properties.status, properties.zoneRedundant
  • AKS: properties.kubernetesVersion, properties.powerState.code, properties.networkProfile.networkPlugin, properties.enableRBAC
  • Web Site: kind (e.g., functionapp,linux), properties.state, properties.defaultHostName, properties.siteConfig.linuxFxVersion
  • Container App: properties.runningStatus, properties.template.containers[].image, properties.template.scale.minReplicas, properties.template.scale.maxReplicas
  • Event Hub Namespace: sku.name, properties.kafkaEnabled, properties.zoneRedundant
  • Service Bus Namespace: sku.name (Basic/Standard/Premium), properties.zoneRedundant, properties.minimumTlsVersion, properties.publicNetworkAccess, properties.disableLocalAuth, properties.status
  • Service Bus Queue: properties.maxSizeInMegabytes, properties.enablePartitioning, properties.deadLetteringOnMessageExpiration, properties.maxDeliveryCount, properties.lockDuration, properties.requiresDuplicateDetection, properties.status
  • Key Vault: properties.enableRbacAuthorization, properties.enableSoftDelete, properties.publicNetworkAccess
  • Redis: properties.sku.name, properties.hostName, properties.redisVersion, properties.enableNonSslPort
  • Cosmos DB: kind (e.g., GlobalDocumentDB), properties.EnabledApiTypes, properties.consistencyPolicy.defaultConsistencyLevel
  • Load Balancer: sku.name, tags.aks-managed-cluster-name
  • App Gateway: properties.sku.name, properties.sku.tier, properties.operationalState, properties.webApplicationFirewallConfiguration.enabled, properties.webApplicationFirewallConfiguration.firewallMode (Detection/Prevention), properties.webApplicationFirewallConfiguration.ruleSetType, properties.webApplicationFirewallConfiguration.ruleSetVersion, properties.webApplicationFirewallConfiguration.disabledRuleGroups[], properties.webApplicationFirewallConfiguration.exclusions[], properties.firewallPolicy.id

Query Patterns

All Azure queries build on four core patterns. Master these and adapt them to any entity type.

Pattern 1: Resource Discovery

List resources by type, filter by subscription/resource group/region/tags, summarize counts:

dql-template
smartscapeNodes "AZURE_*"
| filter azure.subscription == "<SUBSCRIPTION_ID>" and azure.location == "<REGION>"
| summarize count = count(), by: {type}
| sort count desc

To list a specific type, replace "AZURE_*" with the entity type (e.g., "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES"). Add | fields name, azure.subscription, azure.resource.group, azure.location, ... to select specific columns. Use tags[`TagName`] for tag-based filtering.

Pattern 2: Configuration Parsing

Parse azure.object JSON for detailed configuration fields:

dql-template
smartscapeNodes "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES"
| parse azure.object, "JSON:azjson"
| fieldsAdd vmSize = azjson[configuration][properties][hardwareProfile][vmSize],
            osType = azjson[configuration][properties][storageProfile][osDisk][osType]
| summarize vm_count = count(), by: {vmSize, osType, azure.location}
Show full SKILL.md (696 more words)Show less
Pattern 3: Relationship Traversal

Follow relationships between resources. Use "*" for the relationship name since Azure does not populate dt.traverse.relationship:

dql-template
smartscapeNodes "AZURE_MICROSOFT_NETWORK_LOADBALANCERS"
| parse azure.object, "JSON:azjson"
| fieldsAdd lbSku = azjson[configuration][sku][name]
| traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_BACKENDADDRESSPOOLS", fieldsKeep:{lbSku, name, id}
| fieldsAdd backendPoolName = name
| traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS", direction:backward, fieldsKeep:{backendPoolName, id}
| fieldsAdd loadBalancerName = dt.traverse.history[-2][name],
            loadBalancerId = dt.traverse.history[-2][id],
            backendPoolId = dt.traverse.history[-1][id]

Key differences from AWS traversals:

  • Always use "*" as the relationship name (relationship type names are empty for Azure)
  • Azure relationships primarily follow a parent-child hierarchy: sub-resources link backward to parent resources
  • AKS is a major relationship hub with backward links from VMSS, NSGs, LBs, Public IPs, Agent Pools, and Managed Identities
Pattern 4: Tag-Based Ownership

Group resources by any tag for ownership/chargeback:

dql-template
smartscapeNodes "AZURE_*"
| filter isNotNull(tags[`<TAG_NAME>`])
| summarize resource_count = count(), by: {tags[`<TAG_NAME>`], type}
| sort resource_count desc

Common Azure tags: tags[`ACE:CREATED-BY`], tags[`dt_owner_email`], tags[`dt_owner_team`], tags[`project`], tags[`managed-by`]. Replace "AZURE_*" with a specific type to scope to one service.

Find untagged resources: | filter arraySize(tags) == 0


Reference Guide

Load reference files for detailed queries when the core patterns above need service-specific adaptation.

ReferenceWhen to loadKey content
vnet-networking-security.mdVNet topology, subnets, NSGs, public IPs, VPN, peeringVNet/subnet mapping, NSG blast radius, public IP detection
database-monitoring.mdAzure SQL, Cosmos DB, Redis CacheService tier distribution, zone redundancy, public access checks
serverless-containers.mdFunctions, App Service, AKS infra, Container AppsRuntime distribution, App Service Plan mapping, AKS node pools
load-balancing-api.mdLoad Balancers, Application Gateways, API ManagementLB backend pool traversal, App Gateway routing, APIM config
messaging-integration.mdEvent Hubs, Service Bus, Event GridNamespace inventory, Kafka enablement, throughput unit analysis
storage-monitoring.mdStorage Accounts, Blob, File, Queue, TableSKU distribution, access tier, encryption audit, public access
resource-management.mdResource audits, tag compliance, lifecycleUnattached disks, tag coverage, provisioning state analysis
cost-optimization.mdCost savings, unused resources, sizingVM SKU analysis, unattached disks, deallocated VMs
capacity-planning.mdCapacity analysis, scaling, utilizationVMSS headroom, subnet IP counts, AKS node pool sizing
security-compliance.mdSecurity audits, encryption, public access, Key VaultNSG rule analysis, TLS version audit, public endpoint detection, encryption checks
resource-ownership.mdChargeback, ownership, cost allocationTag-based grouping, subscription/resource-group summaries
workload-detection.mdDetermine orchestration context and resolution pathAKS node, VMSS member, standalone VM detection for blast radius analysis
metrics-performance.mdQuery metric timeseries for a specific resourceDQL timeseries patterns for VM, SQL, Storage, Event Hub, LB, App Service, AKS, Cosmos DB, Redis, App Gateway

Best Practices

Query Optimization
  1. Filter early by subscription, resource group, and region
  2. Use specific entity types (avoid "AZURE_*" wildcards when possible)
  3. Limit results with | limit N for exploration
  4. Use isNotNull() checks before accessing nested fields
Configuration Parsing
  1. Always parse azure.object with JSON parser: parse azure.object, "JSON:azjson"
  2. Use consistent field naming: fieldsAdd configField = azjson[configuration][properties][field]
  3. Access SKU via azjson[configuration][sku][name] (not inside properties)
  4. Check for null values after parsing — not all entity types have the same properties structure
  5. Use toString() for complex nested objects
Organizational Hierarchy
  1. Always scope queries by azure.subscription in multi-subscription environments
  2. Use azure.resource.group to narrow to a team or application boundary
  3. Combine azure.location for region-specific analysis
  4. Use summarize ... by: {azure.subscription, azure.resource.group} for organizational breakdowns
Tagging Strategy
  1. Use tags[`key`] for filtering (backtick-quoted key names)
  2. Check arraySize(tags) for untagged resources
  3. Track tag coverage with summarize operations
  4. Common ownership tags: dt_owner_email, dt_owner_team, ACE:CREATED-BY

Limitations and Notes

Smartscape Limitations
  • Azure object configuration requires parsing with parse azure.object, "JSON:azjson"
  • Azure metrics are available as Dynatrace metrics using the cloud.azure.* naming convention (see Azure Metric Naming Convention)
  • Resource discovery depends on Azure integration configuration in Dynatrace
  • Tag synchronization may have slight delays
Relationship Traversal
  • Azure relationship type names are empty — always use "*" as the relationship name in traverse commands
  • Use direction:backward for reverse relationships (e.g., sub-resources to parent)
  • Use fieldsKeep to maintain important fields through traversal
  • Access traversal history with dt.traverse.history[0][id] for single-hop source entity ID; use lookup to resolve source entity name
  • For multi-hop traversals, dt.traverse.history[-N] accesses fields carried via fieldsKeep
  • Azure relationships primarily follow parent-child hierarchy patterns
  • AKS is a major relationship hub — expect many backward relationships converging on AKS cluster entities
AKS Coverage
  • This skill covers AKS infrastructure-layer entities only (clusters, agent pools, VMSS, networking)
  • For Kubernetes workload-layer observability (pods, deployments, services, namespaces), defer to the dt-obs-kubernetes skill
General Tips
  • Use getNodeName() for human-readable resource names
  • Handle null values gracefully with isNotNull() and isNull()
  • Combine subscription, resource group, and region filters for large environments
  • Use countDistinct() for unique resource counts
  • The azure.resourceType field is lowercase ARM format (e.g., microsoft.compute/virtualmachines) — useful for filtering but not for entity type matching

© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (references) in skills/dt-obs-azure of Dynatrace/dynatrace-for-ai.

  • SKILL.md
  • references/README.md
  • references/capacity-planning.md
  • references/cost-optimization.md
  • references/database-monitoring.md
  • references/load-balancing-api.md
  • references/messaging-integration.md
  • references/metrics-performance.md
  • references/resource-management.md
  • references/resource-ownership.md
  • references/security-compliance.md
  • references/serverless-containers.md
  • references/storage-monitoring.md
  • references/vnet-networking-security.md
  • references/workload-detection.md

Open the folder on GitHubat commit 4f9aa71

Compare with similar skills

Dt Obs Azure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dt Obs Azure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dt Obs Azure this skillDynatrace/dynatrace-for-ai163—~6.3kAutomated safety check: PassApache-2.0
Azure Resource Manager SQL Dotnetmicrosoft/skills3.1k5 repos~2.6kAutomated safety check: PassMIT
Implementing Azure Defender For Cloudmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Apex Azure Storagejonathan-vella/apex217—~1.7kAutomated safety check: PassMIT
Azure Storagemicrosoft/GitHub-Copilot-for-Azure2552 repos~1.3kAutomated safety check: PassMIT
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0

Similar skills

  • Official

    Azure Resource Manager SDK for Azure SQL in .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Implementing Azure Defender For Cloud

    mukul975/Anthropic-Cybersecurity-Skills

    Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Apex Azure Storage

    jonathan-vella/apex

    UTILITY SKILL — Azure Storage: Blob, File Shares, Queue, Table and Data Lake, including access tiers and lifecycle management.

    217 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    DatabasesAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from Dynatrace/dynatrace-for-ai

All 33 skills in this repo
  • Dt Obs Analytics

    Dynatrace/dynatrace-for-ai

    Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.

    163 GitHub stars~3.9k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Setup iOS

    Dynatrace/dynatrace-for-ai

    Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.

    163 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Alerting

    Dynatrace/dynatrace-for-ai

    End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

    163 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    163 GitHub stars~4.2k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Ext Monitors

    Dynatrace/dynatrace-for-ai

    3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).

    163 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Problems

    Dynatrace/dynatrace-for-ai

    DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.

    163 GitHub stars~4.6k tokensUpdated 9 days ago
    Auto-check passed

Categories

Questions about Dt Obs Azure

What does Dt Obs Azure do?

Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault. Dt Obs Azure is an agent skill from Dynatrace/dynatrace-for-ai. Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault.

When should I use Dt Obs Azure?

Dt Obs Azure fits situations like: tasks that involve Cloud networking; tasks that involve Secrets management.

How do I install Dt Obs Azure in Claude Code?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a claude-code`. Or copy the skill folder (skills/dt-obs-azure in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-obs-azure in your project. Claude Code loads it when a task matches its description.

How do I install Dt Obs Azure in Codex?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a codex`. Or copy the skill folder (skills/dt-obs-azure in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-obs-azure in your project. Codex loads it when a task matches its description.

Can I use Dt Obs Azure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-obs-azure, .gemini/skills/dt-obs-azure, .github/skills/dt-obs-azure and .opencode/skills/dt-obs-azure in your project.

What does Dt Obs Azure need to run?

SKILL.md names no scripts, command-line tools or credentials: Dt Obs Azure is instructions for the agent only.

Does Dt Obs Azure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dt Obs Azure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dt Obs Azure use?

Dt Obs Azure is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dt Obs Azure use?

About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 38k tokens, read only when the agent opens those files.

What are the alternatives to Dt Obs Azure?

Skills that share tags, products or a category with Dt Obs Azure: Azure Resource Manager SQL Dotnet (microsoft/skills, 3.1k stars), Implementing Azure Defender For Cloud (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Apex Azure Storage (jonathan-vella/apex, 217 stars) and Azure Storage (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dt Obs Azure?

Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.