Azure Resource Manager SQL Dotnet
microsoft/skills
Azure Resource Manager SDK for Azure SQL in .NET. An agent skill from microsoft/skills.
Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-obs-azure .claude/skills/dt-obs-azure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dt-obs-azure" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azure into .claude/skills/dt-obs-azure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-obs-azure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dt-obs-azure .agents/skills/dt-obs-azure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dt-obs-azure" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azure into .agents/skills/dt-obs-azure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-obs-azure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dt-obs-azure .cursor/skills/dt-obs-azure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dt-obs-azure" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azure into .cursor/skills/dt-obs-azure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-obs-azure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Dynatrace/dynatrace-for-ai.git --path skills/dt-obs-azure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dt-obs-azure .gemini/skills/dt-obs-azure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dt-obs-azure" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azure into .gemini/skills/dt-obs-azure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-obs-azure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dt-obs-azure .github/skills/dt-obs-azure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dt-obs-azure" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azure into .github/skills/dt-obs-azure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-obs-azure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-azure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dt-obs-azure .opencode/skills/dt-obs-azure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dt-obs-azure" agent skill from https://github.com/Dynatrace/dynatrace-for-ai/tree/main/skills/dt-obs-azure into .opencode/skills/dt-obs-azure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dt-obs-azure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dt-obs-azureAzure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault.
Dt Obs Azure is an agent skill from Dynatrace/dynatrace-for-ai. Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault. Monitor Azure infrastructure, analyze resource usage, audit security posture, and manage organizational hierarchy across subscriptions and resource groups.
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `references/README.md`, `references/capacity-planning.md` and `references/cost-optimization.md`).
It sits in DevOps & Cloud, covering Cloud networking and Secrets management. It works with Microsoft Azure, Azure Event Hubs and SQL. The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are dql-template, dql-snippet, dql and json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dt Obs Azure loads about 6.3k tokens when it runs, and up to ~45k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,730 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 1,730 words, ~6,295 tokens.
.claude/skills/dt-obs-azure/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.Monitor and analyze Azure resources using Dynatrace Smartscape and DQL. Query Azure services, audit security, manage organizational hierarchy, and plan capacity across your Azure infrastructure.
Use this skill when the user needs to work with Azure resources in Dynatrace. Load the reference file for the task type:
| Task | File to load |
|---|---|
| Inventory and topology queries | (no additional file — use core patterns below) |
| Query Azure metric timeseries (CPU, latency, throughput) | Load references/metrics-performance.md |
| VNet topology, subnets, NSGs, public IPs, VPN, peering | Load references/vnet-networking-security.md |
| Azure SQL, Cosmos DB, PostgreSQL, Redis investigation | Load references/database-monitoring.md |
| Functions, App Service, AKS infrastructure, Container Apps | Load references/serverless-containers.md |
| Azure LB, Application Gateway, Front Door, API Management | Load references/load-balancing-api.md |
| WAF rule analysis, false-positive investigation | Load references/load-balancing-api.md |
| Event Hubs, Service Bus, Event Grid | Load references/messaging-integration.md |
| Storage Accounts, Blob, File, Queue, Table | Load references/storage-monitoring.md |
| Unattached resources, tag compliance, lifecycle | Load references/resource-management.md |
| Cost savings, unused resources, SKU analysis | Load references/cost-optimization.md |
| Capacity headroom, VMSS scaling, quotas | Load references/capacity-planning.md |
| Security audit, encryption, public access, Key Vault | Load references/security-compliance.md |
| NSG rule analysis (0.0.0.0/0, open ports) | Load references/security-compliance.md |
| Storage account encryption/public access audit | Load references/security-compliance.md |
| Cost allocation, chargeback, ownership | Load references/resource-ownership.md |
| Determine orchestration context (AKS, VMSS, standalone) | Load references/workload-detection.md |
Azure resources use the AZURE_* prefix and can be queried using the smartscapeNodes function. All Azure entities are automatically discovered and modeled in Dynatrace Smartscape. Entity type names are derived from the ARM resource provider path: /Microsoft.Compute/virtualMachines becomes AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES. Sub-resources append with underscores: /Microsoft.Sql/servers/databases becomes AZURE_MICROSOFT_SQL_SERVERS_DATABASES.
Compute: AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES, AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS, AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS_VIRTUALMACHINES, AZURE_MICROSOFT_COMPUTE_DISKS, AZURE_MICROSOFT_COMPUTE_SSHPUBLICKEYS, AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES_EXTENSIONS
Networking: AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS, AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS_SUBNETS, AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS, AZURE_MICROSOFT_NETWORK_PUBLICIPADDRESSES, AZURE_MICROSOFT_NETWORK_NETWORKINTERFACES, AZURE_MICROSOFT_NETWORK_LOADBALANCERS, AZURE_MICROSOFT_NETWORK_APPLICATIONGATEWAYS, AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKGATEWAYS, AZURE_MICROSOFT_NETWORK_CONNECTIONS, AZURE_MICROSOFT_NETWORK_EXPRESSROUTECIRCUITS
Database: AZURE_MICROSOFT_SQL_SERVERS, AZURE_MICROSOFT_SQL_SERVERS_DATABASES, AZURE_MICROSOFT_CACHE_REDIS, AZURE_MICROSOFT_CACHE_REDISENTERPRISE, AZURE_MICROSOFT_DOCUMENTDB_DATABASEACCOUNTS
Storage: AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_BLOBSERVICES_CONTAINERS, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_FILESERVICES_SHARES, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_QUEUESERVICES_QUEUES, AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_TABLESERVICES_TABLES
Kubernetes/Containers: AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS, AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS_AGENTPOOLS, AZURE_MICROSOFT_CONTAINERREGISTRY_REGISTRIES, AZURE_MICROSOFT_APP_CONTAINERAPPS, AZURE_MICROSOFT_APP_MANAGEDENVIRONMENTS, AZURE_MICROSOFT_APP_JOBS
App Service: AZURE_MICROSOFT_WEB_SITES, AZURE_MICROSOFT_WEB_SERVERFARMS, AZURE_MICROSOFT_WEB_SITES_FUNCTIONS
Messaging: AZURE_MICROSOFT_EVENTHUB_NAMESPACES, AZURE_MICROSOFT_EVENTHUB_NAMESPACES_EVENTHUBS, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_QUEUES, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS, AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS_SUBSCRIPTIONS
Security/Identity: AZURE_MICROSOFT_KEYVAULT_VAULTS, AZURE_MICROSOFT_MANAGEDIDENTITY_USERASSIGNEDIDENTITIES
Monitoring: AZURE_MICROSOFT_OPERATIONALINSIGHTS_WORKSPACES, AZURE_MICROSOFT_INSIGHTS_COMPONENTS
API Management: AZURE_MICROSOFT_APIMANAGEMENT_SERVICE
Azure organizes resources in a three-level hierarchy: Tenant > Subscription > Resource Group. Every resource belongs to exactly one resource group within one subscription. Use these fields to scope queries:
filter azure.subscription == "08b9810e-..."filter azure.resource.group == "my-rg"filter azure.location == "eastus"Combine these filters for precise scoping:
smartscapeNodes "AZURE_*"
| filter azure.subscription == "<SUBSCRIPTION_ID>"
and azure.resource.group == "<RESOURCE_GROUP>"
and azure.location == "<REGION>"
| summarize count = count(), by: {type}
| sort count descTo see the organizational breakdown across your environment:
smartscapeNodes "AZURE_*"
| summarize resource_count = count(), by: {azure.subscription, azure.resource.group}
| sort resource_count descAll Azure entities include:
azure.subscription — Azure subscription GUIDazure.resource.group — Resource group nameazure.location — Azure region (e.g., eastus, polandcentral)azure.resourceType — ARM resource type (e.g., microsoft.compute/virtualmachines)azure.provisioning_state — Provisioning state (e.g., Succeeded)azure.object — Full ARM resource JSON (see Configuration Parsing)cloud.provider — Always azuretags — Resource tags (use tags[`key`])Some entity types also have:
azure.resourceId — Full ARM resource ID (VMs and some others)azure.resourceName — Resource name (VMs and some others)azure.availabilityZones — Availability zone list (VMs)Azure entity relationships can be traversed using traverse. The dt.traverse.relationship field is not populated for Azure entities, so you must use "*" as the relationship name in all traversal commands.
Key traversal pairs:
traverse "*", "AZURE_MICROSOFT_COMPUTE_DISKS"traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKINTERFACES"traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS"traverse "*", "AZURE_MICROSOFT_RESOURCES_LOCATIONS_AVAILABILITYZONES"traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES_EXTENSIONS", direction:backwardtraverse "*", "AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS"traverse "*", "AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS_SUBNETS"traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS"traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_BACKENDADDRESSPOOLS"traverse "*", "AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS"traverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS"traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS", direction:backwardtraverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKINTERFACES", direction:backwardtraverse "*", "AZURE_MICROSOFT_NETWORK_VIRTUALNETWORKS_SUBNETS", direction:backwardtraverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_BACKENDADDRESSPOOLS"traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_FRONTENDIPCONFIGURATIONS"traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_LOADBALANCINGRULES"traverse "*", "AZURE_MICROSOFT_SQL_SERVERS_DATABASES", direction:backwardtraverse "*", "AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_BLOBSERVICES_CONTAINERS", direction:backwardtraverse "*", "AZURE_MICROSOFT_STORAGE_STORAGEACCOUNTS_FILESERVICES_SHARES", direction:backwardtraverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS", direction:backwardtraverse "*", "AZURE_MICROSOFT_CONTAINERSERVICE_MANAGEDCLUSTERS_AGENTPOOLS", direction:backwardtraverse "*", "AZURE_MICROSOFT_NETWORK_NETWORKSECURITYGROUPS", direction:backwardtraverse "*", "AZURE_MICROSOFT_NETWORK_PUBLICIPADDRESSES", direction:backwardtraverse "*", "AZURE_MICROSOFT_NETWORK_PUBLICIPADDRESSES"traverse "*", "AZURE_MICROSOFT_WEB_SERVERFARMS"traverse "*", "AZURE_MICROSOFT_WEB_SITES_FUNCTIONS", direction:backwardtraverse "*", "AZURE_MICROSOFT_APP_MANAGEDENVIRONMENTS"traverse "*", "AZURE_MICROSOFT_EVENTHUB_NAMESPACES_EVENTHUBS", direction:backwardtraverse "*", "AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_QUEUES", direction:backwardtraverse "*", "AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS", direction:backwardtraverse "*", "AZURE_MICROSOFT_SERVICEBUS_NAMESPACES_TOPICS_SUBSCRIPTIONS", direction:backwardfieldsKeep:{field1, field2} to carry fields through multi-hop traversalsdt.traverse.history[0][id] to get the source entity ID, then lookup to resolve the source entity name:| fieldsAdd sourceId = dt.traverse.history[0][id]
| lookup [smartscapeNodes "SOURCE_TYPE" | fields name, id], sourceField: sourceId, lookupField: id, prefix: "src."dt.traverse.history[-N] works for fields carried via fieldsKeepDynatrace ingests Azure Monitor metrics and exposes them using this naming pattern:
cloud.azure.<provider_namespace>.<resource_type>.<MetricName>The <provider_namespace> uses underscores within the namespace (e.g., microsoft_compute) and <resource_type> is lowercase (e.g., virtualmachines). Hierarchy levels are dot-separated: microsoft_sql.servers.databases. <MetricName> is the Azure Monitor metric name.
Examples:
| Azure Monitor metric | Dynatrace metric key |
|---|---|
VM Percentage CPU | cloud.azure.microsoft_compute.virtualmachines.PercentageCPU |
SQL DB cpu_percent | cloud.azure.microsoft_sql.servers.databases.cpu_percent |
Storage Ingress | cloud.azure.microsoft_storage.storageaccounts.Ingress |
Event Hub IncomingMessages | cloud.azure.microsoft_eventhub.namespaces.IncomingMessages |
Service Bus IncomingMessages | cloud.azure.microsoft_servicebus.namespaces.IncomingMessages |
App Service HttpResponseTime | cloud.azure.microsoft_web.sites.HttpResponseTime |
Load Balancer ByteCount | cloud.azure.microsoft_network.loadbalancers.ByteCount |
AKS node_cpu_usage_percentage | cloud.azure.microsoft_containerservice.managedclusters.node_cpu_usage_percentage |
Cosmos DB TotalRequestUnits | cloud.azure.microsoft_documentdb.databaseaccounts.TotalRequestUnits |
Redis serverLoad | cloud.azure.microsoft_cache.redis.serverLoad |
App Gateway TotalRequests | cloud.azure.microsoft_network.applicationgateways.TotalRequests |
To query a metric:
timeseries cpu = avg(cloud.azure.microsoft_compute.virtualmachines.PercentageCPU),
by: {dt.smartscape_source.id},
from: now()-1h
| limit 10Important: Never refer to these as "Azure Monitor alerts" or "Azure Monitor metrics" in output. Dynatrace monitors Azure resources natively through its Azure integration — these are Dynatrace metrics ingested from Azure.
The azure.object field contains the full ARM resource JSON. Parse it with the azjson alias:
parse azure.object, "JSON:azjson"The JSON is wrapped in a configuration key:
{
"configuration": {
"id": "<ARM resource ID>",
"name": "<resource name>",
"type": "<ARM resource type>",
"location": "<region>",
"sku": { ... },
"properties": { ... },
"zones": [...]
},
"tags": { ... }
}Access patterns:
azjson[configuration][properties][field]azjson[configuration][sku][name]azjson[configuration][kind]azjson[configuration][zones]Common configuration fields by service:
properties.hardwareProfile.vmSize, properties.storageProfile.imageReference.offer, properties.storageProfile.osDisk.osType, properties.extended.instanceView.powerState.displayStatussku.name (VM size), sku.capacity (instance count), tags.aks-managed-poolNameproperties.securityRules[] (custom rules array), properties.securityRules[].properties.direction, properties.securityRules[].properties.access, properties.securityRules[].properties.sourceAddressPrefixkind (e.g., StorageV2), sku.name, properties.accessTier, properties.supportsHttpsTrafficOnly, properties.allowBlobPublicAccess, properties.encryption.keySourceproperties.fullyQualifiedDomainName, properties.publicNetworkAccess, properties.minimalTlsVersionsku.name (tier), sku.capacity (DTU/vCore), properties.status, properties.zoneRedundantproperties.kubernetesVersion, properties.powerState.code, properties.networkProfile.networkPlugin, properties.enableRBACkind (e.g., functionapp,linux), properties.state, properties.defaultHostName, properties.siteConfig.linuxFxVersionproperties.runningStatus, properties.template.containers[].image, properties.template.scale.minReplicas, properties.template.scale.maxReplicassku.name, properties.kafkaEnabled, properties.zoneRedundantsku.name (Basic/Standard/Premium), properties.zoneRedundant, properties.minimumTlsVersion, properties.publicNetworkAccess, properties.disableLocalAuth, properties.statusproperties.maxSizeInMegabytes, properties.enablePartitioning, properties.deadLetteringOnMessageExpiration, properties.maxDeliveryCount, properties.lockDuration, properties.requiresDuplicateDetection, properties.statusproperties.enableRbacAuthorization, properties.enableSoftDelete, properties.publicNetworkAccessproperties.sku.name, properties.hostName, properties.redisVersion, properties.enableNonSslPortkind (e.g., GlobalDocumentDB), properties.EnabledApiTypes, properties.consistencyPolicy.defaultConsistencyLevelsku.name, tags.aks-managed-cluster-nameproperties.sku.name, properties.sku.tier, properties.operationalState, properties.webApplicationFirewallConfiguration.enabled, properties.webApplicationFirewallConfiguration.firewallMode (Detection/Prevention), properties.webApplicationFirewallConfiguration.ruleSetType, properties.webApplicationFirewallConfiguration.ruleSetVersion, properties.webApplicationFirewallConfiguration.disabledRuleGroups[], properties.webApplicationFirewallConfiguration.exclusions[], properties.firewallPolicy.idAll Azure queries build on four core patterns. Master these and adapt them to any entity type.
List resources by type, filter by subscription/resource group/region/tags, summarize counts:
smartscapeNodes "AZURE_*"
| filter azure.subscription == "<SUBSCRIPTION_ID>" and azure.location == "<REGION>"
| summarize count = count(), by: {type}
| sort count descTo list a specific type, replace "AZURE_*" with the entity type (e.g., "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES"). Add | fields name, azure.subscription, azure.resource.group, azure.location, ... to select specific columns. Use tags[`TagName`] for tag-based filtering.
Parse azure.object JSON for detailed configuration fields:
smartscapeNodes "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINES"
| parse azure.object, "JSON:azjson"
| fieldsAdd vmSize = azjson[configuration][properties][hardwareProfile][vmSize],
osType = azjson[configuration][properties][storageProfile][osDisk][osType]
| summarize vm_count = count(), by: {vmSize, osType, azure.location}Follow relationships between resources. Use "*" for the relationship name since Azure does not populate dt.traverse.relationship:
smartscapeNodes "AZURE_MICROSOFT_NETWORK_LOADBALANCERS"
| parse azure.object, "JSON:azjson"
| fieldsAdd lbSku = azjson[configuration][sku][name]
| traverse "*", "AZURE_MICROSOFT_NETWORK_LOADBALANCERS_BACKENDADDRESSPOOLS", fieldsKeep:{lbSku, name, id}
| fieldsAdd backendPoolName = name
| traverse "*", "AZURE_MICROSOFT_COMPUTE_VIRTUALMACHINESCALESETS", direction:backward, fieldsKeep:{backendPoolName, id}
| fieldsAdd loadBalancerName = dt.traverse.history[-2][name],
loadBalancerId = dt.traverse.history[-2][id],
backendPoolId = dt.traverse.history[-1][id]Key differences from AWS traversals:
"*" as the relationship name (relationship type names are empty for Azure)Group resources by any tag for ownership/chargeback:
smartscapeNodes "AZURE_*"
| filter isNotNull(tags[`<TAG_NAME>`])
| summarize resource_count = count(), by: {tags[`<TAG_NAME>`], type}
| sort resource_count descCommon Azure tags: tags[`ACE:CREATED-BY`], tags[`dt_owner_email`], tags[`dt_owner_team`], tags[`project`], tags[`managed-by`]. Replace "AZURE_*" with a specific type to scope to one service.
Find untagged resources: | filter arraySize(tags) == 0
Load reference files for detailed queries when the core patterns above need service-specific adaptation.
| Reference | When to load | Key content |
|---|---|---|
| vnet-networking-security.md | VNet topology, subnets, NSGs, public IPs, VPN, peering | VNet/subnet mapping, NSG blast radius, public IP detection |
| database-monitoring.md | Azure SQL, Cosmos DB, Redis Cache | Service tier distribution, zone redundancy, public access checks |
| serverless-containers.md | Functions, App Service, AKS infra, Container Apps | Runtime distribution, App Service Plan mapping, AKS node pools |
| load-balancing-api.md | Load Balancers, Application Gateways, API Management | LB backend pool traversal, App Gateway routing, APIM config |
| messaging-integration.md | Event Hubs, Service Bus, Event Grid | Namespace inventory, Kafka enablement, throughput unit analysis |
| storage-monitoring.md | Storage Accounts, Blob, File, Queue, Table | SKU distribution, access tier, encryption audit, public access |
| resource-management.md | Resource audits, tag compliance, lifecycle | Unattached disks, tag coverage, provisioning state analysis |
| cost-optimization.md | Cost savings, unused resources, sizing | VM SKU analysis, unattached disks, deallocated VMs |
| capacity-planning.md | Capacity analysis, scaling, utilization | VMSS headroom, subnet IP counts, AKS node pool sizing |
| security-compliance.md | Security audits, encryption, public access, Key Vault | NSG rule analysis, TLS version audit, public endpoint detection, encryption checks |
| resource-ownership.md | Chargeback, ownership, cost allocation | Tag-based grouping, subscription/resource-group summaries |
| workload-detection.md | Determine orchestration context and resolution path | AKS node, VMSS member, standalone VM detection for blast radius analysis |
| metrics-performance.md | Query metric timeseries for a specific resource | DQL timeseries patterns for VM, SQL, Storage, Event Hub, LB, App Service, AKS, Cosmos DB, Redis, App Gateway |
"AZURE_*" wildcards when possible)| limit N for explorationisNotNull() checks before accessing nested fieldsazure.object with JSON parser: parse azure.object, "JSON:azjson"fieldsAdd configField = azjson[configuration][properties][field]azjson[configuration][sku][name] (not inside properties)toString() for complex nested objectsazure.subscription in multi-subscription environmentsazure.resource.group to narrow to a team or application boundaryazure.location for region-specific analysissummarize ... by: {azure.subscription, azure.resource.group} for organizational breakdownstags[`key`] for filtering (backtick-quoted key names)arraySize(tags) for untagged resourcesdt_owner_email, dt_owner_team, ACE:CREATED-BYparse azure.object, "JSON:azjson"cloud.azure.* naming convention (see Azure Metric Naming Convention)"*" as the relationship name in traverse commandsdirection:backward for reverse relationships (e.g., sub-resources to parent)fieldsKeep to maintain important fields through traversaldt.traverse.history[0][id] for single-hop source entity ID; use lookup to resolve source entity namedt.traverse.history[-N] accesses fields carried via fieldsKeepdt-obs-kubernetes skillgetNodeName() for human-readable resource namesisNotNull() and isNull()countDistinct() for unique resource countsazure.resourceType field is lowercase ARM format (e.g., microsoft.compute/virtualmachines) — useful for filtering but not for entity type matching© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 14 other files (references) in skills/dt-obs-azure of Dynatrace/dynatrace-for-ai.
Open the folder on GitHubat commit 4f9aa71
Dt Obs Azure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dt Obs Azure this skillDynatrace/dynatrace-for-ai | 163 | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | |
| Azure Resource Manager SQL Dotnetmicrosoft/skills | 3.1k | 5 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Implementing Azure Defender For Cloudmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Apex Azure Storagejonathan-vella/apex | 217 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Azure Storagemicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Dangling DNS Finderanirudhbiyani/findmytakeover | 180 | — | ~1.8k | Automated safety check: Pass | GPL-3.0 |
microsoft/skills
Azure Resource Manager SDK for Azure SQL in .NET. An agent skill from microsoft/skills.
mukul975/Anthropic-Cybersecurity-Skills
Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…
jonathan-vella/apex
UTILITY SKILL — Azure Storage: Blob, File Shares, Queue, Table and Data Lake, including access tiers and lifecycle management.
microsoft/GitHub-Copilot-for-Azure
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.
anirudhbiyani/findmytakeover
Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
Dynatrace/dynatrace-for-ai
Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.
Dynatrace/dynatrace-for-ai
Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.
Dynatrace/dynatrace-for-ai
End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…
Dynatrace/dynatrace-for-ai
AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.
Dynatrace/dynatrace-for-ai
3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).
Dynatrace/dynatrace-for-ai
DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.
Works with
Categories
Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault. Dt Obs Azure is an agent skill from Dynatrace/dynatrace-for-ai. Azure cloud resources including VMs, VMSS, SQL Database, Storage, AKS, App Service, Functions, VNet networking, load balancers, Event Hubs, Container Apps, and Key Vault.
Dt Obs Azure fits situations like: tasks that involve Cloud networking; tasks that involve Secrets management.
Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a claude-code`. Or copy the skill folder (skills/dt-obs-azure in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-obs-azure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a codex`. Or copy the skill folder (skills/dt-obs-azure in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-obs-azure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-azure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-obs-azure, .gemini/skills/dt-obs-azure, .github/skills/dt-obs-azure and .opencode/skills/dt-obs-azure in your project.
SKILL.md names no scripts, command-line tools or credentials: Dt Obs Azure is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dt Obs Azure is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 38k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dt Obs Azure: Azure Resource Manager SQL Dotnet (microsoft/skills, 3.1k stars), Implementing Azure Defender For Cloud (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Apex Azure Storage (jonathan-vella/apex, 217 stars) and Azure Storage (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.
Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.