{"resources":{"datadog":{"id":"datadog","name":"datadog","fields":{"apiKey":{"name":"apiKey","type":"\u001bdatadog.apiKey","title":"Datadog API Key","desc":"Credential that authorizes Datadog agents and integrations to submit metrics, traces, logs, and events to the organization. The `last4` field exposes only the final four characters so a key can be identified without revealing the secret. The `createdAt` and `modifiedAt` timestamps let you audit key age and flag stale or unrotated credentials.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"apiKeys":{"name":"apiKeys","type":"\u0019\u001bdatadog.apiKey","title":"API keys that allow agents and integrations to send data to Datadog","provider":"go.mondoo.com/mql/providers/datadog"},"applicationKey":{"name":"applicationKey","type":"\u001bdatadog.applicationKey","title":"Datadog Application Key","desc":"Application key that a user presents alongside an API key to make authenticated Datadog HTTP API calls. Auditing these surfaces which keys exist, who owns them, and how broad their access is: the `scopes` field is null when the key has full account access, and otherwise lists the specific permission scopes granted to it.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"applicationKeys":{"name":"applicationKeys","type":"\u0019\u001bdatadog.applicationKey","title":"Application keys used by users for HTTP API calls","provider":"go.mondoo.com/mql/providers/datadog"},"dashboard":{"name":"dashboard","type":"\u001bdatadog.dashboard","title":"Datadog Dashboard","desc":"Visualization dashboard in a Datadog organization, showing metrics, logs, traces, and other telemetry on a shared canvas. The layoutType distinguishes free-form canvases (`free`) from auto-arranged grids (`ordered`). Query these to audit dashboard ownership through the authorHandle, spot dashboards left editable versus locked read-only, and track when dashboards were created or last modified.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"dashboards":{"name":"dashboards","type":"\u0019\u001bdatadog.dashboard","title":"Dashboards in the organization","provider":"go.mondoo.com/mql/providers/datadog"},"downtime":{"name":"downtime","type":"\u001bdatadog.downtime","title":"Datadog Downtime","desc":"Datadog scheduled downtime that silences monitor alerts during planned maintenance or incidents, so on-call teams are not paged for expected disruption. Query these to audit which monitors are muted, over what scope, and on what schedule. The `status` field distinguishes active, scheduled, ended, and canceled downtimes, and `monitorIdentifier` selects whether the downtime targets a single monitor or a set of monitor tags.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"downtimes":{"name":"downtimes","type":"\u0019\u001bdatadog.downtime","title":"Downtimes (scheduled)","provider":"go.mondoo.com/mql/providers/datadog"},"integration":{"name":"integration","type":"\u001bdatadog.integration","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"integrationAwsAccounts":{"name":"integrationAwsAccounts","type":"\u0019\u001bdatadog.integration.aws","title":"Configured AWS integrations (Datadog AWS account links)","provider":"go.mondoo.com/mql/providers/datadog"},"ipAllowlistEnabled":{"name":"ipAllowlistEnabled","type":"\u0004","title":"Whether the IP allowlist is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"ipAllowlistEntries":{"name":"ipAllowlistEntries","type":"\u0019\n","title":"IP allowlist entries","desc":"One entry per allowed source. Each is a dict with `cidrBlock` (the permitted IP range in CIDR notation), `note` (free-form label), and `createdAt` and `modifiedAt` timestamps.","provider":"go.mondoo.com/mql/providers/datadog"},"logIndex":{"name":"logIndex","type":"\u001bdatadog.logIndex","title":"Datadog Log Index","desc":"Datadog log index that partitions and retains ingested log data. Log indexes control which logs are stored, how long they are kept, and how much is billed, so auditing them surfaces short retention windows, missing daily limits that expose cost overruns, and exclusion filters that silently sample or drop security-relevant logs. Each index is identified by its `name`, and `filter` holds the query that routes logs into it.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"logIndexes":{"name":"logIndexes","type":"\u0019\u001bdatadog.logIndex","title":"Log indexes that organize ingested log data","provider":"go.mondoo.com/mql/providers/datadog"},"logsArchive":{"name":"logsArchive","type":"\u001bdatadog.logsArchive","title":"Datadog Logs Archive","desc":"Datadog logs archive that ships retained logs to long-term cloud storage in Amazon S3, Google Cloud Storage, or Azure Blob Storage. The query filter selects which logs land in the archive, and destinationType (s3, gcs, or azure) determines which keys populate the destination configuration. Useful for auditing where log data is retained, whether archives are healthy, and the rehydration limits applied to them.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"logsArchives":{"name":"logsArchives","type":"\u0019\u001bdatadog.logsArchive","title":"Logs archives that ship logs to long-term storage","provider":"go.mondoo.com/mql/providers/datadog"},"monitor":{"name":"monitor","type":"\u001bdatadog.monitor","title":"Datadog Monitor","desc":"Alerting monitor that watches a metric, log, or service check and fires notifications when a threshold is breached. The `type` field distinguishes what is watched (metric alert, service check, log alert, and so on), and `overallState` reports the live evaluation result (Alert, Warn, No Data, or OK). Auditing monitors surfaces alerting coverage gaps, no-data handling, and how notifications are routed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"monitors":{"name":"monitors","type":"\u0019\u001bdatadog.monitor","title":"Alerting monitors","provider":"go.mondoo.com/mql/providers/datadog"},"role":{"name":"role","type":"\u001bdatadog.role","title":"Datadog Role","desc":"Role-based access control (RBAC) role governing what members can see and do within the organization. Roles bundle permissions and are assigned to users, so auditing them shows how administrative and read/write access is scoped. The `userCount` field reports how many members hold the role, which helps flag over-provisioned or unused roles.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"roles":{"name":"roles","type":"\u0019\u001bdatadog.role","title":"Roles defined for permissioning","provider":"go.mondoo.com/mql/providers/datadog"},"rumApplication":{"name":"rumApplication","type":"\u001bdatadog.rumApplication","title":"Datadog RUM Application","desc":"Real User Monitoring (RUM) application that collects browser or mobile telemetry from end users. The `type` field records the platform (one of browser, ios, android, react-native, flutter, roku, unity, or kotlin-multiplatform), and `clientToken` is the credential embedded in the client SDK to send RUM events, so auditing which applications exist and whether each is active helps confirm that only sanctioned properties emit user telemetry.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"rumApplications":{"name":"rumApplications","type":"\u0019\u001bdatadog.rumApplication","title":"Real User Monitoring (RUM) applications","provider":"go.mondoo.com/mql/providers/datadog"},"securityFilter":{"name":"securityFilter","type":"\u001bdatadog.securityFilter","title":"Datadog Security Monitoring Filter","desc":"Security monitoring filter that excludes matching data from detection rule evaluation, scoping which logs Cloud SIEM analyzes. Query it to audit whether each filter is enabled and what `query` expression it applies, since an overly broad filter can hide activity from detection.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"securityFilters":{"name":"securityFilters","type":"\u0019\u001bdatadog.securityFilter","title":"Security monitoring filters that exclude logs from rule evaluation","provider":"go.mondoo.com/mql/providers/datadog"},"securityRule":{"name":"securityRule","type":"\u001bdatadog.securityRule","title":"Datadog Security Monitoring Rule","desc":"Datadog Cloud SIEM detection rule that identifies threats and policy violations across logs and cloud activity. A rule defines the query conditions that generate security signals, the severity assigned to each match, and the detection method used to evaluate incoming data, so it is the core control governing what a Cloud SIEM deployment detects. Use isEnabled to tell which rules are active, isDefault to separate built-in rules from custom ones, and message for the triage guidance shown on a generated signal.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"securityRules":{"name":"securityRules","type":"\u0019\u001bdatadog.securityRule","title":"Security monitoring rules that detect threats and policy violations","provider":"go.mondoo.com/mql/providers/datadog"},"securitySuppression":{"name":"securitySuppression","type":"\u001bdatadog.securitySuppression","title":"Datadog Security Monitoring Suppression","desc":"Suppression rule that silences matching security signals without affecting log ingestion or the underlying detection rules. Audit these to see which detections are being muted, how broadly, and whether the suppression is still active. The `enabled` flag and `expirationDate` reveal whether a suppression is live or lapsed, while the query fields define its scope.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"securitySuppressions":{"name":"securitySuppressions","type":"\u0019\u001bdatadog.securitySuppression","title":"Security monitoring suppressions that silence specific signals","provider":"go.mondoo.com/mql/providers/datadog"},"sensitiveDataScannerGroup":{"name":"sensitiveDataScannerGroup","type":"\u001bdatadog.sensitiveDataScannerGroup","title":"Datadog Sensitive Data Scanner Group","desc":"Sensitive Data Scanner group that bundles PII detection and redaction rules applied to Datadog log and APM data. Auditing a group confirms whether redaction is active (`isEnabled`), which data sources it covers (`productList`, with values such as logs and apm), and how the `filter` query scopes the subset of data that gets scanned for sensitive values.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"sensitiveDataScannerGroups":{"name":"sensitiveDataScannerGroups","type":"\u0019\u001bdatadog.sensitiveDataScannerGroup","title":"Sensitive Data Scanner groups (PII redaction rule containers)","provider":"go.mondoo.com/mql/providers/datadog"},"serviceAccount":{"name":"serviceAccount","type":"\u001bdatadog.serviceAccount","title":"Datadog Service Account","desc":"Non-human identity used for programmatic API access, separate from any individual user login. Service accounts can own application keys independently of people, so auditing which ones exist, whether they are disabled, and their status surfaces long-lived automation credentials that outlast staff changes. Use handle and email to attribute a service account to its owning team or integration.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"serviceAccounts":{"name":"serviceAccounts","type":"\u0019\u001bdatadog.serviceAccount","title":"Service accounts (non-user identities for API access)","provider":"go.mondoo.com/mql/providers/datadog"},"slo":{"name":"slo","type":"\u001bdatadog.slo","title":"Datadog Service Level Objective","desc":"Service Level Objective that tracks a reliability or performance target for a service over a rolling window, letting you audit which services have SLOs defined and how strict their commitments are. The `type` field distinguishes metric, monitor, and time_slice SLOs; monitor-based SLOs reference their underlying monitors through `monitorIds`. The `targetThreshold` and `warningThreshold` percentages together with `timeframe` capture the reliability budget being promised.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"slos":{"name":"slos","type":"\u0019\u001bdatadog.slo","title":"Service Level Objectives (SLOs)","provider":"go.mondoo.com/mql/providers/datadog"},"syntheticsGlobalVariable":{"name":"syntheticsGlobalVariable","type":"\u001bdatadog.syntheticsGlobalVariable","title":"Datadog Synthetics Global Variable","desc":"Reusable value that can be shared and referenced across multiple Datadog Synthetics tests, letting one definition supply data such as credentials, hostnames, or tokens to many tests. The `isTotp` and `isFido` flags mark variables that carry multi-factor authentication material (Time-based One-Time Password and FIDO), which is worth auditing since those variables hold sensitive secrets. When the value is derived from another test, `parseTestPublicId` identifies that source test.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"syntheticsGlobalVariables":{"name":"syntheticsGlobalVariables","type":"\u0019\u001bdatadog.syntheticsGlobalVariable","title":"Global variables shared across synthetics tests","provider":"go.mondoo.com/mql/providers/datadog"},"syntheticsPrivateLocation":{"name":"syntheticsPrivateLocation","type":"\u001bdatadog.syntheticsPrivateLocation","title":"Datadog Synthetics private location","desc":"A Synthetics private location: a customer-managed worker that runs synthetics tests from inside a private network, so internal endpoints unreachable from Datadog's public infrastructure can still be monitored. Auditing these tells you which internal surfaces are under test and, through `metadata`, which roles are permitted to attach tests to the location.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"syntheticsPrivateLocations":{"name":"syntheticsPrivateLocations","type":"\u0019\u001bdatadog.syntheticsPrivateLocation","title":"Private locations that run synthetics tests inside customer networks","provider":"go.mondoo.com/mql/providers/datadog"},"syntheticsTest":{"name":"syntheticsTest","type":"\u001bdatadog.syntheticsTest","title":"Datadog Synthetics Test","desc":"Datadog Synthetics test that continuously verifies application availability and performance by probing endpoints or driving browser flows from managed or private locations. The `type` distinguishes lightweight `api` checks from full `browser` tests, while `subtype` selects the protocol being probed. Query `status` and `message` to see whether a test is live and how it alerts, and use `monitorId` to pivot to the backing monitor. Auditing tests confirms that critical user journeys and public endpoints are monitored for uptime and regressions.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"syntheticsTests":{"name":"syntheticsTests","type":"\u0019\u001bdatadog.syntheticsTest","title":"Synthetics tests configured in the organization","provider":"go.mondoo.com/mql/providers/datadog"},"team":{"name":"team","type":"\u001bdatadog.team","title":"Datadog Team","desc":"Group of Datadog users organized for ownership, on-call rotation, and access control. Teams tie people to the resources they are responsible for, so auditing them shows who owns what and how membership is scoped. The `handle` is the team's URL slug and `userCount` reports how many members belong to the team.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"teams":{"name":"teams","type":"\u0019\u001bdatadog.team","title":"Datadog teams (groups of users)","provider":"go.mondoo.com/mql/providers/datadog"},"user":{"name":"user","type":"\u001bdatadog.user","title":"Datadog User","desc":"User account belonging to the Datadog organization, covering both human members and service accounts. Use it to audit who has access, spot dormant or unverified accounts, and confirm disabled users have been deactivated. The status field reports Active, Pending, or Disabled, and serviceAccount distinguishes machine identities from people.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001bdatadog.user","title":"Datadog users in the organization","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog","desc":"Organization-wide Datadog configuration and inventory. Covers users, roles, monitors, dashboards, synthetics tests, SLOs, log indexes, security rules, downtimes, API keys, application keys, AWS integrations, teams, sensitive data scanner groups, security filters and suppressions, service accounts, logs archives, RUM applications, and synthetics global variables and private locations. The organization IP allowlist is exposed through ipAllowlistEnabled and ipAllowlistEntries.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.apiKey":{"id":"datadog.apiKey","name":"datadog.apiKey","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"API key ID","provider":"go.mondoo.com/mql/providers/datadog"},"last4":{"name":"last4","type":"\u0007","is_mandatory":true,"title":"Last four characters","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog API Key","desc":"Credential that authorizes Datadog agents and integrations to submit metrics, traces, logs, and events to the organization. The `last4` field exposes only the final four characters so a key can be identified without revealing the secret. The `createdAt` and `modifiedAt` timestamps let you audit key age and flag stale or unrotated credentials.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.applicationKey":{"id":"datadog.applicationKey","name":"datadog.applicationKey","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Application key ID","provider":"go.mondoo.com/mql/providers/datadog"},"last4":{"name":"last4","type":"\u0007","is_mandatory":true,"title":"Last four characters","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/datadog"},"scopes":{"name":"scopes","type":"\u0019\u0007","is_mandatory":true,"title":"Scopes (null means full access)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Application Key","desc":"Application key that a user presents alongside an API key to make authenticated Datadog HTTP API calls. Auditing these surfaces which keys exist, who owns them, and how broad their access is: the `scopes` field is null when the key has full account access, and otherwise lists the specific permission scopes granted to it.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.dashboard":{"id":"datadog.dashboard","name":"datadog.dashboard","fields":{"authorHandle":{"name":"authorHandle","type":"\u0007","is_mandatory":true,"title":"Author handle","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Dashboard description","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Dashboard ID","provider":"go.mondoo.com/mql/providers/datadog"},"isReadOnly":{"name":"isReadOnly","type":"\u0004","is_mandatory":true,"title":"Is read only","provider":"go.mondoo.com/mql/providers/datadog"},"layoutType":{"name":"layoutType","type":"\u0007","is_mandatory":true,"title":"Layout type (ordered, free)","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"title":{"name":"title","type":"\u0007","is_mandatory":true,"title":"Dashboard title","provider":"go.mondoo.com/mql/providers/datadog"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"URL path","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Dashboard","desc":"Visualization dashboard in a Datadog organization, showing metrics, logs, traces, and other telemetry on a shared canvas. The layoutType distinguishes free-form canvases (`free`) from auto-arranged grids (`ordered`). Query these to audit dashboard ownership through the authorHandle, spot dashboards left editable versus locked read-only, and track when dashboards were created or last modified.","min_provider_version":"13.0.1","defaults":"id title","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.downtime":{"id":"datadog.downtime","name":"datadog.downtime","fields":{"canceledAt":{"name":"canceledAt","type":"\t","is_mandatory":true,"title":"Canceled at","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"displayTimezone":{"name":"displayTimezone","type":"\u0007","is_mandatory":true,"title":"Display timezone","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Downtime ID","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"monitorIdentifier":{"name":"monitorIdentifier","type":"\n","is_mandatory":true,"title":"Monitor targeted by the downtime","desc":"One of two shapes: `monitorId` (number) when the downtime targets a single monitor, or `monitorTags` (list of strings) when it targets every monitor matching those tags.","provider":"go.mondoo.com/mql/providers/datadog"},"muteFirstRecoveryNotification":{"name":"muteFirstRecoveryNotification","type":"\u0004","is_mandatory":true,"title":"Mute first recovery notification","provider":"go.mondoo.com/mql/providers/datadog"},"notifyEndStates":{"name":"notifyEndStates","type":"\u0019\u0007","is_mandatory":true,"title":"Monitor states that trigger an end-of-downtime notification","desc":"Each value is one of `alert`, `warn`, or `no data`.","provider":"go.mondoo.com/mql/providers/datadog"},"notifyEndTypes":{"name":"notifyEndTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Downtime end events that trigger a notification","desc":"Each value is one of `canceled` or `expired`.","provider":"go.mondoo.com/mql/providers/datadog"},"schedule":{"name":"schedule","type":"\n","is_mandatory":true,"title":"Downtime schedule window","desc":"Keys: `timezone` (timezone of a recurring schedule), and for a one-time downtime `start` and `end` (RFC 3339 timestamps).","provider":"go.mondoo.com/mql/providers/datadog"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"Scope","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current downtime status","desc":"One of `active`, `scheduled`, `ended`, or `canceled`.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Downtime","desc":"Datadog scheduled downtime that silences monitor alerts during planned maintenance or incidents, so on-call teams are not paged for expected disruption. Query these to audit which monitors are muted, over what scope, and on what schedule. The `status` field distinguishes active, scheduled, ended, and canceled downtimes, and `monitorIdentifier` selects whether the downtime targets a single monitor or a set of monitor tags.","min_provider_version":"13.0.1","defaults":"id status","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration":{"id":"datadog.integration","fields":{"aws":{"name":"aws","type":"\u001bdatadog.integration.aws","title":"Datadog AWS Integration Account","desc":"AWS account linked to Datadog for metrics, resource, and log collection. The roleName is the IAM role Datadog assumes to read from the account, so auditing it exposes the delegation trust that grants Datadog access. The metricsEnabled, resourceCollectionEnabled, and logsEnabled flags show which data streams are active, while includedRegions and filterTags narrow what Datadog ingests.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true}},"is_extension":true},"datadog.integration.aws":{"id":"datadog.integration.aws","name":"datadog.integration.aws","fields":{"accountId":{"name":"accountId","type":"\u0007","is_mandatory":true,"title":"AWS account ID","provider":"go.mondoo.com/mql/providers/datadog"},"accountTags":{"name":"accountTags","type":"\u0019\u0007","is_mandatory":true,"title":"Account tags","provider":"go.mondoo.com/mql/providers/datadog"},"excludedRegions":{"name":"excludedRegions","type":"\u0019\u0007","is_mandatory":true,"title":"Excluded regions","desc":"Always empty. The Datadog v2 AWS integration API expresses region selection as includedRegions (an allowlist) rather than an exclusion list. Retained for backward compatibility with the earlier schema.","provider":"go.mondoo.com/mql/providers/datadog"},"filterTags":{"name":"filterTags","type":"\u0019\u0007","is_mandatory":true,"title":"Filter tags","provider":"go.mondoo.com/mql/providers/datadog"},"hostTags":{"name":"hostTags","type":"\u0019\u0007","is_mandatory":true,"title":"Host tags","provider":"go.mondoo.com/mql/providers/datadog"},"includedRegions":{"name":"includedRegions","type":"\u0019\u0007","is_mandatory":true,"title":"Included regions","desc":"Explicit allowlist of AWS regions Datadog collects data from. Empty when the account is configured to collect from all regions.","min_provider_version":"13.0.17","provider":"go.mondoo.com/mql/providers/datadog"},"logsEnabled":{"name":"logsEnabled","type":"\u0004","is_mandatory":true,"title":"Logs collection enabled","provider":"go.mondoo.com/mql/providers/datadog"},"metricsEnabled":{"name":"metricsEnabled","type":"\u0004","is_mandatory":true,"title":"Metrics collection enabled","provider":"go.mondoo.com/mql/providers/datadog"},"resourceCollectionEnabled":{"name":"resourceCollectionEnabled","type":"\u0004","is_mandatory":true,"title":"Resource collection enabled","provider":"go.mondoo.com/mql/providers/datadog"},"roleName":{"name":"roleName","type":"\u0007","is_mandatory":true,"title":"Role name for Datadog delegation","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog AWS Integration Account","desc":"AWS account linked to Datadog for metrics, resource, and log collection. The roleName is the IAM role Datadog assumes to read from the account, so auditing it exposes the delegation trust that grants Datadog access. The metricsEnabled, resourceCollectionEnabled, and logsEnabled flags show which data streams are active, while includedRegions and filterTags narrow what Datadog ingests.","min_provider_version":"13.0.1","defaults":"accountId","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logIndex":{"id":"datadog.logIndex","name":"datadog.logIndex","fields":{"dailyLimit":{"name":"dailyLimit","type":"\u0005","is_mandatory":true,"title":"Daily limit","provider":"go.mondoo.com/mql/providers/datadog"},"dailyLimitWarningThresholdPercentage":{"name":"dailyLimitWarningThresholdPercentage","type":"\u0006","is_mandatory":true,"title":"Daily-limit warning threshold as a percentage (0-100)","provider":"go.mondoo.com/mql/providers/datadog"},"exclusionFilters":{"name":"exclusionFilters","type":"\u0019\n","is_mandatory":true,"title":"Exclusion filters that sample or drop matching logs","desc":"Each entry has `name` (the exclusion filter name), `isEnabled` (whether the filter is active), `query` (the log query selecting which logs to exclude), and `sampleRate` (fraction of matching logs retained, where 0.0 drops all matches and 1.0 keeps them all).","provider":"go.mondoo.com/mql/providers/datadog"},"filter":{"name":"filter","type":"\u0007","is_mandatory":true,"title":"Log filter query","provider":"go.mondoo.com/mql/providers/datadog"},"isRateLimited":{"name":"isRateLimited","type":"\u0004","is_mandatory":true,"title":"Is rate limited","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Index name","provider":"go.mondoo.com/mql/providers/datadog"},"numFlexLogsRetentionDays":{"name":"numFlexLogsRetentionDays","type":"\u0005","is_mandatory":true,"title":"Number of flex logs retention days","provider":"go.mondoo.com/mql/providers/datadog"},"numRetentionDays":{"name":"numRetentionDays","type":"\u0005","is_mandatory":true,"title":"Number of days to retain","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Log Index","desc":"Datadog log index that partitions and retains ingested log data. Log indexes control which logs are stored, how long they are kept, and how much is billed, so auditing them surfaces short retention windows, missing daily limits that expose cost overruns, and exclusion filters that silently sample or drop security-relevant logs. Each index is identified by its `name`, and `filter` holds the query that routes logs into it.","min_provider_version":"13.0.1","defaults":"name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logsArchive":{"id":"datadog.logsArchive","name":"datadog.logsArchive","fields":{"destination":{"name":"destination","type":"\n","is_mandatory":true,"title":"Cloud storage destination configuration","desc":"Keys vary by destinationType. For s3 and gcs: bucket and path. For azure: container, storageAccount, and path.","provider":"go.mondoo.com/mql/providers/datadog"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type (s3, gcs, azure)","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Archive ID","provider":"go.mondoo.com/mql/providers/datadog"},"includeTags":{"name":"includeTags","type":"\u0004","is_mandatory":true,"title":"Whether tags from the original logs are preserved in the archive","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Archive name","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Query filter","provider":"go.mondoo.com/mql/providers/datadog"},"rehydrationMaxScanSizeInGb":{"name":"rehydrationMaxScanSizeInGb","type":"\u0005","is_mandatory":true,"title":"Rehydration max scan size in GB","provider":"go.mondoo.com/mql/providers/datadog"},"rehydrationTags":{"name":"rehydrationTags","type":"\u0019\u0007","is_mandatory":true,"title":"Rehydration tags","provider":"go.mondoo.com/mql/providers/datadog"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"State (UNKNOWN, WORKING, FAILING, WORKING_AUTH_LEGACY)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Logs Archive","desc":"Datadog logs archive that ships retained logs to long-term cloud storage in Amazon S3, Google Cloud Storage, or Azure Blob Storage. The query filter selects which logs land in the archive, and destinationType (s3, gcs, or azure) determines which keys populate the destination configuration. Useful for auditing where log data is retained, whether archives are healthy, and the rehydration limits applied to them.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.monitor":{"id":"datadog.monitor","name":"datadog.monitor","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"creator":{"name":"creator","type":"\u0007","is_mandatory":true,"title":"Creator email","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Monitor ID","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message (notification text)","provider":"go.mondoo.com/mql/providers/datadog"},"modified":{"name":"modified","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Monitor name","provider":"go.mondoo.com/mql/providers/datadog"},"notifyNoData":{"name":"notifyNoData","type":"\u0004","is_mandatory":true,"title":"Whether the monitor notifies when data is missing","provider":"go.mondoo.com/mql/providers/datadog"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Alert behavior options","desc":"Keys: `renotifyInterval` (minutes between re-notifications while the monitor stays in alert), `timeoutH` (hours before a triggered alert auto-resolves), `evaluationDelay` (seconds the evaluation is held back to allow late-arriving data), and `notifyAudit` (bool, whether changes to the monitor are announced to its notification targets).","provider":"go.mondoo.com/mql/providers/datadog"},"overallState":{"name":"overallState","type":"\u0007","is_mandatory":true,"title":"Overall state (Alert, Warn, No Data, OK)","provider":"go.mondoo.com/mql/providers/datadog"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority (1-5, or null)","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Monitor query","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Monitor type (metric alert, service check, log alert, etc.)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Monitor","desc":"Alerting monitor that watches a metric, log, or service check and fires notifications when a threshold is breached. The `type` field distinguishes what is watched (metric alert, service check, log alert, and so on), and `overallState` reports the live evaluation result (Alert, Warn, No Data, or OK). Auditing monitors surfaces alerting coverage gaps, no-data handling, and how notifications are routed.","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.role":{"id":"datadog.role","name":"datadog.role","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Role ID","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Role name","provider":"go.mondoo.com/mql/providers/datadog"},"userCount":{"name":"userCount","type":"\u0005","is_mandatory":true,"title":"User count","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Role","desc":"Role-based access control (RBAC) role governing what members can see and do within the organization. Roles bundle permissions and are assigned to users, so auditing them shows how administrative and read/write access is scoped. The `userCount` field reports how many members hold the role, which helps flag over-provisioned or unused roles.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.rumApplication":{"id":"datadog.rumApplication","name":"datadog.rumApplication","fields":{"clientToken":{"name":"clientToken","type":"\u0007","is_mandatory":true,"title":"Client token","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Application ID","provider":"go.mondoo.com/mql/providers/datadog"},"isActive":{"name":"isActive","type":"\u0004","is_mandatory":true,"title":"Is active","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Application name","provider":"go.mondoo.com/mql/providers/datadog"},"orgId":{"name":"orgId","type":"\u0007","is_mandatory":true,"title":"Organization ID","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Application type (browser, ios, android, react-native, flutter, roku, unity, kotlin-multiplatform)","provider":"go.mondoo.com/mql/providers/datadog"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog RUM Application","desc":"Real User Monitoring (RUM) application that collects browser or mobile telemetry from end users. The `type` field records the platform (one of browser, ios, android, react-native, flutter, roku, unity, or kotlin-multiplatform), and `clientToken` is the credential embedded in the client SDK to send RUM events, so auditing which applications exist and whether each is active helps confirm that only sanctioned properties emit user telemetry.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.securityFilter":{"id":"datadog.securityFilter","name":"datadog.securityFilter","fields":{"filteredDataType":{"name":"filteredDataType","type":"\u0007","is_mandatory":true,"title":"Category of data the filter applies to","desc":"Currently only `logs`.","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Filter ID","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the filter is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Filter name","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Filter query","provider":"go.mondoo.com/mql/providers/datadog"},"version":{"name":"version","type":"\u0005","is_mandatory":true,"title":"Version","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Security Monitoring Filter","desc":"Security monitoring filter that excludes matching data from detection rule evaluation, scoping which logs Cloud SIEM analyzes. Query it to audit whether each filter is enabled and what `query` expression it applies, since an overly broad filter can hide activity from detection.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.securityRule":{"id":"datadog.securityRule","name":"datadog.securityRule","fields":{"cases":{"name":"cases","type":"\u0019\n","is_mandatory":true,"title":"Signal cases","desc":"Each case is a dict with `name` (case label), `status` (the severity assigned when the case matches: info, low, medium, high, or critical), and `condition` (the boolean expression over the rule's queries that triggers this case).","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"filters":{"name":"filters","type":"\u0019\n","is_mandatory":true,"title":"Rule filters","desc":"Each filter is a dict with `query` (the log or event query the filter matches) and `action`, one of require (only evaluate events matching the query) or suppress (exclude matching events from detection).","provider":"go.mondoo.com/mql/providers/datadog"},"hasExtendedTitle":{"name":"hasExtendedTitle","type":"\u0004","is_mandatory":true,"title":"Has extended title","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Rule ID","provider":"go.mondoo.com/mql/providers/datadog"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Is default (built-in)","provider":"go.mondoo.com/mql/providers/datadog"},"isDeleted":{"name":"isDeleted","type":"\u0004","is_mandatory":true,"title":"Is deleted","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/mql/providers/datadog"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Detection options","desc":"Rule-specific evaluation parameters. Keys: `detectionMethod` (one of threshold, new_value, anomaly_detection, impossible_travel, hardcoded, third_party, anomaly_threshold, or sequence_detection), `evaluationWindow` (seconds of data evaluated per query), `keepAlive` (seconds a signal stays open on repeated matches), and `maxSignalDuration` (seconds before a signal is force-closed).","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule type","desc":"One of log_detection, infrastructure_configuration, workload_security, cloud_configuration, application_security, api_security, or workload_activity.","provider":"go.mondoo.com/mql/providers/datadog"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Security Monitoring Rule","desc":"Datadog Cloud SIEM detection rule that identifies threats and policy violations across logs and cloud activity. A rule defines the query conditions that generate security signals, the severity assigned to each match, and the detection method used to evaluate incoming data, so it is the core control governing what a Cloud SIEM deployment detects. Use isEnabled to tell which rules are active, isDefault to separate built-in rules from custom ones, and message for the triage guidance shown on a generated signal.","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.securitySuppression":{"id":"datadog.securitySuppression","name":"datadog.securitySuppression","fields":{"dataExclusionQuery":{"name":"dataExclusionQuery","type":"\u0007","is_mandatory":true,"title":"Data exclusion query","desc":"Query that excludes matching events from the detection pipeline entirely, so no signal is generated for them in the first place.","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the suppression is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"expirationDate":{"name":"expirationDate","type":"\t","is_mandatory":true,"title":"Expiration date","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Suppression ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Suppression name","provider":"go.mondoo.com/mql/providers/datadog"},"ruleQuery":{"name":"ruleQuery","type":"\u0007","is_mandatory":true,"title":"Rule query","desc":"Query that selects which detection rules the suppression applies to. Signals from rules matching this query are candidates for suppression.","provider":"go.mondoo.com/mql/providers/datadog"},"suppressionQuery":{"name":"suppressionQuery","type":"\u0007","is_mandatory":true,"title":"Suppression query","desc":"Query evaluated against a signal's attributes. Signals from the selected rules that also match this query are suppressed, so a broad query silences more signals.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Security Monitoring Suppression","desc":"Suppression rule that silences matching security signals without affecting log ingestion or the underlying detection rules. Audit these to see which detections are being muted, how broadly, and whether the suppression is still active. The `enabled` flag and `expirationDate` reveal whether a suppression is live or lapsed, while the query fields define its scope.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.sensitiveDataScannerGroup":{"id":"datadog.sensitiveDataScannerGroup","name":"datadog.sensitiveDataScannerGroup","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"filter":{"name":"filter","type":"\u0007","is_mandatory":true,"title":"Filter query","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Group ID","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the group is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/mql/providers/datadog"},"productList":{"name":"productList","type":"\u0019\u0007","is_mandatory":true,"title":"Product list (logs, apm)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Sensitive Data Scanner Group","desc":"Sensitive Data Scanner group that bundles PII detection and redaction rules applied to Datadog log and APM data. Auditing a group confirms whether redaction is active (`isEnabled`), which data sources it covers (`productList`, with values such as logs and apm), and how the `filter` query scopes the subset of data that gets scanned for sensitive values.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.serviceAccount":{"id":"datadog.serviceAccount","name":"datadog.serviceAccount","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Disabled","provider":"go.mondoo.com/mql/providers/datadog"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email","provider":"go.mondoo.com/mql/providers/datadog"},"handle":{"name":"handle","type":"\u0007","is_mandatory":true,"title":"Handle","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Service account ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Service Account","desc":"Non-human identity used for programmatic API access, separate from any individual user login. Service accounts can own application keys independently of people, so auditing which ones exist, whether they are disabled, and their status surfaces long-lived automation credentials that outlast staff changes. Use handle and email to attribute a service account to its owning team or integration.","min_provider_version":"13.0.1","defaults":"id email","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.slo":{"id":"datadog.slo","name":"datadog.slo","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"creator":{"name":"creator","type":"\u0007","is_mandatory":true,"title":"Creator email","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"SLO ID","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"monitorIds":{"name":"monitorIds","type":"\u0019\u0005","is_mandatory":true,"title":"Monitor IDs (for monitor-based SLOs)","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"SLO name","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"targetThreshold":{"name":"targetThreshold","type":"\u0006","is_mandatory":true,"title":"Target threshold (percentage, e.g., 99.9)","provider":"go.mondoo.com/mql/providers/datadog"},"timeframe":{"name":"timeframe","type":"\u0007","is_mandatory":true,"title":"Timeframe (7d, 30d, 90d)","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"SLO type (metric, monitor, time_slice)","provider":"go.mondoo.com/mql/providers/datadog"},"warningThreshold":{"name":"warningThreshold","type":"\u0006","is_mandatory":true,"title":"Warning threshold (percentage)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Service Level Objective","desc":"Service Level Objective that tracks a reliability or performance target for a service over a rolling window, letting you audit which services have SLOs defined and how strict their commitments are. The `type` field distinguishes metric, monitor, and time_slice SLOs; monitor-based SLOs reference their underlying monitors through `monitorIds`. The `targetThreshold` and `warningThreshold` percentages together with `timeframe` capture the reliability budget being promised.","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.syntheticsGlobalVariable":{"id":"datadog.syntheticsGlobalVariable","name":"datadog.syntheticsGlobalVariable","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Variable ID","provider":"go.mondoo.com/mql/providers/datadog"},"isFido":{"name":"isFido","type":"\u0004","is_mandatory":true,"title":"Whether the variable is a FIDO variable","provider":"go.mondoo.com/mql/providers/datadog"},"isTotp":{"name":"isTotp","type":"\u0004","is_mandatory":true,"title":"Whether the variable is a Time-based One-Time Password (TOTP/MFA) variable","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Variable name","provider":"go.mondoo.com/mql/providers/datadog"},"parseTestPublicId":{"name":"parseTestPublicId","type":"\u0007","is_mandatory":true,"title":"Parse test public ID (source test)","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Synthetics Global Variable","desc":"Reusable value that can be shared and referenced across multiple Datadog Synthetics tests, letting one definition supply data such as credentials, hostnames, or tokens to many tests. The `isTotp` and `isFido` flags mark variables that carry multi-factor authentication material (Time-based One-Time Password and FIDO), which is worth auditing since those variables hold sensitive secrets. When the value is derived from another test, `parseTestPublicId` identifies that source test.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.syntheticsPrivateLocation":{"id":"datadog.syntheticsPrivateLocation","name":"datadog.syntheticsPrivateLocation","fields":{"description":{"name":"description","type":"\u0007","title":"Description of the private location","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Location ID","provider":"go.mondoo.com/mql/providers/datadog"},"metadata":{"name":"metadata","type":"\n","title":"Private-location metadata","desc":"Dict with a single `restrictedRoles` key: the list of role IDs allowed to use this private location. Empty when the location is not restricted to specific roles.","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Location name","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","title":"Tags applied to the private location","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Synthetics private location","desc":"A Synthetics private location: a customer-managed worker that runs synthetics tests from inside a private network, so internal endpoints unreachable from Datadog's public infrastructure can still be monitored. Auditing these tells you which internal surfaces are under test and, through `metadata`, which roles are permitted to attach tests to the location.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.syntheticsTest":{"id":"datadog.syntheticsTest","name":"datadog.syntheticsTest","fields":{"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Request configuration","desc":"Request under test. Keys: `method` (HTTP method, for example GET or POST) and `url` (the endpoint the test probes).","provider":"go.mondoo.com/mql/providers/datadog"},"creator":{"name":"creator","type":"\u0007","is_mandatory":true,"title":"Creator email","provider":"go.mondoo.com/mql/providers/datadog"},"locations":{"name":"locations","type":"\u0019\u0007","is_mandatory":true,"title":"Locations","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message (notification text)","provider":"go.mondoo.com/mql/providers/datadog"},"monitorId":{"name":"monitorId","type":"\u0005","is_mandatory":true,"title":"Monitor ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Test name","provider":"go.mondoo.com/mql/providers/datadog"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Execution options","desc":"Scheduling and failure-handling settings. Keys: `tickEvery` (run interval in seconds), `followRedirects` (whether HTTP redirects are followed), and `minFailureDuration` (seconds a failure must persist before the test is marked failing).","provider":"go.mondoo.com/mql/providers/datadog"},"publicId":{"name":"publicId","type":"\u0007","is_mandatory":true,"title":"Public ID","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (live, paused)","provider":"go.mondoo.com/mql/providers/datadog"},"subtype":{"name":"subtype","type":"\u0007","is_mandatory":true,"title":"Subtype (http, ssl, dns, websocket, tcp, udp, icmp, grpc, multi)","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Test type (api, browser)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Synthetics Test","desc":"Datadog Synthetics test that continuously verifies application availability and performance by probing endpoints or driving browser flows from managed or private locations. The `type` distinguishes lightweight `api` checks from full `browser` tests, while `subtype` selects the protocol being probed. Query `status` and `message` to see whether a test is live and how it alerts, and use `monitorId` to pivot to the backing monitor. Auditing tests confirms that critical user journeys and public endpoints are monitored for uptime and regressions.","min_provider_version":"13.0.1","defaults":"publicId name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.team":{"id":"datadog.team","name":"datadog.team","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"handle":{"name":"handle","type":"\u0007","is_mandatory":true,"title":"Team handle (slug)","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Team ID","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Team name","provider":"go.mondoo.com/mql/providers/datadog"},"userCount":{"name":"userCount","type":"\u0005","is_mandatory":true,"title":"User count","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Team","desc":"Group of Datadog users organized for ownership, on-call rotation, and access control. Teams tie people to the resources they are responsible for, so auditing them shows who owns what and how membership is scoped. The `handle` is the team's URL slug and `userCount` reports how many members belong to the team.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.user":{"id":"datadog.user","name":"datadog.user","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Disabled","provider":"go.mondoo.com/mql/providers/datadog"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address","provider":"go.mondoo.com/mql/providers/datadog"},"handle":{"name":"handle","type":"\u0007","is_mandatory":true,"title":"Handle (username)","provider":"go.mondoo.com/mql/providers/datadog"},"icon":{"name":"icon","type":"\u0007","is_mandatory":true,"title":"Icon URL","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"User ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"User name","provider":"go.mondoo.com/mql/providers/datadog"},"serviceAccount":{"name":"serviceAccount","type":"\u0004","is_mandatory":true,"title":"Is service account","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (Active, Pending, Disabled)","provider":"go.mondoo.com/mql/providers/datadog"},"title":{"name":"title","type":"\u0007","is_mandatory":true,"title":"Title","provider":"go.mondoo.com/mql/providers/datadog"},"verified":{"name":"verified","type":"\u0004","is_mandatory":true,"title":"Verified","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog User","desc":"User account belonging to the Datadog organization, covering both human members and service accounts. Use it to audit who has access, spot dormant or unverified accounts, and confirm disabled users have been deactivated. The status field reports Active, Pending, or Disabled, and serviceAccount distinguishes machine identities from people.","min_provider_version":"13.0.1","defaults":"id email status","provider":"go.mondoo.com/mql/providers/datadog"}}}