Agent skill

Dd Logs

by datadog-labs in datadog-labs/agent-skills

Log management - search, archives, metrics, and cost control.

MITAuto-check passedBusiness, Finance & HR

Install Dd Logs

skills CLI
$ npx skills add datadog-labs/agent-skills --skill dd-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install datadog-labs/agent-skills dd-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/datadog-labs/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dd-logs .claude/skills/dd-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dd-logs
GitHub stars
177
Used in
1 other repo
Token cost
~1.2k tokens
SKILL.md length
204 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Log management - search, archives, metrics, and cost control.

  • Works in 5 steps: Check context first (prior outputs,… → If a required value is missing, run a… → If still ambiguous, ask the user to… → …
  • Tasks that involve Budgeting and forecasting
  • SKILL.md covers Prerequisites, Command Execution Order…, Quick Start and Search Logs, plus 7 more sections
  • Calls jq

What it does

Dd Logs is an agent skill from datadog-labs/agent-skills. Log management - search, archives, metrics, and cost control.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Budgeting and forecasting. The repository describes itself as: Public repository for Datadog Agent Skills. The licence is MIT.

When your agent uses it

  • Tasks that involve Budgeting and forecasting

Example prompts

  • “/dd-logs”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check context first (prior outputs, conversation, saved values).
  2. If a required value is missing, run a discovery command first.
  3. If still ambiguous, ask the user to confirm.
  4. Then run the target command.
  5. Avoid speculative commands likely to fail.

What it can do on your machine

Read from SKILL.md and the folder at commit 5b40c73. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.datadoghq.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dd Logs loads about 1.2k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 204 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from datadog-labs/agent-skills at commit 5b40c73, republished under its MIT licence (© datadog-labs). 204 words, ~1,177 tokens.

Download SKILL.mdSave it as .claude/skills/dd-logs/SKILL.md (or your agent's skills folder).
name
dd-logs
description
Log management - search, archives, metrics, and cost control.
metadata.version
1.0.1
metadata.author
datadog-labs
metadata.repository
https://github.com/datadog-labs/agent-skills
metadata.tags
datadog,logs,logging,search,dd-logs
metadata.globs
**/datadog*.yaml,**/*log*
metadata.alwaysApply
false

Datadog Logs

Search, process, and archive logs with cost awareness.

Prerequisites

Datadog Pup should already be installed. See Setup Pup if not.

Command Execution Order (Token-Efficient)

For scoped commands, use this order:

  1. Check context first (prior outputs, conversation, saved values).
  2. If a required value is missing, run a discovery command first.
  3. If still ambiguous, ask the user to confirm.
  4. Then run the target command.
  5. Avoid speculative commands likely to fail.

Quick Start

bash
pup auth login

Search Logs

bash
# Basic search
pup logs search --query="status:error" --from="1h"

# With filters
pup logs search --query="service:api status:error" --from="1h" --limit 100

# JSON output
pup logs search --query="@http.status_code:>=500" --from="1h"
Search Syntax
QueryMeaning
errorFull-text search
status:errorTag equals
@http.status_code:500Attribute equals
@http.status_code:>=400Numeric range
service:api AND env:prodBoolean
@message:*timeout*Wildcard

Configuration APIs

Available log configuration commands in pup 0.42.0:

bash
# List log archives
pup logs archives list

# List log restriction queries
pup logs restriction-queries list

# List custom log destinations
pup logs custom-destinations list
Common Processors
json
{
  "name": "API Logs",
  "filter": {"query": "service:api"},
  "processors": [
    {
      "type": "grok-parser",
      "name": "Parse nginx",
      "source": "message",
      "grok": {"match_rules": "%{IPORHOST:client_ip} %{DATA:method} %{DATA:path} %{NUMBER:status}"}
    },
    {
      "type": "status-remapper",
      "name": "Set severity",
      "sources": ["level", "severity"]
    },
    {
      "type": "attribute-remapper",
      "name": "Remap user_id",
      "sources": ["user_id"],
      "target": "usr.id"
    }
  ]
}

Exclusion Filters (Cost Control)

Index only what matters:

json
{
  "name": "Drop debug logs",
  "filter": {"query": "status:debug"},
  "is_enabled": true
}
High-Volume Exclusions
bash
# Find noisiest log sources
pup logs search --query="*" --from="1h" | jq 'group_by(.service) | map({service: .[0].service, count: length}) | sort_by(-.count)[:10]'
ExcludeQuery
Health checks@http.url:"/health" OR @http.url:"/ready"
Debug logsstatus:debug
Static assets@http.url:*.css OR @http.url:*.js
Heartbeats@message:*heartbeat*

Archives

Store logs cheaply for compliance:

bash
# List archives
pup logs archives list

# Archive config (S3 example)
{
  "name": "compliance-archive",
  "query": "*",
  "destination": {
    "type": "s3",
    "bucket": "my-logs-archive",
    "path": "/datadog"
  },
  "rehydration_tags": ["team:platform"]
}
Rehydrate (Restore)
bash
# No `pup logs rehydrate` command in pup 0.42.0.
# Use Datadog UI/API for rehydration workflows.

Log-Based Metrics

Create metrics from logs (cheaper than indexing):

bash
# List log-based metrics
pup logs metrics list

# Get one metric by ID
pup logs metrics get api.errors.count

Cardinality warning: Group by bounded values only.

Sensitive Data

Scrubbing Rules
json
{
  "type": "hash-remapper",
  "name": "Hash emails",
  "sources": ["email", "@user.email"]
}
Never Log
python
# In your app - sanitize before sending
import re

def sanitize_log(message: str) -> str:
    # Remove credit cards
    message = re.sub(r'\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b', '[REDACTED]', message)
    # Remove SSNs
    message = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED]', message)
    return message

Troubleshooting

ProblemFix
Logs not appearingCheck agent, pipeline filters
High costsAdd exclusion filters
Search slowNarrow time range, use indexes
Missing attributesCheck grok parser

References/Documentation

© datadog-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in dd-logs of datadog-labs/agent-skills.

Open the folder on GitHubat commit 5b40c73

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in datadog-labs/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dd Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dd Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dd Logs this skilldatadog-labs/agent-skills1771 repos~1.2kAutomated safety check: PassMIT
Longbridge Researchhelsome/folio2693 repos~2.1kAutomated safety check: PassMIT
Cre Asset Managementahacker-1/cre-agent-skills1131 repos~1.8kAutomated safety check: PassApache-2.0
Bet SizingJoelLewis/finance_skills205—~2.5kAutomated safety check: PassMIT
Dd LogsDataDog/pup1k—~1.3kAutomated safety check: PassApache-2.0
Cash Flow ForecastWellApp-ai/Well345—~567Automated safety check: PassMIT

Similar skills

  • Longbridge Research

    helsome/folio

    Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…

    269 GitHub starsUsed in 3 repos~2.1k tokens
    Business, Finance & HRAuto-check passed
  • Cre Asset Management

    ahacker-1/cre-agent-skills

    CRE Asset Management analysis suite — 9 specialist skills for post-acquisition multifamily operations including annual budgeting, monthly variance analysis, rent collection, renewal decisions…

    113 GitHub starsUsed in 1 repo~1.8k tokens
    Business, Finance & HRAuto-check passed
  • Bet Sizing

    JoelLewis/finance_skills

    Determine how much capital to allocate to individual positions within a portfolio.

    205 GitHub stars~2.5k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Dd Logs

    DataDog/pup

    Official

    Log management - search, pipelines, archives, and cost control.

    1k GitHub stars~1.3k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Cash Flow Forecast

    WellApp-ai/Well

    Forecast cash flow and runway for a Well workspace from booked invoices and collected bank transactions.

    345 GitHub stars~567 tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Cash Flow Snapshot

    sandbaseai/sandbase-skills

    Create a 30/60/90-day cash-flow forecast from AR, AP, opening cash, payment timing, and fixed-cost data.

    201 GitHub stars~1.9k tokensUpdated 12 days ago
    Business, Finance & HRAuto-check passed

More from datadog-labs/agent-skills

All 38 skills in this repo
  • Bootstrap a reproducible LLM Observability experiment through the Python ddtrace SDK or the Node dd-trace SDK.

    177 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Dd Account Setup

    datadog-labs/agent-skills

    Ensure the user has an authenticated Datadog account with a valid DDAPIKEY on the right region before any Datadog setup or instrumentation.

    177 GitHub stars~4.4k tokensUpdated today
    Auto-check: notes
  • Dd Orchestrator

    datadog-labs/agent-skills

    Entry point for Datadog onboarding. An agent skill from datadog-labs/agent-skills.

    177 GitHub stars~6.7k tokensUpdated today
    Auto-check passed
  • Dd Apm

    datadog-labs/agent-skills

    APM - install, onboard, instrument, enable, set up, configure, traces, services, dependencies, performance analysis, Data Streams Monitoring (DSM), queue lag, pipeline latency.

    177 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Agent Install

    datadog-labs/agent-skills

    Install the Datadog Agent on Kubernetes using the Datadog Operator — required before enabling Single Step Instrumentation (SSI), which automatically instruments applications for APM without code…

    177 GitHub stars~2.1k tokensUpdated today
    Auto-check: warnings
  • Dd AWS Integration

    datadog-labs/agent-skills

    Set up the Datadog AWS integration with Terraform - creates the cross-account IAM role Datadog assumes (external ID, no stored credentials), attaches the permission policies Datadog publishes, and…

    177 GitHub stars~6.8k tokensUpdated today
    Auto-check: notes

Questions about Dd Logs

What does Dd Logs do?

Log management - search, archives, metrics, and cost control. Dd Logs is an agent skill from datadog-labs/agent-skills. Log management - search, archives, metrics, and cost control.

When should I use Dd Logs?

Dd Logs fits situations like: tasks that involve Budgeting and forecasting.

How do I install Dd Logs in Claude Code?

Run `npx skills add datadog-labs/agent-skills --skill dd-logs -a claude-code`. Or copy the skill folder (dd-logs in datadog-labs/agent-skills) into .claude/skills/dd-logs in your project. Claude Code loads it when a task matches its description.

How do I install Dd Logs in Codex?

Run `npx skills add datadog-labs/agent-skills --skill dd-logs -a codex`. Or copy the skill folder (dd-logs in datadog-labs/agent-skills) into .agents/skills/dd-logs in your project. Codex loads it when a task matches its description.

Can I use Dd Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add datadog-labs/agent-skills --skill dd-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dd-logs, .gemini/skills/dd-logs, .github/skills/dd-logs and .opencode/skills/dd-logs in your project.

What does Dd Logs need to run?

Going by SKILL.md and its folder, Dd Logs needs the command-line tools its instructions call (jq). Our summary lists: Python 3.

Does Dd Logs access the network?

SKILL.md names 1 domain. As links in the text: docs.datadoghq.com. This is read from the text; nothing was executed.

Is Dd Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dd Logs use?

Dd Logs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dd Logs use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dd Logs?

Skills that share tags, products or a category with Dd Logs: Longbridge Research (helsome/folio, 269 stars), Cre Asset Management (ahacker-1/cre-agent-skills, 113 stars), Bet Sizing (JoelLewis/finance_skills, 205 stars) and Dd Logs (DataDog/pup, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dd Logs?

datadog-labs (a GitHub organization) maintains it in datadog-labs/agent-skills, which has 177 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.

Source: datadog-labs/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.