{"resources":{"datadog":{"id":"datadog","name":"datadog","fields":{"apiKey":{"name":"apiKey","type":"\u001bdatadog.apiKey","title":"Datadog API Key","desc":"Credential that authorizes Datadog agents and integrations to submit metrics, traces, logs, and events to the organization. The `last4` field exposes only the final four characters so a key can be identified without revealing the secret. The `createdAt` and `modifiedAt` timestamps let you audit key age and flag stale or unrotated credentials, and `lastUsedAt` separates keys that are still submitting data from abandoned ones that should be revoked. The `createdBy` and `modifiedBy` fields attribute a key to the accounts that issued and last changed it.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"apiKeys":{"name":"apiKeys","type":"\u0019\u001bdatadog.apiKey","title":"API keys that allow agents and integrations to send data to Datadog","provider":"go.mondoo.com/mql/providers/datadog"},"applicationKey":{"name":"applicationKey","type":"\u001bdatadog.applicationKey","title":"Datadog Application Key","desc":"Application key that a user presents alongside an API key to make authenticated Datadog HTTP API calls. Auditing these surfaces which keys exist, who owns them, and how broad their access is: the `scopes` field is empty when the key has full account access, and otherwise lists the specific permission scopes granted to it. A key with no scopes inherits every permission its `owner` holds, so pairing the two shows the effective reach of the credential, and `lastUsedAt` separates live keys from dormant ones.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"applicationKeys":{"name":"applicationKeys","type":"\u0019\u001bdatadog.applicationKey","title":"Application keys used by users for HTTP API calls","provider":"go.mondoo.com/mql/providers/datadog"},"asset":{"name":"asset","type":"\u001basset","title":"Asset this root belongs to","desc":"Platform, version, identity and labels of the asset this root describes.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"authnMapping":{"name":"authnMapping","type":"\u001bdatadog.authnMapping","title":"Datadog Identity Provider Attribute Mapping","desc":"Rule granting a role or team to everyone whose identity provider assertion carries a given attribute, so it is where privilege is actually decided for a single sign-on organization. A mapping matches when the assertion contains `attributeKey` with the value `attributeValue`, and grants the `role` or `team` it points at. Auditing these shows which external directory groups confer administrative access, which is invisible from the role assignments alone because the grants are applied at login.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"authnMappings":{"name":"authnMappings","type":"\u0019\u001bdatadog.authnMapping","title":"Mappings from identity provider attributes to roles and teams","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"dashboard":{"name":"dashboard","type":"\u001bdatadog.dashboard","title":"Datadog Dashboard","desc":"Visualization dashboard in a Datadog organization, showing metrics, logs, traces, and other telemetry on a shared canvas. The layoutType distinguishes free-form canvases (`free`) from auto-arranged grids (`ordered`). Query these to audit dashboard ownership through the authorHandle, spot dashboards left editable versus locked read-only, and track when dashboards were created or last modified.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"dashboards":{"name":"dashboards","type":"\u0019\u001bdatadog.dashboard","title":"Dashboards in the organization","provider":"go.mondoo.com/mql/providers/datadog"},"downtime":{"name":"downtime","type":"\u001bdatadog.downtime","title":"Datadog Downtime","desc":"Datadog scheduled downtime that silences monitor alerts during planned maintenance or incidents, so on-call teams are not paged for expected disruption. Query these to audit which monitors are muted, over what scope, and on what schedule. The `status` field distinguishes active, scheduled, ended, and canceled downtimes, and `monitorIdentifier` selects whether the downtime targets a single monitor or a set of monitor tags.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"downtimes":{"name":"downtimes","type":"\u0019\u001bdatadog.downtime","title":"Downtimes (scheduled)","provider":"go.mondoo.com/mql/providers/datadog"},"executionPolicies":{"name":"executionPolicies","type":"\u0019\u001bdatadog.executionPolicy","title":"Execution policies governing what Datadog may run on Agent hosts","min_provider_version":"13.0.23","provider":"go.mondoo.com/mql/providers/datadog"},"executionPolicy":{"name":"executionPolicy","type":"\u001bdatadog.executionPolicy","title":"Datadog Execution Policy","desc":"Rule governing whether Datadog may run a given action on the hosts an Agent tag selects. Each policy pairs an effect, allow or deny, with an action pattern naming the integration and the fully qualified actions it covers, and with the targets the policy applies to. A policy whose effect is allow and whose integration is INTEGRATION_REMOTE_ACTION grants remote shell access to every host its targets reach, which makes those policies the ones worth reading first. The scope narrows where the policy applies, naming Kubernetes namespaces, script names, or remote shell paths together with the access granted on them, and a scopeType of none means the policy carries no restriction at all. The version, createdBy and updatedBy fields record who last changed the policy and how many times it has been changed. The `id` selects a policy, for example datadog.executionPolicies.where(id == \"1c9e5b46-0000-0000-0000-000000000000\").","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"identityProvider":{"name":"identityProvider","type":"\u001bdatadog.identityProvider","title":"Identity provider members can authenticate through","desc":"A login method configured for the organization, reported one row per provider with `authenticationMethod` naming the mechanism and `enabled` recording whether members can currently use it. This is the view that shows what remains available alongside single sign-on, so an organization that has rolled out SAML but left another method enabled is visible here rather than in the SAML settings on the org resource.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"identityProviders":{"name":"identityProviders","type":"\u0019\u001bdatadog.identityProvider","title":"Identity providers users can authenticate through","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"integration":{"name":"integration","type":"\u001bdatadog.integration","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"integrationAwsAccounts":{"name":"integrationAwsAccounts","type":"\u0019\u001bdatadog.integration.aws","title":"Configured AWS integrations (Datadog AWS account links)","provider":"go.mondoo.com/mql/providers/datadog"},"integrationAzureAccounts":{"name":"integrationAzureAccounts","type":"\u0019\u001bdatadog.integration.azure","title":"Configured Azure integrations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"integrationCloudflareAccounts":{"name":"integrationCloudflareAccounts","type":"\u0019\u001bdatadog.integration.cloudflare","title":"Configured Cloudflare integrations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"integrationConfluentAccounts":{"name":"integrationConfluentAccounts","type":"\u0019\u001bdatadog.integration.confluent","title":"Configured Confluent Cloud integrations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"integrationFastlyAccounts":{"name":"integrationFastlyAccounts","type":"\u0019\u001bdatadog.integration.fastly","title":"Configured Fastly integrations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"integrationGcpAccounts":{"name":"integrationGcpAccounts","type":"\u0019\u001bdatadog.integration.gcp","title":"Configured Google Cloud integrations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"integrationOktaAccounts":{"name":"integrationOktaAccounts","type":"\u0019\u001bdatadog.integration.okta","title":"Configured Okta integrations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"ipAllowlistEnabled":{"name":"ipAllowlistEnabled","type":"\u0004","title":"Whether the IP allowlist is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"ipAllowlistEntries":{"name":"ipAllowlistEntries","type":"\u0019\n","title":"IP allowlist entries","desc":"One entry per allowed source. Each is a dict with `cidrBlock` (the permitted IP range in CIDR notation), `note` (free-form label), and `createdAt` and `modifiedAt` timestamps.","provider":"go.mondoo.com/mql/providers/datadog"},"logIndex":{"name":"logIndex","type":"\u001bdatadog.logIndex","title":"Datadog Log Index","desc":"Datadog log index that partitions and retains ingested log data. Log indexes control which logs are stored, how long they are kept, and how much is billed, so auditing them surfaces short retention windows, missing daily limits that expose cost overruns, and exclusion filters that silently sample or drop security-relevant logs. Each index is identified by its `name`, and `filter` holds the query that routes logs into it.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"logIndexes":{"name":"logIndexes","type":"\u0019\u001bdatadog.logIndex","title":"Log indexes that organize ingested log data","provider":"go.mondoo.com/mql/providers/datadog"},"logsArchive":{"name":"logsArchive","type":"\u001bdatadog.logsArchive","title":"Datadog Logs Archive","desc":"Datadog logs archive that ships retained logs to long-term cloud storage in Amazon S3, Google Cloud Storage, or Azure Blob Storage. The query filter selects which logs land in the archive, and destinationType (s3, gcs, or azure) determines which keys populate the destination configuration. Useful for auditing where log data is retained, whether archives are healthy, and the rehydration limits applied to them.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"logsArchives":{"name":"logsArchives","type":"\u0019\u001bdatadog.logsArchive","title":"Logs archives that ship logs to long-term storage","provider":"go.mondoo.com/mql/providers/datadog"},"logsCustomDestination":{"name":"logsCustomDestination","type":"\u001bdatadog.logsCustomDestination","title":"Datadog Log Forwarding Destination","desc":"External system that Datadog copies matching log events to, so it is an egress path for whatever the `query` selects. Auditing these shows where log data leaves Datadog and how the connection is authenticated: the `destinationType` names the receiving system, `endpoint` is the address it is sent to, and `enabled` reports whether forwarding is live. The `forwardTags` flag together with `forwardTagsRestrictionList` controls whether host and service tags travel with the events.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"logsCustomDestinations":{"name":"logsCustomDestinations","type":"\u0019\u001bdatadog.logsCustomDestination","title":"Destinations logs are forwarded to outside Datadog","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"logsPipeline":{"name":"logsPipeline","type":"\u001bdatadog.logsPipeline","title":"Datadog Log Processing Pipeline","desc":"Pipeline that parses, enriches and rewrites log events as they are ingested, ahead of indexing. Pipelines are where log content is reshaped, so auditing them shows which log sources are processed at all and whether the processing that redacts or remaps sensitive fields is switched on. The `filterQuery` selects which events enter the pipeline, `isEnabled` reports whether it runs, and `isReadOnly` distinguishes the integration pipelines Datadog ships from those the organization authored.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"logsPipelines":{"name":"logsPipelines","type":"\u0019\u001bdatadog.logsPipeline","title":"Log processing pipelines","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"logsRestrictionQueries":{"name":"logsRestrictionQueries","type":"\u0019\u001bdatadog.logsRestrictionQuery","title":"Queries that restrict which logs a role can read","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"logsRestrictionQuery":{"name":"logsRestrictionQuery","type":"\u001bdatadog.logsRestrictionQuery","title":"Datadog Log Restriction Query","desc":"Query limiting which log events the roles it is attached to may read, so it is the mechanism that keeps one team from reading another team's logs. A role with no restriction query reads every log its permissions allow; a role with one reads only events matching `restrictionQuery`. The `roleCount` and `userCount` fields report how far the restriction reaches, and `roles` resolves the roles it is bound to.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"monitor":{"name":"monitor","type":"\u001bdatadog.monitor","title":"Datadog Monitor","desc":"Alerting monitor that watches a metric, log, or service check and fires notifications when a threshold is breached. The `type` field distinguishes what is watched (metric alert, service check, log alert, and so on), and `overallState` reports the live evaluation result (Alert, Warn, No Data, or OK). Auditing monitors surfaces alerting coverage gaps, no-data handling, and how notifications are routed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"monitors":{"name":"monitors","type":"\u0019\u001bdatadog.monitor","title":"Alerting monitors","provider":"go.mondoo.com/mql/providers/datadog"},"oauthClient":{"name":"oauthClient","type":"\u001bdatadog.oauthClient","title":"Third-party OAuth client authorized against the organization","desc":"An OAuth2 application that members of the organization have granted standing access to Datadog data. Each client is listed once for the whole organization, with `userCount` reporting how many people have authorized it and `lastExercised` when its access was most recently used. `disabled` records an organization-wide revocation, which blocks the client for everyone regardless of individual consent. The authorizations hold the per-person grants, including the scopes each member handed over, so a client with a large `userCount` and broad scopes is worth reviewing even when nobody remembers approving it. Clients that stop appearing in `lastExercised` for long periods are candidates for revocation.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"oauthClients":{"name":"oauthClients","type":"\u0019\u001bdatadog.oauthClient","title":"Third-party OAuth clients the organization has authorized","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"org":{"name":"org","type":"\u001bdatadog.organization","title":"Organization the credentials authenticate against","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"orgConnection":{"name":"orgConnection","type":"\u001bdatadog.orgConnection","title":"Connection sharing data with another Datadog organization","desc":"A link between this organization and another one, letting telemetry cross an organizational boundary. `sourceOrgId` and `sourceOrgName` name the organization data flows out of, `sinkOrgId` and `sinkOrgName` the one it flows into, so comparing them against the organization publicId shows which direction a given connection runs. `connectionTypes` lists the kinds of data covered by the link, and createdBy identifies who established it.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"orgConnections":{"name":"orgConnections","type":"\u0019\u001bdatadog.orgConnection","title":"Connections that share data with other Datadog organizations","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"organization":{"name":"organization","type":"\u001bdatadog.organization","title":"Datadog Organization","desc":"Datadog organization the supplied credentials authenticate against, and the account-wide settings that govern how people reach it. The single sign-on fields describe whether SAML is configured and how strictly it is enforced: samlEnabled reports whether SAML login is turned on, samlStrictModeEnabled reports whether username and password login is refused once SAML is active, and samlIdpInitiatedLoginEnabled reports whether the identity provider may start a session on its own. The samlAutocreateUsersEnabled and samlAutocreateUsersDomains fields expose which email domains are granted an account automatically on first login, and samlAutocreateAccessRole is the role those accounts receive. Beyond SAML, privateWidgetShare reports whether individual dashboard widgets can be shared outside the organization, and domainAllowlistEnabled together with domainAllowlistDomains restrict which email domains may be invited at all.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"permission":{"name":"permission","type":"\u001bdatadog.permission","title":"Datadog Permission","desc":"Individual capability that a role can grant, such as reading dashboards or managing API keys. Permissions are the leaves of the role-based access control model, so listing the permissions attached to a role shows exactly what its members can do rather than what the role is called. The name field is the stable identifier used in policy (for example org_management or logs_read_data), while displayName and groupName carry the wording shown in the Datadog roles interface. The restricted field marks permissions that cannot be granted through the API and are reserved to built-in roles.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"permissions":{"name":"permissions","type":"\u0019\u001bdatadog.permission","title":"Permissions that can be granted to a role","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"restrictionPolicy":{"name":"restrictionPolicy","type":"\u001bdatadog.restrictionPolicy","title":"Datadog Restriction Policy","desc":"Access control list attached to one Datadog resource, overriding the organization-wide role permissions for that resource alone. A dashboard or monitor with no restriction policy is governed purely by role permissions; one with a policy is reachable only by the principals the policy names. The `id` is the Datadog resource identifier the policy protects, in the form type:identifier, for example dashboard:abc-def-ghi or monitor:12345. The bindings hold the grants themselves, so an empty bindings list means the policy exists but grants nothing beyond the resource owner.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"role":{"name":"role","type":"\u001bdatadog.role","title":"Datadog Role","desc":"Role-based access control (RBAC) role governing what members can see and do within the organization. Roles bundle permissions and are assigned to users, so auditing them shows how administrative and read/write access is scoped. The `userCount` field reports how many members hold the role, which helps flag over-provisioned or unused roles. The permissions field expands the role into the individual capabilities it grants, and users lists the members who hold it, so the two together answer who can perform a given action.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"roles":{"name":"roles","type":"\u0019\u001bdatadog.role","title":"Roles defined for permissioning","provider":"go.mondoo.com/mql/providers/datadog"},"rumApplication":{"name":"rumApplication","type":"\u001bdatadog.rumApplication","title":"Datadog RUM Application","desc":"Real User Monitoring (RUM) application that collects browser or mobile telemetry from end users. The `type` field records the platform (one of browser, ios, android, react-native, flutter, roku, unity, or kotlin-multiplatform), and `clientToken` is the credential embedded in the client SDK to send RUM events, so auditing which applications exist and whether each is active helps confirm that only sanctioned properties emit user telemetry.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"rumApplications":{"name":"rumApplications","type":"\u0019\u001bdatadog.rumApplication","title":"Real User Monitoring (RUM) applications","provider":"go.mondoo.com/mql/providers/datadog"},"securityFilter":{"name":"securityFilter","type":"\u001bdatadog.securityFilter","title":"Datadog Security Monitoring Filter","desc":"Security monitoring filter that excludes matching data from detection rule evaluation, scoping which logs Cloud SIEM analyzes. Query it to audit whether each filter is enabled and what `query` expression it applies, since an overly broad filter can hide activity from detection.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"securityFilters":{"name":"securityFilters","type":"\u0019\u001bdatadog.securityFilter","title":"Security monitoring filters that exclude logs from rule evaluation","provider":"go.mondoo.com/mql/providers/datadog"},"securityRule":{"name":"securityRule","type":"\u001bdatadog.securityRule","title":"Datadog Security Monitoring Rule","desc":"Datadog Cloud SIEM detection rule that identifies threats and policy violations across logs and cloud activity. A rule defines the query conditions that generate security signals, the severity assigned to each match, and the detection method used to evaluate incoming data, so it is the core control governing what a Cloud SIEM deployment detects. Use isEnabled to tell which rules are active, isDefault to separate built-in rules from custom ones, and message for the triage guidance shown on a generated signal.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"securityRules":{"name":"securityRules","type":"\u0019\u001bdatadog.securityRule","title":"Security monitoring rules that detect threats and policy violations","provider":"go.mondoo.com/mql/providers/datadog"},"securitySuppression":{"name":"securitySuppression","type":"\u001bdatadog.securitySuppression","title":"Datadog Security Monitoring Suppression","desc":"Suppression rule that silences matching security signals without affecting log ingestion or the underlying detection rules. Audit these to see which detections are being muted, how broadly, and whether the suppression is still active. The `enabled` flag and `expirationDate` reveal whether a suppression is live or lapsed, while the query fields define its scope.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"securitySuppressions":{"name":"securitySuppressions","type":"\u0019\u001bdatadog.securitySuppression","title":"Security monitoring suppressions that silence specific signals","provider":"go.mondoo.com/mql/providers/datadog"},"sensitiveDataScannerGroup":{"name":"sensitiveDataScannerGroup","type":"\u001bdatadog.sensitiveDataScannerGroup","title":"Datadog Sensitive Data Scanner Group","desc":"Sensitive Data Scanner group that bundles PII detection and redaction rules applied to Datadog log and APM data. Auditing a group confirms whether redaction is active (`isEnabled`), which data sources it covers (`productList`, with values such as logs and apm), and how the `filter` query scopes the subset of data that gets scanned for sensitive values.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"sensitiveDataScannerGroups":{"name":"sensitiveDataScannerGroups","type":"\u0019\u001bdatadog.sensitiveDataScannerGroup","title":"Sensitive Data Scanner groups (PII redaction rule containers)","provider":"go.mondoo.com/mql/providers/datadog"},"serviceAccount":{"name":"serviceAccount","type":"\u001bdatadog.serviceAccount","title":"Datadog Service Account","desc":"Non-human identity used for programmatic API access, separate from any individual user login. Service accounts can own application keys independently of people, so auditing which ones exist, whether they are disabled, and their status surfaces long-lived automation credentials that outlast staff changes. Use handle and email to attribute a service account to its owning team or integration.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"serviceAccounts":{"name":"serviceAccounts","type":"\u0019\u001bdatadog.serviceAccount","title":"Service accounts (non-user identities for API access)","provider":"go.mondoo.com/mql/providers/datadog"},"sharedDashboard":{"name":"sharedDashboard","type":"\u001bdatadog.sharedDashboard","title":"Datadog Shared Dashboard","desc":"Public or invite-only share of a dashboard, exposing its telemetry outside the Datadog organization through a generated URL. A share with `shareType` open serves the dashboard to anyone holding the link and needs no Datadog account, so it is the strongest exposure signal on a dashboard; invite shares restrict access to the addresses in `invitees`. The `token` selects the share and forms the tail of `publicUrl`. Use `status` to tell live shares from paused ones, `expiration` to find shares that never lapse, and `embeddableDomains` to see which sites may frame the dashboard.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"slo":{"name":"slo","type":"\u001bdatadog.slo","title":"Datadog Service Level Objective","desc":"Service Level Objective that tracks a reliability or performance target for a service over a rolling window, letting you audit which services have SLOs defined and how strict their commitments are. The `type` field distinguishes metric, monitor, and time_slice SLOs; monitor-based SLOs reference their underlying monitors through `monitorIds`. The `targetThreshold` and `warningThreshold` percentages together with `timeframe` capture the reliability budget being promised.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"slos":{"name":"slos","type":"\u0019\u001bdatadog.slo","title":"Service Level Objectives (SLOs)","provider":"go.mondoo.com/mql/providers/datadog"},"syntheticsGlobalVariable":{"name":"syntheticsGlobalVariable","type":"\u001bdatadog.syntheticsGlobalVariable","title":"Datadog Synthetics Global Variable","desc":"Reusable value that can be shared and referenced across multiple Datadog Synthetics tests, letting one definition supply data such as credentials, hostnames, or tokens to many tests. The `isTotp` and `isFido` flags mark variables that carry multi-factor authentication material (Time-based One-Time Password and FIDO), which is worth auditing since those variables hold sensitive secrets. When the value is derived from another test, `parseTestPublicId` identifies that source test.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"syntheticsGlobalVariables":{"name":"syntheticsGlobalVariables","type":"\u0019\u001bdatadog.syntheticsGlobalVariable","title":"Global variables shared across synthetics tests","provider":"go.mondoo.com/mql/providers/datadog"},"syntheticsPrivateLocation":{"name":"syntheticsPrivateLocation","type":"\u001bdatadog.syntheticsPrivateLocation","title":"Datadog Synthetics private location","desc":"A Synthetics private location: a customer-managed worker that runs synthetics tests from inside a private network, so internal endpoints unreachable from Datadog's public infrastructure can still be monitored. Auditing these tells you which internal surfaces are under test and, through `metadata`, which roles are permitted to attach tests to the location.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"syntheticsPrivateLocations":{"name":"syntheticsPrivateLocations","type":"\u0019\u001bdatadog.syntheticsPrivateLocation","title":"Private locations that run synthetics tests inside customer networks","provider":"go.mondoo.com/mql/providers/datadog"},"syntheticsTest":{"name":"syntheticsTest","type":"\u001bdatadog.syntheticsTest","title":"Datadog Synthetics Test","desc":"Datadog Synthetics test that continuously verifies application availability and performance by probing endpoints or driving browser flows from managed or private locations. The `type` distinguishes lightweight `api` checks from full `browser` tests, while `subtype` selects the protocol being probed. Query `status` and `message` to see whether a test is live and how it alerts, and use `monitorId` to pivot to the backing monitor. Auditing tests confirms that critical user journeys and public endpoints are monitored for uptime and regressions.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"syntheticsTests":{"name":"syntheticsTests","type":"\u0019\u001bdatadog.syntheticsTest","title":"Synthetics tests configured in the organization","provider":"go.mondoo.com/mql/providers/datadog"},"team":{"name":"team","type":"\u001bdatadog.team","title":"Datadog Team","desc":"Group of Datadog users organized for ownership, on-call rotation, and access control. Teams tie people to the resources they are responsible for, so auditing them shows who owns what and how membership is scoped. The `handle` is the team's URL slug, `userCount` reports how many members belong to the team, and `members` resolves those members to their user accounts.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"teams":{"name":"teams","type":"\u0019\u001bdatadog.team","title":"Datadog teams (groups of users)","provider":"go.mondoo.com/mql/providers/datadog"},"user":{"name":"user","type":"\u001bdatadog.user","title":"Datadog User","desc":"User account belonging to the Datadog organization, covering both human members and service accounts. Use it to audit who has access, spot dormant or unverified accounts, and confirm disabled users have been deactivated. The status field reports Active, Pending, or Disabled, and serviceAccount distinguishes machine identities from people.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001bdatadog.user","title":"Datadog users in the organization","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog","desc":"Organization-wide Datadog configuration and inventory. Covers users, roles, permissions, monitors, dashboards, synthetics tests, SLOs, log indexes, security rules, downtimes, API keys, application keys, AWS integrations, teams, sensitive data scanner groups, security filters and suppressions, service accounts, logs archives, RUM applications, and synthetics global variables and private locations. The org field carries the single sign-on and sharing settings that govern how the organization is accessed, and the organization IP allowlist is exposed through ipAllowlistEnabled and ipAllowlistEntries. Identity provider attribute mappings, log processing pipelines, log forwarding destinations and log restriction queries cover how privilege is granted at login and where log data is read and sent. identityProviders lists the login methods available to members, oauthClients the third-party applications holding standing access, and orgConnections the other Datadog organizations this one shares data with. The integration fields cover the standing credentials Datadog holds against outside providers, spanning AWS, Google Cloud, Azure, Okta, Cloudflare, Fastly and Confluent Cloud.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/datadog","root":true},"datadog.apiKey":{"id":"datadog.apiKey","name":"datadog.apiKey","fields":{"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Key category","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"createdBy":{"name":"createdBy","type":"\u001bdatadog.user","title":"User that created the key","desc":"Null when the creating account has been removed from the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"API key ID","provider":"go.mondoo.com/mql/providers/datadog"},"last4":{"name":"last4","type":"\u0007","is_mandatory":true,"title":"Last four characters","provider":"go.mondoo.com/mql/providers/datadog"},"lastUsedAt":{"name":"lastUsedAt","type":"\t","is_mandatory":true,"title":"Last used at","desc":"Null when the key has never been used to submit data, which together with an old createdAt identifies a credential that can be revoked.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedBy":{"name":"modifiedBy","type":"\u001bdatadog.user","title":"User that last modified the key","desc":"Null when the key has not been modified since creation, or the modifying account has been removed from the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/datadog"},"remoteConfigReadEnabled":{"name":"remoteConfigReadEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the key may read remote configuration","desc":"Remote configuration lets an agent authenticated with this key pull configuration changes from Datadog, so a key with it enabled carries more than submit-only access.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog API Key","desc":"Credential that authorizes Datadog agents and integrations to submit metrics, traces, logs, and events to the organization. The `last4` field exposes only the final four characters so a key can be identified without revealing the secret. The `createdAt` and `modifiedAt` timestamps let you audit key age and flag stale or unrotated credentials, and `lastUsedAt` separates keys that are still submitting data from abandoned ones that should be revoked. The `createdBy` and `modifiedBy` fields attribute a key to the accounts that issued and last changed it.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.applicationKey":{"id":"datadog.applicationKey","name":"datadog.applicationKey","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Application key ID","provider":"go.mondoo.com/mql/providers/datadog"},"last4":{"name":"last4","type":"\u0007","is_mandatory":true,"title":"Last four characters","provider":"go.mondoo.com/mql/providers/datadog"},"lastUsedAt":{"name":"lastUsedAt","type":"\t","is_mandatory":true,"title":"Last used at","desc":"Null when the key has never been used, which together with an old createdAt identifies a credential that can be revoked.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/datadog"},"owner":{"name":"owner","type":"\u001bdatadog.user","title":"User that owns the key","desc":"An unscoped key acts with every permission this user holds. Null when the owning account has been removed from the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"scopes":{"name":"scopes","type":"\u0019\u0007","is_mandatory":true,"title":"Scopes (empty means full access)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Application Key","desc":"Application key that a user presents alongside an API key to make authenticated Datadog HTTP API calls. Auditing these surfaces which keys exist, who owns them, and how broad their access is: the `scopes` field is empty when the key has full account access, and otherwise lists the specific permission scopes granted to it. A key with no scopes inherits every permission its `owner` holds, so pairing the two shows the effective reach of the credential, and `lastUsedAt` separates live keys from dormant ones.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.authnMapping":{"id":"datadog.authnMapping","name":"datadog.authnMapping","fields":{"attributeKey":{"name":"attributeKey","type":"\u0007","is_mandatory":true,"title":"Identity provider attribute the mapping matches on","provider":"go.mondoo.com/mql/providers/datadog"},"attributeValue":{"name":"attributeValue","type":"\u0007","is_mandatory":true,"title":"Attribute value the mapping matches on","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Mapping ID","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"role":{"name":"role","type":"\u001bdatadog.role","title":"Role granted by the mapping","desc":"Null when the mapping grants a team instead.","provider":"go.mondoo.com/mql/providers/datadog"},"team":{"name":"team","type":"\u001bdatadog.team","title":"Team granted by the mapping","desc":"Null when the mapping grants a role instead.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Identity Provider Attribute Mapping","desc":"Rule granting a role or team to everyone whose identity provider assertion carries a given attribute, so it is where privilege is actually decided for a single sign-on organization. A mapping matches when the assertion contains `attributeKey` with the value `attributeValue`, and grants the `role` or `team` it points at. Auditing these shows which external directory groups confer administrative access, which is invisible from the role assignments alone because the grants are applied at login.","min_provider_version":"13.0.21","defaults":"id attributeKey attributeValue","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.dashboard":{"id":"datadog.dashboard","name":"datadog.dashboard","fields":{"author":{"name":"author","type":"\u001bdatadog.user","title":"User that authored the dashboard","desc":"Null when the author no longer has an account in the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Dashboard description","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Dashboard ID","provider":"go.mondoo.com/mql/providers/datadog"},"isReadOnly":{"name":"isReadOnly","type":"\u0004","is_mandatory":true,"title":"Is read only","provider":"go.mondoo.com/mql/providers/datadog"},"layoutType":{"name":"layoutType","type":"\u0007","is_mandatory":true,"title":"Layout type (ordered, free)","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"restrictionPolicy":{"name":"restrictionPolicy","type":"\u001bdatadog.restrictionPolicy","title":"Access control list attached to this dashboard","desc":"Null when no restriction policy is set, in which case access follows the organization-wide role permissions.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"sharedDashboards":{"name":"sharedDashboards","type":"\u0019\u001bdatadog.sharedDashboard","title":"Shares exposing this dashboard outside the organization","desc":"Empty when the dashboard has never been shared.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"title":{"name":"title","type":"\u0007","is_mandatory":true,"title":"Dashboard title","provider":"go.mondoo.com/mql/providers/datadog"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"URL path","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Dashboard","desc":"Visualization dashboard in a Datadog organization, showing metrics, logs, traces, and other telemetry on a shared canvas. The layoutType distinguishes free-form canvases (`free`) from auto-arranged grids (`ordered`). Query these to audit dashboard ownership through the authorHandle, spot dashboards left editable versus locked read-only, and track when dashboards were created or last modified.","min_provider_version":"13.0.1","defaults":"id title","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.downtime":{"id":"datadog.downtime","name":"datadog.downtime","fields":{"canceledAt":{"name":"canceledAt","type":"\t","is_mandatory":true,"title":"Canceled at","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"displayTimezone":{"name":"displayTimezone","type":"\u0007","is_mandatory":true,"title":"Display timezone","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Downtime ID","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"monitorIdentifier":{"name":"monitorIdentifier","type":"\n","is_mandatory":true,"title":"Monitor targeted by the downtime","desc":"One of two shapes: `monitorId` (number) when the downtime targets a single monitor, or `monitorTags` (list of strings) when it targets every monitor matching those tags.","provider":"go.mondoo.com/mql/providers/datadog"},"muteFirstRecoveryNotification":{"name":"muteFirstRecoveryNotification","type":"\u0004","is_mandatory":true,"title":"Mute first recovery notification","provider":"go.mondoo.com/mql/providers/datadog"},"notifyEndStates":{"name":"notifyEndStates","type":"\u0019\u0007","is_mandatory":true,"title":"Monitor states that trigger an end-of-downtime notification","desc":"Each value is one of `alert`, `warn`, or `no data`.","provider":"go.mondoo.com/mql/providers/datadog"},"notifyEndTypes":{"name":"notifyEndTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Downtime end events that trigger a notification","desc":"Each value is one of `canceled` or `expired`.","provider":"go.mondoo.com/mql/providers/datadog"},"schedule":{"name":"schedule","type":"\n","is_mandatory":true,"title":"Downtime schedule window","desc":"Keys: `timezone` (timezone of a recurring schedule), and for a one-time downtime `start` and `end` (RFC 3339 timestamps).","provider":"go.mondoo.com/mql/providers/datadog"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"Scope","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current downtime status","desc":"One of `active`, `scheduled`, `ended`, or `canceled`.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Downtime","desc":"Datadog scheduled downtime that silences monitor alerts during planned maintenance or incidents, so on-call teams are not paged for expected disruption. Query these to audit which monitors are muted, over what scope, and on what schedule. The `status` field distinguishes active, scheduled, ended, and canceled downtimes, and `monitorIdentifier` selects whether the downtime targets a single monitor or a set of monitor tags.","min_provider_version":"13.0.1","defaults":"id status","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.executionPolicy":{"id":"datadog.executionPolicy","name":"datadog.executionPolicy","fields":{"actionFqns":{"name":"actionFqns","type":"\u0019\u0007","is_mandatory":true,"title":"Fully qualified action names the policy matches","desc":"A single entry of `*` matches every action of the integration. Names are otherwise prefixed with the action namespace of the integration, for example com.datadoghq.script.* for the Script integration.","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the policy was created","provider":"go.mondoo.com/mql/providers/datadog"},"createdBy":{"name":"createdBy","type":"\u001bdatadog.user","title":"User that created the policy","provider":"go.mondoo.com/mql/providers/datadog"},"effect":{"name":"effect","type":"\u0007","is_mandatory":true,"title":"Whether the policy allows or denies the actions it matches","desc":"One of allow or deny. Datadog may add further effects, so a value outside that pair should not be read as either.","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the execution policy","provider":"go.mondoo.com/mql/providers/datadog"},"integration":{"name":"integration","type":"\u0007","is_mandatory":true,"title":"Integration the action pattern applies to","desc":"One of INTEGRATION_KUBERNETES, INTEGRATION_SCRIPT, or INTEGRATION_REMOTE_ACTION. Datadog may add further integrations.","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the execution policy","provider":"go.mondoo.com/mql/providers/datadog"},"remoteShellRule":{"name":"remoteShellRule","type":"\u001bdatadog.executionPolicy.remoteShellRule","title":"Remote shell rule of a Datadog execution policy","desc":"One set of file system paths together with the level of remote shell access granted over them. An access of read_write permits writing through the remote shell, so a read_write rule over a broad path is the strongest grant a policy can carry.","is_private":true,"provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"scope":{"name":"scope","type":"\u001bdatadog.executionPolicy.scopeRestriction","is_mandatory":true,"title":"Where the policy applies","provider":"go.mondoo.com/mql/providers/datadog"},"scopeRestriction":{"name":"scopeRestriction","type":"\u001bdatadog.executionPolicy.scopeRestriction","title":"Scope restriction of a Datadog execution policy","desc":"Narrowing that decides which objects a policy reaches once its targets have selected the hosts. At most one member is populated and scopeType says which: kubernetes fills kubernetesNamespaces, scripts fills scriptNames, and remoteActionRshell fills remoteShellRules. A scopeType of none means the policy carries no restriction and applies wherever its targets match, which is the widest reading available. A scopeType of unknown means Datadog returned a restriction this provider cannot read as a single member, either because the kind is not modeled here or because more than one member came back at once, so the member lists may describe only part of what the policy restricts and an empty list must not be read as an absence of restriction.","is_private":true,"provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"target":{"name":"target","type":"\u001bdatadog.executionPolicy.target","title":"Target of a Datadog execution policy","desc":"Agent tags identifying the hosts a policy applies to. A target naming a broad tag such as env:prod reaches every host reporting it, so the tags are what decide how wide an allow policy actually is. The name field carries the label given to the target and is null when none was set.","is_private":true,"provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"targets":{"name":"targets","type":"\u0019\u001bdatadog.executionPolicy.target","is_mandatory":true,"title":"Hosts the policy applies to, selected by Agent tags","provider":"go.mondoo.com/mql/providers/datadog"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the policy was last updated","provider":"go.mondoo.com/mql/providers/datadog"},"updatedBy":{"name":"updatedBy","type":"\u001bdatadog.user","title":"User that last updated the policy","provider":"go.mondoo.com/mql/providers/datadog"},"version":{"name":"version","type":"\u0005","is_mandatory":true,"title":"Version of the policy, incremented on every update","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Execution Policy","desc":"Rule governing whether Datadog may run a given action on the hosts an Agent tag selects. Each policy pairs an effect, allow or deny, with an action pattern naming the integration and the fully qualified actions it covers, and with the targets the policy applies to. A policy whose effect is allow and whose integration is INTEGRATION_REMOTE_ACTION grants remote shell access to every host its targets reach, which makes those policies the ones worth reading first. The scope narrows where the policy applies, naming Kubernetes namespaces, script names, or remote shell paths together with the access granted on them, and a scopeType of none means the policy carries no restriction at all. The version, createdBy and updatedBy fields record who last changed the policy and how many times it has been changed. The `id` selects a policy, for example datadog.executionPolicies.where(id == \"1c9e5b46-0000-0000-0000-000000000000\").","min_provider_version":"13.0.23","defaults":"name effect integration","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.executionPolicy.remoteShellRule":{"id":"datadog.executionPolicy.remoteShellRule","name":"datadog.executionPolicy.remoteShellRule","fields":{"access":{"name":"access","type":"\u0007","is_mandatory":true,"title":"Level of remote shell access granted over the target paths","desc":"One of read_only or read_write. Datadog may add further levels, so a value outside that pair should not be read as read_only.","provider":"go.mondoo.com/mql/providers/datadog"},"targetPaths":{"name":"targetPaths","type":"\u0019\u0007","is_mandatory":true,"title":"File system paths the rule applies to","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Remote shell rule of a Datadog execution policy","desc":"One set of file system paths together with the level of remote shell access granted over them. An access of read_write permits writing through the remote shell, so a read_write rule over a broad path is the strongest grant a policy can carry.","private":true,"min_provider_version":"13.0.23","defaults":"access","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.executionPolicy.scopeRestriction":{"id":"datadog.executionPolicy.scopeRestriction","name":"datadog.executionPolicy.scopeRestriction","fields":{"kubernetesNamespaces":{"name":"kubernetesNamespaces","type":"\u0019\u0007","is_mandatory":true,"title":"Kubernetes namespaces the policy is restricted to","provider":"go.mondoo.com/mql/providers/datadog"},"remoteShellRules":{"name":"remoteShellRules","type":"\u0019\u001bdatadog.executionPolicy.remoteShellRule","is_mandatory":true,"title":"Remote shell paths the policy is restricted to, with the access granted on each","provider":"go.mondoo.com/mql/providers/datadog"},"scopeType":{"name":"scopeType","type":"\u0007","is_mandatory":true,"title":"Which member of the restriction carries the values","desc":"One of kubernetes, scripts, remoteActionRshell, none when the policy carries no restriction, or unknown when Datadog returned a restriction this provider cannot read as a single member.","provider":"go.mondoo.com/mql/providers/datadog"},"scriptNames":{"name":"scriptNames","type":"\u0019\u0007","is_mandatory":true,"title":"Script names the policy is restricted to","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Scope restriction of a Datadog execution policy","desc":"Narrowing that decides which objects a policy reaches once its targets have selected the hosts. At most one member is populated and scopeType says which: kubernetes fills kubernetesNamespaces, scripts fills scriptNames, and remoteActionRshell fills remoteShellRules. A scopeType of none means the policy carries no restriction and applies wherever its targets match, which is the widest reading available. A scopeType of unknown means Datadog returned a restriction this provider cannot read as a single member, either because the kind is not modeled here or because more than one member came back at once, so the member lists may describe only part of what the policy restricts and an empty list must not be read as an absence of restriction.","private":true,"min_provider_version":"13.0.23","defaults":"scopeType","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.executionPolicy.target":{"id":"datadog.executionPolicy.target","name":"datadog.executionPolicy.target","fields":{"agentTags":{"name":"agentTags","type":"\u0019\u0007","is_mandatory":true,"title":"Agent tags identifying the hosts the policy applies to","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Label given to the target","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Target of a Datadog execution policy","desc":"Agent tags identifying the hosts a policy applies to. A target naming a broad tag such as env:prod reaches every host reporting it, so the tags are what decide how wide an allow policy actually is. The name field carries the label given to the target and is null when none was set.","private":true,"min_provider_version":"13.0.23","defaults":"name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.identityProvider":{"id":"datadog.identityProvider","name":"datadog.identityProvider","fields":{"authenticationMethod":{"name":"authenticationMethod","type":"\u0007","is_mandatory":true,"title":"Mechanism members authenticate with","provider":"go.mondoo.com/mql/providers/datadog"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether members can currently authenticate through this provider","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the identity provider","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Identity provider members can authenticate through","desc":"A login method configured for the organization, reported one row per provider with `authenticationMethod` naming the mechanism and `enabled` recording whether members can currently use it. This is the view that shows what remains available alongside single sign-on, so an organization that has rolled out SAML but left another method enabled is visible here rather than in the SAML settings on the org resource.","min_provider_version":"13.0.21","defaults":"id authenticationMethod enabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration":{"id":"datadog.integration","fields":{"aws":{"name":"aws","type":"\u001bdatadog.integration.aws","title":"Datadog AWS Integration Account","desc":"AWS account linked to Datadog for metrics, resource, and log collection. The roleName is the IAM role Datadog assumes to read from the account, so auditing it exposes the delegation trust that grants Datadog access. The metricsEnabled, resourceCollectionEnabled, and logsEnabled flags show which data streams are active, while includedRegions and filterTags narrow what Datadog ingests.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"azure":{"name":"azure","type":"\u001bdatadog.integration.azure","title":"Azure integration","desc":"An Azure app registration Datadog authenticates with to collect from a tenant. `tenantName` and `clientId` identify the tenant and the application, and `secretlessAuthEnabled` records whether the link uses workload identity federation instead of a client secret. `cspmEnabled` and `resourceCollectionEnabled` show how far beyond metrics the collection reaches. `errors` carries problems Datadog reported for the integration, which is where a revoked or expired credential shows up. The client secret itself is never exposed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"cloudflare":{"name":"cloudflare","type":"\u001bdatadog.integration.cloudflare","title":"Cloudflare integration","desc":"A Cloudflare account Datadog holds an API token for. `zones` lists the zones the token is scoped to and `resources` the Cloudflare products collected, so an integration with no zone restriction reaches everything the token can see. The token itself is never exposed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"confluent":{"name":"confluent","type":"\u001bdatadog.integration.confluent","title":"Confluent Cloud integration","desc":"A Confluent Cloud account Datadog holds an API key for, along with the clusters and connectors collected under it. Each entry in `resources` is a dict with `id` (the Confluent resource identifier), `resourceType` (the kind of resource, such as kafka or connector), `enableCustomMetrics` and `tags`. The API key and secret are never exposed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"fastly":{"name":"fastly","type":"\u001bdatadog.integration.fastly","title":"Fastly integration","desc":"A Fastly account Datadog holds an API key for, along with the services collected under it. Each entry in `services` is a dict with `id` (the Fastly service identifier) and `tags` (the tags applied to it). The API key itself is never exposed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"gcp":{"name":"gcp","type":"\u001bdatadog.integration.gcp","title":"Google Cloud integration","desc":"A Google Cloud service account Datadog impersonates to collect from a set of projects, established through workload identity federation rather than an exported key. `clientEmail` names the service account, and `accessibleProjects` reports the projects it can currently reach, which is the blast radius of the grant. `isCspmEnabled`, `isSecurityCommandCenterEnabled`, `resourceCollectionEnabled` and `isResourceChangeCollectionEnabled` record how much of the environment is pulled in beyond metrics. `hostFilters`, `cloudRunRevisionFilters` and `regionFilterConfigs` narrow what is collected.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"okta":{"name":"okta","type":"\u001bdatadog.integration.okta","title":"Okta integration","desc":"An Okta organization Datadog collects logs and events from. `domain` names the Okta org and `authMethod` records whether the link uses an API token or OAuth client credentials, which determines what can be rotated and how the access is scoped. The API token and client secret backing the integration are never exposed.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true}},"is_extension":true},"datadog.integration.aws":{"id":"datadog.integration.aws","name":"datadog.integration.aws","fields":{"accountId":{"name":"accountId","type":"\u0007","is_mandatory":true,"title":"AWS account ID","provider":"go.mondoo.com/mql/providers/datadog"},"accountTags":{"name":"accountTags","type":"\u0019\u0007","is_mandatory":true,"title":"Account tags","provider":"go.mondoo.com/mql/providers/datadog"},"excludedRegions":{"name":"excludedRegions","type":"\u0019\u0007","is_mandatory":true,"title":"Excluded regions","desc":"Always empty. The Datadog v2 AWS integration API expresses region selection as includedRegions (an allowlist) rather than an exclusion list. Retained for backward compatibility with the earlier schema.","provider":"go.mondoo.com/mql/providers/datadog"},"filterTags":{"name":"filterTags","type":"\u0019\u0007","is_mandatory":true,"title":"Filter tags","provider":"go.mondoo.com/mql/providers/datadog"},"hostTags":{"name":"hostTags","type":"\u0019\u0007","is_mandatory":true,"title":"Host tags","provider":"go.mondoo.com/mql/providers/datadog"},"includedRegions":{"name":"includedRegions","type":"\u0019\u0007","is_mandatory":true,"title":"Included regions","desc":"Explicit allowlist of AWS regions Datadog collects data from. Empty when the account is configured to collect from all regions.","min_provider_version":"13.0.17","provider":"go.mondoo.com/mql/providers/datadog"},"logsEnabled":{"name":"logsEnabled","type":"\u0004","is_mandatory":true,"title":"Logs collection enabled","provider":"go.mondoo.com/mql/providers/datadog"},"metricsEnabled":{"name":"metricsEnabled","type":"\u0004","is_mandatory":true,"title":"Metrics collection enabled","provider":"go.mondoo.com/mql/providers/datadog"},"resourceCollectionEnabled":{"name":"resourceCollectionEnabled","type":"\u0004","is_mandatory":true,"title":"Resource collection enabled","provider":"go.mondoo.com/mql/providers/datadog"},"roleName":{"name":"roleName","type":"\u0007","is_mandatory":true,"title":"Role name for Datadog delegation","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog AWS Integration Account","desc":"AWS account linked to Datadog for metrics, resource, and log collection. The roleName is the IAM role Datadog assumes to read from the account, so auditing it exposes the delegation trust that grants Datadog access. The metricsEnabled, resourceCollectionEnabled, and logsEnabled flags show which data streams are active, while includedRegions and filterTags narrow what Datadog ingests.","min_provider_version":"13.0.1","defaults":"accountId","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration.azure":{"id":"datadog.integration.azure","name":"datadog.integration.azure","fields":{"appServicePlanFilters":{"name":"appServicePlanFilters","type":"\u0007","is_mandatory":true,"title":"Tags limiting which App Service Plans are collected","provider":"go.mondoo.com/mql/providers/datadog"},"automute":{"name":"automute","type":"\u0004","is_mandatory":true,"title":"Whether hosts are muted while they are shutting down","provider":"go.mondoo.com/mql/providers/datadog"},"clientId":{"name":"clientId","type":"\u0007","is_mandatory":true,"title":"Application (client) ID Datadog authenticates as","provider":"go.mondoo.com/mql/providers/datadog"},"containerAppFilters":{"name":"containerAppFilters","type":"\u0007","is_mandatory":true,"title":"Tags limiting which Container Apps are collected","provider":"go.mondoo.com/mql/providers/datadog"},"cspmEnabled":{"name":"cspmEnabled","type":"\u0004","is_mandatory":true,"title":"Whether cloud security posture management is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"customMetricsEnabled":{"name":"customMetricsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether custom metrics are collected","provider":"go.mondoo.com/mql/providers/datadog"},"errors":{"name":"errors","type":"\u0019\u0007","is_mandatory":true,"title":"Problems Datadog reported for this integration","provider":"go.mondoo.com/mql/providers/datadog"},"hostFilters":{"name":"hostFilters","type":"\u0007","is_mandatory":true,"title":"Tags limiting which hosts are collected","provider":"go.mondoo.com/mql/providers/datadog"},"metricsEnabled":{"name":"metricsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether metric collection is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"resourceCollectionEnabled":{"name":"resourceCollectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether resource collection is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"secretlessAuthEnabled":{"name":"secretlessAuthEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the integration authenticates without a client secret","provider":"go.mondoo.com/mql/providers/datadog"},"tenantName":{"name":"tenantName","type":"\u0007","is_mandatory":true,"title":"Azure tenant the integration collects from","provider":"go.mondoo.com/mql/providers/datadog"},"usageMetricsEnabled":{"name":"usageMetricsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether usage metrics are collected","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Azure integration","desc":"An Azure app registration Datadog authenticates with to collect from a tenant. `tenantName` and `clientId` identify the tenant and the application, and `secretlessAuthEnabled` records whether the link uses workload identity federation instead of a client secret. `cspmEnabled` and `resourceCollectionEnabled` show how far beyond metrics the collection reaches. `errors` carries problems Datadog reported for the integration, which is where a revoked or expired credential shows up. The client secret itself is never exposed.","min_provider_version":"13.0.21","defaults":"tenantName clientId cspmEnabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration.cloudflare":{"id":"datadog.integration.cloudflare","name":"datadog.integration.cloudflare","fields":{"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Address associated with the Cloudflare account","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the Cloudflare account entry","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name given to the integration","provider":"go.mondoo.com/mql/providers/datadog"},"resources":{"name":"resources","type":"\u0019\u0007","is_mandatory":true,"title":"Cloudflare products collected","provider":"go.mondoo.com/mql/providers/datadog"},"zones":{"name":"zones","type":"\u0019\u0007","is_mandatory":true,"title":"Zones the integration is scoped to","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Cloudflare integration","desc":"A Cloudflare account Datadog holds an API token for. `zones` lists the zones the token is scoped to and `resources` the Cloudflare products collected, so an integration with no zone restriction reaches everything the token can see. The token itself is never exposed.","min_provider_version":"13.0.21","defaults":"name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration.confluent":{"id":"datadog.integration.confluent","name":"datadog.integration.confluent","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the Confluent account entry","provider":"go.mondoo.com/mql/providers/datadog"},"resources":{"name":"resources","type":"\u0019\n","is_mandatory":true,"title":"Confluent resources collected under this account","desc":"Each entry is a dict with `id` (the Confluent resource identifier), `resourceType` (the kind of resource, such as kafka or connector), `enableCustomMetrics` (whether custom metrics are collected for it), and `tags`.","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to every metric from this account","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Confluent Cloud integration","desc":"A Confluent Cloud account Datadog holds an API key for, along with the clusters and connectors collected under it. Each entry in `resources` is a dict with `id` (the Confluent resource identifier), `resourceType` (the kind of resource, such as kafka or connector), `enableCustomMetrics` and `tags`. The API key and secret are never exposed.","min_provider_version":"13.0.21","defaults":"id","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration.fastly":{"id":"datadog.integration.fastly","name":"datadog.integration.fastly","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the Fastly account entry","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name given to the integration","provider":"go.mondoo.com/mql/providers/datadog"},"services":{"name":"services","type":"\u0019\n","is_mandatory":true,"title":"Fastly services collected under this account","desc":"Each entry is a dict with `id`, the Fastly service identifier, and `tags`, the list of tags applied to that service.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Fastly integration","desc":"A Fastly account Datadog holds an API key for, along with the services collected under it. Each entry in `services` is a dict with `id` (the Fastly service identifier) and `tags` (the tags applied to it). The API key itself is never exposed.","min_provider_version":"13.0.21","defaults":"name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration.gcp":{"id":"datadog.integration.gcp","name":"datadog.integration.gcp","fields":{"accessibleProjects":{"name":"accessibleProjects","type":"\u0019\u0007","is_mandatory":true,"title":"Projects the service account can currently reach","provider":"go.mondoo.com/mql/providers/datadog"},"accountTags":{"name":"accountTags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to every metric from this account","provider":"go.mondoo.com/mql/providers/datadog"},"automute":{"name":"automute","type":"\u0004","is_mandatory":true,"title":"Whether hosts are muted while they are shutting down","provider":"go.mondoo.com/mql/providers/datadog"},"clientEmail":{"name":"clientEmail","type":"\u0007","is_mandatory":true,"title":"Service account Datadog authenticates as","provider":"go.mondoo.com/mql/providers/datadog"},"cloudRunRevisionFilters":{"name":"cloudRunRevisionFilters","type":"\u0019\u0007","is_mandatory":true,"title":"Tags limiting which Cloud Run revisions are collected","provider":"go.mondoo.com/mql/providers/datadog"},"hostFilters":{"name":"hostFilters","type":"\u0019\u0007","is_mandatory":true,"title":"Tags limiting which hosts are collected","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the service account entry","provider":"go.mondoo.com/mql/providers/datadog"},"isCspmEnabled":{"name":"isCspmEnabled","type":"\u0004","is_mandatory":true,"title":"Whether cloud security posture management is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"isGlobalLocationEnabled":{"name":"isGlobalLocationEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the global location is included in collection","provider":"go.mondoo.com/mql/providers/datadog"},"isPerProjectQuotaEnabled":{"name":"isPerProjectQuotaEnabled","type":"\u0004","is_mandatory":true,"title":"Whether per-project quota is used for API calls","provider":"go.mondoo.com/mql/providers/datadog"},"isResourceChangeCollectionEnabled":{"name":"isResourceChangeCollectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether resource change collection is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"isSecurityCommandCenterEnabled":{"name":"isSecurityCommandCenterEnabled","type":"\u0004","is_mandatory":true,"title":"Whether Security Command Center findings are collected","provider":"go.mondoo.com/mql/providers/datadog"},"regionFilterConfigs":{"name":"regionFilterConfigs","type":"\u0019\u0007","is_mandatory":true,"title":"Regions collection is restricted to","provider":"go.mondoo.com/mql/providers/datadog"},"resourceCollectionEnabled":{"name":"resourceCollectionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether resource collection is enabled","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Google Cloud integration","desc":"A Google Cloud service account Datadog impersonates to collect from a set of projects, established through workload identity federation rather than an exported key. `clientEmail` names the service account, and `accessibleProjects` reports the projects it can currently reach, which is the blast radius of the grant. `isCspmEnabled`, `isSecurityCommandCenterEnabled`, `resourceCollectionEnabled` and `isResourceChangeCollectionEnabled` record how much of the environment is pulled in beyond metrics. `hostFilters`, `cloudRunRevisionFilters` and `regionFilterConfigs` narrow what is collected.","min_provider_version":"13.0.21","defaults":"clientEmail isCspmEnabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.integration.okta":{"id":"datadog.integration.okta","name":"datadog.integration.okta","fields":{"authMethod":{"name":"authMethod","type":"\u0007","is_mandatory":true,"title":"Credential type the integration authenticates with","desc":"Either an API token or OAuth client credentials.","provider":"go.mondoo.com/mql/providers/datadog"},"clientId":{"name":"clientId","type":"\u0007","is_mandatory":true,"title":"Client ID used when authenticating with OAuth client credentials","provider":"go.mondoo.com/mql/providers/datadog"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Okta organization the integration collects from","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the Okta account entry","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name given to the integration","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Okta integration","desc":"An Okta organization Datadog collects logs and events from. `domain` names the Okta org and `authMethod` records whether the link uses an API token or OAuth client credentials, which determines what can be rotated and how the access is scoped. The API token and client secret backing the integration are never exposed.","min_provider_version":"13.0.21","defaults":"name domain authMethod","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logIndex":{"id":"datadog.logIndex","name":"datadog.logIndex","fields":{"dailyLimit":{"name":"dailyLimit","type":"\u0005","is_mandatory":true,"title":"Daily limit","provider":"go.mondoo.com/mql/providers/datadog"},"dailyLimitWarningThresholdPercentage":{"name":"dailyLimitWarningThresholdPercentage","type":"\u0006","is_mandatory":true,"title":"Daily-limit warning threshold as a percentage (0-100)","provider":"go.mondoo.com/mql/providers/datadog"},"exclusionFilters":{"name":"exclusionFilters","type":"\u0019\n","is_mandatory":true,"title":"Exclusion filters that sample or drop matching logs","desc":"Each entry has `name` (the exclusion filter name), `isEnabled` (whether the filter is active), `query` (the log query selecting which logs to exclude), and `sampleRate` (fraction of matching logs retained, where 0.0 drops all matches and 1.0 keeps them all).","provider":"go.mondoo.com/mql/providers/datadog"},"filter":{"name":"filter","type":"\u0007","is_mandatory":true,"title":"Log filter query","provider":"go.mondoo.com/mql/providers/datadog"},"isRateLimited":{"name":"isRateLimited","type":"\u0004","is_mandatory":true,"title":"Is rate limited","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Index name","provider":"go.mondoo.com/mql/providers/datadog"},"numFlexLogsRetentionDays":{"name":"numFlexLogsRetentionDays","type":"\u0005","is_mandatory":true,"title":"Number of flex logs retention days","provider":"go.mondoo.com/mql/providers/datadog"},"numRetentionDays":{"name":"numRetentionDays","type":"\u0005","is_mandatory":true,"title":"Number of days to retain","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Log Index","desc":"Datadog log index that partitions and retains ingested log data. Log indexes control which logs are stored, how long they are kept, and how much is billed, so auditing them surfaces short retention windows, missing daily limits that expose cost overruns, and exclusion filters that silently sample or drop security-relevant logs. Each index is identified by its `name`, and `filter` holds the query that routes logs into it.","min_provider_version":"13.0.1","defaults":"name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logsArchive":{"id":"datadog.logsArchive","name":"datadog.logsArchive","fields":{"destination":{"name":"destination","type":"\n","is_mandatory":true,"title":"Cloud storage destination configuration","desc":"Keys vary by destinationType. For s3 and gcs: bucket and path. For azure: container, storageAccount, and path.","provider":"go.mondoo.com/mql/providers/datadog"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type (s3, gcs, azure)","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Archive ID","provider":"go.mondoo.com/mql/providers/datadog"},"includeTags":{"name":"includeTags","type":"\u0004","is_mandatory":true,"title":"Whether tags from the original logs are preserved in the archive","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Archive name","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Query filter","provider":"go.mondoo.com/mql/providers/datadog"},"rehydrationMaxScanSizeInGb":{"name":"rehydrationMaxScanSizeInGb","type":"\u0005","is_mandatory":true,"title":"Rehydration max scan size in GB","provider":"go.mondoo.com/mql/providers/datadog"},"rehydrationTags":{"name":"rehydrationTags","type":"\u0019\u0007","is_mandatory":true,"title":"Rehydration tags","provider":"go.mondoo.com/mql/providers/datadog"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"State (UNKNOWN, WORKING, FAILING, WORKING_AUTH_LEGACY)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Logs Archive","desc":"Datadog logs archive that ships retained logs to long-term cloud storage in Amazon S3, Google Cloud Storage, or Azure Blob Storage. The query filter selects which logs land in the archive, and destinationType (s3, gcs, or azure) determines which keys populate the destination configuration. Useful for auditing where log data is retained, whether archives are healthy, and the rehydration limits applied to them.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logsCustomDestination":{"id":"datadog.logsCustomDestination","name":"datadog.logsCustomDestination","fields":{"authType":{"name":"authType","type":"\u0007","is_mandatory":true,"title":"Authentication method used to reach the destination","desc":"One of basic or custom_header for an HTTP destination, and empty for destination types that authenticate another way.","provider":"go.mondoo.com/mql/providers/datadog"},"destinationType":{"name":"destinationType","type":"\u0007","is_mandatory":true,"title":"Destination type","desc":"One of http, splunk_hec, elasticsearch, or microsoft_sentinel. Empty when Datadog reports a destination type this provider does not yet recognize.","provider":"go.mondoo.com/mql/providers/datadog"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether forwarding is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"endpoint":{"name":"endpoint","type":"\u0007","is_mandatory":true,"title":"Address log events are sent to","desc":"The HTTP, Splunk or Elasticsearch endpoint URL. For a Microsoft Sentinel destination this is the data collection endpoint.","provider":"go.mondoo.com/mql/providers/datadog"},"forwardTags":{"name":"forwardTags","type":"\u0004","is_mandatory":true,"title":"Whether tags are forwarded alongside the log events","provider":"go.mondoo.com/mql/providers/datadog"},"forwardTagsRestrictionList":{"name":"forwardTagsRestrictionList","type":"\u0019\u0007","is_mandatory":true,"title":"Tag keys forwarded when the restriction list is in use","provider":"go.mondoo.com/mql/providers/datadog"},"forwardTagsRestrictionListType":{"name":"forwardTagsRestrictionListType","type":"\u0007","is_mandatory":true,"title":"How the tag restriction list is applied","desc":"One of ALLOW_LIST or BLOCK_LIST.","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Destination ID","provider":"go.mondoo.com/mql/providers/datadog"},"indexName":{"name":"indexName","type":"\u0007","is_mandatory":true,"title":"Elasticsearch index events are written to","desc":"Empty for destination types other than elasticsearch.","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Destination name","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Query selecting which log events are forwarded","desc":"Empty when every ingested log is forwarded.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Log Forwarding Destination","desc":"External system that Datadog copies matching log events to, so it is an egress path for whatever the `query` selects. Auditing these shows where log data leaves Datadog and how the connection is authenticated: the `destinationType` names the receiving system, `endpoint` is the address it is sent to, and `enabled` reports whether forwarding is live. The `forwardTags` flag together with `forwardTagsRestrictionList` controls whether host and service tags travel with the events.","min_provider_version":"13.0.21","defaults":"id name destinationType enabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logsPipeline":{"id":"datadog.logsPipeline","name":"datadog.logsPipeline","fields":{"filterQuery":{"name":"filterQuery","type":"\u0007","is_mandatory":true,"title":"Query selecting which log events enter the pipeline","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Pipeline ID","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the pipeline is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"isReadOnly":{"name":"isReadOnly","type":"\u0004","is_mandatory":true,"title":"Whether the pipeline is read only","desc":"True for the integration pipelines Datadog ships, which cannot be edited.","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Pipeline name","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Pipeline type","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Log Processing Pipeline","desc":"Pipeline that parses, enriches and rewrites log events as they are ingested, ahead of indexing. Pipelines are where log content is reshaped, so auditing them shows which log sources are processed at all and whether the processing that redacts or remaps sensitive fields is switched on. The `filterQuery` selects which events enter the pipeline, `isEnabled` reports whether it runs, and `isReadOnly` distinguishes the integration pipelines Datadog ships from those the organization authored.","min_provider_version":"13.0.21","defaults":"id name isEnabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.logsRestrictionQuery":{"id":"datadog.logsRestrictionQuery","name":"datadog.logsRestrictionQuery","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Restriction query ID","provider":"go.mondoo.com/mql/providers/datadog"},"lastModifierEmail":{"name":"lastModifierEmail","type":"\u0007","is_mandatory":true,"title":"Email address of the account that last modified the restriction","provider":"go.mondoo.com/mql/providers/datadog"},"lastModifierName":{"name":"lastModifierName","type":"\u0007","is_mandatory":true,"title":"Name of the account that last modified the restriction","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"restrictionQuery":{"name":"restrictionQuery","type":"\u0007","is_mandatory":true,"title":"Query limiting which log events may be read","provider":"go.mondoo.com/mql/providers/datadog"},"roleCount":{"name":"roleCount","type":"\u0005","is_mandatory":true,"title":"Number of roles the restriction is attached to","provider":"go.mondoo.com/mql/providers/datadog"},"roles":{"name":"roles","type":"\u0019\u001bdatadog.role","title":"Roles the restriction is attached to","provider":"go.mondoo.com/mql/providers/datadog"},"userCount":{"name":"userCount","type":"\u0005","is_mandatory":true,"title":"Number of users covered by the restriction","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Log Restriction Query","desc":"Query limiting which log events the roles it is attached to may read, so it is the mechanism that keeps one team from reading another team's logs. A role with no restriction query reads every log its permissions allow; a role with one reads only events matching `restrictionQuery`. The `roleCount` and `userCount` fields report how far the restriction reaches, and `roles` resolves the roles it is bound to.","min_provider_version":"13.0.21","defaults":"id restrictionQuery","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.monitor":{"id":"datadog.monitor","name":"datadog.monitor","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"createdBy":{"name":"createdBy","type":"\u001bdatadog.user","title":"User that created the monitor","desc":"Null when the creator no longer has an account in the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Monitor ID","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message (notification text)","provider":"go.mondoo.com/mql/providers/datadog"},"modified":{"name":"modified","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Monitor name","provider":"go.mondoo.com/mql/providers/datadog"},"notifyNoData":{"name":"notifyNoData","type":"\u0004","is_mandatory":true,"title":"Whether the monitor notifies when data is missing","provider":"go.mondoo.com/mql/providers/datadog"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Alert behavior options","desc":"Keys: `renotifyInterval` (minutes between re-notifications while the monitor stays in alert), `timeoutH` (hours before a triggered alert auto-resolves), `evaluationDelay` (seconds the evaluation is held back to allow late-arriving data), and `notifyAudit` (bool, whether changes to the monitor are announced to its notification targets).","provider":"go.mondoo.com/mql/providers/datadog"},"overallState":{"name":"overallState","type":"\u0007","is_mandatory":true,"title":"Overall state (Alert, Warn, No Data, OK)","provider":"go.mondoo.com/mql/providers/datadog"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority (1-5, or null)","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Monitor query","provider":"go.mondoo.com/mql/providers/datadog"},"restrictionPolicy":{"name":"restrictionPolicy","type":"\u001bdatadog.restrictionPolicy","title":"Access control list attached to this monitor","desc":"Null when no restriction policy is set, in which case access follows the organization-wide role permissions.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Monitor type (metric alert, service check, log alert, etc.)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Monitor","desc":"Alerting monitor that watches a metric, log, or service check and fires notifications when a threshold is breached. The `type` field distinguishes what is watched (metric alert, service check, log alert, and so on), and `overallState` reports the live evaluation result (Alert, Warn, No Data, or OK). Auditing monitors surfaces alerting coverage gaps, no-data handling, and how notifications are routed.","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.oauthClient":{"id":"datadog.oauthClient","name":"datadog.oauthClient","fields":{"authorization":{"name":"authorization","type":"\u001bdatadog.oauthClient.authorization","title":"Grant a member made to a third-party OAuth client","desc":"One person's authorization of an OAuth2 application, holding the scopes they consented to and the times the grant was created, changed and last used. `disabled` reflects a revocation by the member themselves, while `orgDisabled` reflects an organization-wide revocation of the client; a grant is only live when both are false. The scopes are the actual permissions the application can exercise on that member's behalf, which is what makes this the level to audit rather than the client as a whole. The user field identifies whose access is delegated.","provider":"go.mondoo.com/mql/providers/datadog","is_implicit_resource":true},"authorizations":{"name":"authorizations","type":"\u0019\u001bdatadog.oauthClient.authorization","title":"Individual grants members have made to this client","provider":"go.mondoo.com/mql/providers/datadog"},"clientId":{"name":"clientId","type":"\u0007","is_mandatory":true,"title":"Identifier of the OAuth2 client the organization authorized","provider":"go.mondoo.com/mql/providers/datadog"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the organization has revoked this client for all members","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the authorization record","provider":"go.mondoo.com/mql/providers/datadog"},"lastExercised":{"name":"lastExercised","type":"\t","is_mandatory":true,"title":"When the client last used its authorization","provider":"go.mondoo.com/mql/providers/datadog"},"userCount":{"name":"userCount","type":"\u0005","is_mandatory":true,"title":"Number of members who have authorized this client","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Third-party OAuth client authorized against the organization","desc":"An OAuth2 application that members of the organization have granted standing access to Datadog data. Each client is listed once for the whole organization, with `userCount` reporting how many people have authorized it and `lastExercised` when its access was most recently used. `disabled` records an organization-wide revocation, which blocks the client for everyone regardless of individual consent. The authorizations hold the per-person grants, including the scopes each member handed over, so a client with a large `userCount` and broad scopes is worth reviewing even when nobody remembers approving it. Clients that stop appearing in `lastExercised` for long periods are candidates for revocation.","min_provider_version":"13.0.21","defaults":"clientId userCount disabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.oauthClient.authorization":{"id":"datadog.oauthClient.authorization","name":"datadog.oauthClient.authorization","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"When the grant was created","provider":"go.mondoo.com/mql/providers/datadog"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the member has revoked this grant","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the authorization","provider":"go.mondoo.com/mql/providers/datadog"},"lastExercised":{"name":"lastExercised","type":"\t","is_mandatory":true,"title":"When the client last used this grant","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"When the grant was last modified","provider":"go.mondoo.com/mql/providers/datadog"},"orgDisabled":{"name":"orgDisabled","type":"\u0004","is_mandatory":true,"title":"Whether the organization has revoked the client for all members","provider":"go.mondoo.com/mql/providers/datadog"},"scopes":{"name":"scopes","type":"\u0019\u0007","is_mandatory":true,"title":"Scopes the member granted to the client","provider":"go.mondoo.com/mql/providers/datadog"},"user":{"name":"user","type":"\u001bdatadog.user","title":"Member who granted the access","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Grant a member made to a third-party OAuth client","desc":"One person's authorization of an OAuth2 application, holding the scopes they consented to and the times the grant was created, changed and last used. `disabled` reflects a revocation by the member themselves, while `orgDisabled` reflects an organization-wide revocation of the client; a grant is only live when both are false. The scopes are the actual permissions the application can exercise on that member's behalf, which is what makes this the level to audit rather than the client as a whole. The user field identifies whose access is delegated.","min_provider_version":"13.0.21","defaults":"id disabled scopes","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.orgConnection":{"id":"datadog.orgConnection","name":"datadog.orgConnection","fields":{"connectionTypes":{"name":"connectionTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Kinds of data the connection covers","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"When the connection was created","provider":"go.mondoo.com/mql/providers/datadog"},"createdBy":{"name":"createdBy","type":"\u001bdatadog.user","title":"Member who created the connection","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the connection","provider":"go.mondoo.com/mql/providers/datadog"},"sinkOrgId":{"name":"sinkOrgId","type":"\u0007","is_mandatory":true,"title":"Identifier of the organization data flows into","provider":"go.mondoo.com/mql/providers/datadog"},"sinkOrgName":{"name":"sinkOrgName","type":"\u0007","is_mandatory":true,"title":"Name of the organization data flows into","provider":"go.mondoo.com/mql/providers/datadog"},"sourceOrgId":{"name":"sourceOrgId","type":"\u0007","is_mandatory":true,"title":"Identifier of the organization data flows out of","provider":"go.mondoo.com/mql/providers/datadog"},"sourceOrgName":{"name":"sourceOrgName","type":"\u0007","is_mandatory":true,"title":"Name of the organization data flows out of","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Connection sharing data with another Datadog organization","desc":"A link between this organization and another one, letting telemetry cross an organizational boundary. `sourceOrgId` and `sourceOrgName` name the organization data flows out of, `sinkOrgId` and `sinkOrgName` the one it flows into, so comparing them against the organization publicId shows which direction a given connection runs. `connectionTypes` lists the kinds of data covered by the link, and createdBy identifies who established it.","min_provider_version":"13.0.21","defaults":"id connectionTypes","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.organization":{"id":"datadog.organization","name":"datadog.organization","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Organization description","provider":"go.mondoo.com/mql/providers/datadog"},"domainAllowlistDomains":{"name":"domainAllowlistDomains","type":"\u0019\u0007","title":"Email domains that may be invited to the organization","provider":"go.mondoo.com/mql/providers/datadog"},"domainAllowlistEnabled":{"name":"domainAllowlistEnabled","type":"\u0004","title":"Whether the email domain allowlist is enforced","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Organization name","provider":"go.mondoo.com/mql/providers/datadog"},"privateWidgetShare":{"name":"privateWidgetShare","type":"\u0004","is_mandatory":true,"title":"Whether individual dashboard widgets can be shared outside the organization","provider":"go.mondoo.com/mql/providers/datadog"},"publicId":{"name":"publicId","type":"\u0007","is_mandatory":true,"title":"Organization public ID","provider":"go.mondoo.com/mql/providers/datadog"},"samlAutocreateAccessRole":{"name":"samlAutocreateAccessRole","type":"\u0007","is_mandatory":true,"title":"Role granted to automatically created users","desc":"One of st (Standard), adm (Administrator), or ro (Read Only). Empty when automatic user creation is off.","provider":"go.mondoo.com/mql/providers/datadog"},"samlAutocreateUsersDomains":{"name":"samlAutocreateUsersDomains","type":"\u0019\u0007","is_mandatory":true,"title":"Email domains whose users are created automatically on first SAML login","provider":"go.mondoo.com/mql/providers/datadog"},"samlAutocreateUsersEnabled":{"name":"samlAutocreateUsersEnabled","type":"\u0004","is_mandatory":true,"title":"Whether users are created automatically on first SAML login","provider":"go.mondoo.com/mql/providers/datadog"},"samlCanBeEnabled":{"name":"samlCanBeEnabled","type":"\u0004","is_mandatory":true,"title":"Whether SAML can be enabled for this organization","desc":"False until an identity provider metadata file has been uploaded, so it distinguishes an organization that has declined single sign-on from one that cannot yet turn it on.","provider":"go.mondoo.com/mql/providers/datadog"},"samlEnabled":{"name":"samlEnabled","type":"\u0004","is_mandatory":true,"title":"Whether SAML single sign-on is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"samlIdpEndpoint":{"name":"samlIdpEndpoint","type":"\u0007","is_mandatory":true,"title":"Identity provider endpoint URL","provider":"go.mondoo.com/mql/providers/datadog"},"samlIdpInitiatedLoginEnabled":{"name":"samlIdpInitiatedLoginEnabled","type":"\u0004","is_mandatory":true,"title":"Whether identity provider initiated login is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"samlIdpMetadataUploaded":{"name":"samlIdpMetadataUploaded","type":"\u0004","is_mandatory":true,"title":"Whether identity provider metadata has been uploaded","provider":"go.mondoo.com/mql/providers/datadog"},"samlLoginUrl":{"name":"samlLoginUrl","type":"\u0007","is_mandatory":true,"title":"SAML login URL","provider":"go.mondoo.com/mql/providers/datadog"},"samlStrictModeEnabled":{"name":"samlStrictModeEnabled","type":"\u0004","is_mandatory":true,"title":"Whether SAML strict mode is enabled","desc":"Strict mode refuses username and password logins once SAML is active, so an organization with samlEnabled true and this false still permits a direct login that bypasses the identity provider.","provider":"go.mondoo.com/mql/providers/datadog"},"trial":{"name":"trial","type":"\u0004","is_mandatory":true,"title":"Whether the organization is on a trial plan","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Organization","desc":"Datadog organization the supplied credentials authenticate against, and the account-wide settings that govern how people reach it. The single sign-on fields describe whether SAML is configured and how strictly it is enforced: samlEnabled reports whether SAML login is turned on, samlStrictModeEnabled reports whether username and password login is refused once SAML is active, and samlIdpInitiatedLoginEnabled reports whether the identity provider may start a session on its own. The samlAutocreateUsersEnabled and samlAutocreateUsersDomains fields expose which email domains are granted an account automatically on first login, and samlAutocreateAccessRole is the role those accounts receive. Beyond SAML, privateWidgetShare reports whether individual dashboard widgets can be shared outside the organization, and domainAllowlistEnabled together with domainAllowlistDomains restrict which email domains may be invited at all.","min_provider_version":"13.0.21","defaults":"publicId name samlEnabled","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.permission":{"id":"datadog.permission","name":"datadog.permission","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of what the permission grants","provider":"go.mondoo.com/mql/providers/datadog"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name shown in the Datadog interface","provider":"go.mondoo.com/mql/providers/datadog"},"displayType":{"name":"displayType","type":"\u0007","is_mandatory":true,"title":"Display type","desc":"How the permission is presented in the roles interface. One of read, write, or other.","provider":"go.mondoo.com/mql/providers/datadog"},"groupName":{"name":"groupName","type":"\u0007","is_mandatory":true,"title":"Group the permission belongs to","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Permission ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Permission name","desc":"The stable identifier referenced by scoped application keys and role definitions, for example org_management, user_access_manage, or logs_read_data.","provider":"go.mondoo.com/mql/providers/datadog"},"restricted":{"name":"restricted","type":"\u0004","is_mandatory":true,"title":"Whether the permission is restricted to built-in roles","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Permission","desc":"Individual capability that a role can grant, such as reading dashboards or managing API keys. Permissions are the leaves of the role-based access control model, so listing the permissions attached to a role shows exactly what its members can do rather than what the role is called. The name field is the stable identifier used in policy (for example org_management or logs_read_data), while displayName and groupName carry the wording shown in the Datadog roles interface. The restricted field marks permissions that cannot be granted through the API and are reserved to built-in roles.","min_provider_version":"13.0.21","defaults":"name groupName","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.restrictionPolicy":{"id":"datadog.restrictionPolicy","name":"datadog.restrictionPolicy","fields":{"bindings":{"name":"bindings","type":"\u0019\n","is_mandatory":true,"title":"Access grants","desc":"Each binding is a dict with `relation` (the access level granted, such as viewer or editor) and `principals` (the list of identities holding it). A principal is written as type:identifier, for example role:abc-123, team:def-456, user:ghi-789, or org:jkl-012 to grant the whole organization.","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Resource the policy protects","desc":"The Datadog resource identifier the policy applies to, in the form type:identifier, for example dashboard:abc-def-ghi, monitor:12345, slo:abc123, or security-rule:def456.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Restriction Policy","desc":"Access control list attached to one Datadog resource, overriding the organization-wide role permissions for that resource alone. A dashboard or monitor with no restriction policy is governed purely by role permissions; one with a policy is reachable only by the principals the policy names. The `id` is the Datadog resource identifier the policy protects, in the form type:identifier, for example dashboard:abc-def-ghi or monitor:12345. The bindings hold the grants themselves, so an empty bindings list means the policy exists but grants nothing beyond the resource owner.","min_provider_version":"13.0.21","defaults":"id","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.role":{"id":"datadog.role","name":"datadog.role","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Role ID","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Role name","provider":"go.mondoo.com/mql/providers/datadog"},"permissions":{"name":"permissions","type":"\u0019\u001bdatadog.permission","title":"Permissions granted by the role","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"userCount":{"name":"userCount","type":"\u0005","is_mandatory":true,"title":"User count","provider":"go.mondoo.com/mql/providers/datadog"},"users":{"name":"users","type":"\u0019\u001bdatadog.user","title":"Users that hold the role","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Role","desc":"Role-based access control (RBAC) role governing what members can see and do within the organization. Roles bundle permissions and are assigned to users, so auditing them shows how administrative and read/write access is scoped. The `userCount` field reports how many members hold the role, which helps flag over-provisioned or unused roles. The permissions field expands the role into the individual capabilities it grants, and users lists the members who hold it, so the two together answer who can perform a given action.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.rumApplication":{"id":"datadog.rumApplication","name":"datadog.rumApplication","fields":{"clientToken":{"name":"clientToken","type":"\u0007","is_mandatory":true,"title":"Client token","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Application ID","provider":"go.mondoo.com/mql/providers/datadog"},"isActive":{"name":"isActive","type":"\u0004","is_mandatory":true,"title":"Is active","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Application name","provider":"go.mondoo.com/mql/providers/datadog"},"orgId":{"name":"orgId","type":"\u0007","is_mandatory":true,"title":"Organization ID","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Application type (browser, ios, android, react-native, flutter, roku, unity, kotlin-multiplatform)","provider":"go.mondoo.com/mql/providers/datadog"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog RUM Application","desc":"Real User Monitoring (RUM) application that collects browser or mobile telemetry from end users. The `type` field records the platform (one of browser, ios, android, react-native, flutter, roku, unity, or kotlin-multiplatform), and `clientToken` is the credential embedded in the client SDK to send RUM events, so auditing which applications exist and whether each is active helps confirm that only sanctioned properties emit user telemetry.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.securityFilter":{"id":"datadog.securityFilter","name":"datadog.securityFilter","fields":{"filteredDataType":{"name":"filteredDataType","type":"\u0007","is_mandatory":true,"title":"Category of data the filter applies to","desc":"Currently only `logs`.","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Filter ID","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the filter is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Filter name","provider":"go.mondoo.com/mql/providers/datadog"},"query":{"name":"query","type":"\u0007","is_mandatory":true,"title":"Filter query","provider":"go.mondoo.com/mql/providers/datadog"},"version":{"name":"version","type":"\u0005","is_mandatory":true,"title":"Version","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Security Monitoring Filter","desc":"Security monitoring filter that excludes matching data from detection rule evaluation, scoping which logs Cloud SIEM analyzes. Query it to audit whether each filter is enabled and what `query` expression it applies, since an overly broad filter can hide activity from detection.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.securityRule":{"id":"datadog.securityRule","name":"datadog.securityRule","fields":{"cases":{"name":"cases","type":"\u0019\n","is_mandatory":true,"title":"Signal cases","desc":"Each case is a dict with `name` (case label), `status` (the severity assigned when the case matches: info, low, medium, high, or critical), and `condition` (the boolean expression over the rule's queries that triggers this case).","provider":"go.mondoo.com/mql/providers/datadog"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"filters":{"name":"filters","type":"\u0019\n","is_mandatory":true,"title":"Rule filters","desc":"Each filter is a dict with `query` (the log or event query the filter matches) and `action`, one of require (only evaluate events matching the query) or suppress (exclude matching events from detection).","provider":"go.mondoo.com/mql/providers/datadog"},"hasExtendedTitle":{"name":"hasExtendedTitle","type":"\u0004","is_mandatory":true,"title":"Has extended title","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Rule ID","provider":"go.mondoo.com/mql/providers/datadog"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Is default (built-in)","provider":"go.mondoo.com/mql/providers/datadog"},"isDeleted":{"name":"isDeleted","type":"\u0004","is_mandatory":true,"title":"Is deleted","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/mql/providers/datadog"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Detection options","desc":"Rule-specific evaluation parameters. Keys: `detectionMethod` (one of threshold, new_value, anomaly_detection, impossible_travel, hardcoded, third_party, anomaly_threshold, or sequence_detection), `evaluationWindow` (seconds of data evaluated per query), `keepAlive` (seconds a signal stays open on repeated matches), and `maxSignalDuration` (seconds before a signal is force-closed).","provider":"go.mondoo.com/mql/providers/datadog"},"restrictionPolicy":{"name":"restrictionPolicy","type":"\u001bdatadog.restrictionPolicy","title":"Access control list attached to this rule","desc":"Null when no restriction policy is set, in which case access follows the organization-wide role permissions.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule type","desc":"One of log_detection, infrastructure_configuration, workload_security, cloud_configuration, application_security, api_security, or workload_activity.","provider":"go.mondoo.com/mql/providers/datadog"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Security Monitoring Rule","desc":"Datadog Cloud SIEM detection rule that identifies threats and policy violations across logs and cloud activity. A rule defines the query conditions that generate security signals, the severity assigned to each match, and the detection method used to evaluate incoming data, so it is the core control governing what a Cloud SIEM deployment detects. Use isEnabled to tell which rules are active, isDefault to separate built-in rules from custom ones, and message for the triage guidance shown on a generated signal.","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.securitySuppression":{"id":"datadog.securitySuppression","name":"datadog.securitySuppression","fields":{"dataExclusionQuery":{"name":"dataExclusionQuery","type":"\u0007","is_mandatory":true,"title":"Data exclusion query","desc":"Query that excludes matching events from the detection pipeline entirely, so no signal is generated for them in the first place.","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the suppression is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"expirationDate":{"name":"expirationDate","type":"\t","is_mandatory":true,"title":"Expiration date","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Suppression ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Suppression name","provider":"go.mondoo.com/mql/providers/datadog"},"ruleQuery":{"name":"ruleQuery","type":"\u0007","is_mandatory":true,"title":"Rule query","desc":"Query that selects which detection rules the suppression applies to. Signals from rules matching this query are candidates for suppression.","provider":"go.mondoo.com/mql/providers/datadog"},"suppressionQuery":{"name":"suppressionQuery","type":"\u0007","is_mandatory":true,"title":"Suppression query","desc":"Query evaluated against a signal's attributes. Signals from the selected rules that also match this query are suppressed, so a broad query silences more signals.","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Security Monitoring Suppression","desc":"Suppression rule that silences matching security signals without affecting log ingestion or the underlying detection rules. Audit these to see which detections are being muted, how broadly, and whether the suppression is still active. The `enabled` flag and `expirationDate` reveal whether a suppression is live or lapsed, while the query fields define its scope.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.sensitiveDataScannerGroup":{"id":"datadog.sensitiveDataScannerGroup","name":"datadog.sensitiveDataScannerGroup","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"filter":{"name":"filter","type":"\u0007","is_mandatory":true,"title":"Filter query","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Group ID","provider":"go.mondoo.com/mql/providers/datadog"},"isEnabled":{"name":"isEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the group is enabled","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/mql/providers/datadog"},"productList":{"name":"productList","type":"\u0019\u0007","is_mandatory":true,"title":"Product list (logs, apm)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Sensitive Data Scanner Group","desc":"Sensitive Data Scanner group that bundles PII detection and redaction rules applied to Datadog log and APM data. Auditing a group confirms whether redaction is active (`isEnabled`), which data sources it covers (`productList`, with values such as logs and apm), and how the `filter` query scopes the subset of data that gets scanned for sensitive values.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.serviceAccount":{"id":"datadog.serviceAccount","name":"datadog.serviceAccount","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Disabled","provider":"go.mondoo.com/mql/providers/datadog"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email","provider":"go.mondoo.com/mql/providers/datadog"},"handle":{"name":"handle","type":"\u0007","is_mandatory":true,"title":"Handle","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Service account ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Service Account","desc":"Non-human identity used for programmatic API access, separate from any individual user login. Service accounts can own application keys independently of people, so auditing which ones exist, whether they are disabled, and their status surfaces long-lived automation credentials that outlast staff changes. Use handle and email to attribute a service account to its owning team or integration.","min_provider_version":"13.0.1","defaults":"id email","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.sharedDashboard":{"id":"datadog.sharedDashboard","name":"datadog.sharedDashboard","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"dashboard":{"name":"dashboard","type":"\u001bdatadog.dashboard","title":"Dashboard being shared","provider":"go.mondoo.com/mql/providers/datadog"},"embeddableDomains":{"name":"embeddableDomains","type":"\u0019\u0007","is_mandatory":true,"title":"Domains permitted to embed the dashboard","provider":"go.mondoo.com/mql/providers/datadog"},"expiration":{"name":"expiration","type":"\t","is_mandatory":true,"title":"Expiration","desc":"Null when the share never expires, which leaves the URL live indefinitely.","provider":"go.mondoo.com/mql/providers/datadog"},"invitees":{"name":"invitees","type":"\u0019\u0007","is_mandatory":true,"title":"Addresses invited to an invite-only share","provider":"go.mondoo.com/mql/providers/datadog"},"lastAccessed":{"name":"lastAccessed","type":"\t","is_mandatory":true,"title":"Last time the shared dashboard was viewed","provider":"go.mondoo.com/mql/providers/datadog"},"publicUrl":{"name":"publicUrl","type":"\u0007","is_mandatory":true,"title":"Public URL serving the shared dashboard","provider":"go.mondoo.com/mql/providers/datadog"},"shareType":{"name":"shareType","type":"\u0007","is_mandatory":true,"title":"Share type","desc":"One of open, when anyone with the link may view the dashboard without a Datadog account; invite, when access is limited to the addresses in invitees; embed, when the dashboard is framed by the sites in embeddableDomains; or secure-embed, when an embedded dashboard also requires a signed token.","provider":"go.mondoo.com/mql/providers/datadog"},"sharer":{"name":"sharer","type":"\u001bdatadog.user","title":"User that created the share","desc":"Null when the sharing account has been removed from the organization.","provider":"go.mondoo.com/mql/providers/datadog"},"sharerDisabled":{"name":"sharerDisabled","type":"\u0004","is_mandatory":true,"title":"Whether the account that created the share has been disabled","desc":"A share created by a disabled account keeps serving the dashboard, so it outlives the access of the person who published it.","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Share status","desc":"One of active or paused. A paused share keeps its URL but stops serving the dashboard.","provider":"go.mondoo.com/mql/providers/datadog"},"title":{"name":"title","type":"\u0007","is_mandatory":true,"title":"Dashboard title","provider":"go.mondoo.com/mql/providers/datadog"},"token":{"name":"token","type":"\u0007","is_mandatory":true,"title":"Share token","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Shared Dashboard","desc":"Public or invite-only share of a dashboard, exposing its telemetry outside the Datadog organization through a generated URL. A share with `shareType` open serves the dashboard to anyone holding the link and needs no Datadog account, so it is the strongest exposure signal on a dashboard; invite shares restrict access to the addresses in `invitees`. The `token` selects the share and forms the tail of `publicUrl`. Use `status` to tell live shares from paused ones, `expiration` to find shares that never lapse, and `embeddableDomains` to see which sites may frame the dashboard.","min_provider_version":"13.0.21","defaults":"token shareType status","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.slo":{"id":"datadog.slo","name":"datadog.slo","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"createdBy":{"name":"createdBy","type":"\u001bdatadog.user","title":"User that created the SLO","desc":"Null when the creator no longer has an account in the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"SLO ID","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"monitorIds":{"name":"monitorIds","type":"\u0019\u0005","is_mandatory":true,"title":"Monitor IDs (for monitor-based SLOs)","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"SLO name","provider":"go.mondoo.com/mql/providers/datadog"},"restrictionPolicy":{"name":"restrictionPolicy","type":"\u001bdatadog.restrictionPolicy","title":"Access control list attached to this SLO","desc":"Null when no restriction policy is set, in which case access follows the organization-wide role permissions.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"targetThreshold":{"name":"targetThreshold","type":"\u0006","is_mandatory":true,"title":"Target threshold (percentage, e.g., 99.9)","provider":"go.mondoo.com/mql/providers/datadog"},"timeframe":{"name":"timeframe","type":"\u0007","is_mandatory":true,"title":"Timeframe (7d, 30d, 90d)","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"SLO type (metric, monitor, time_slice)","provider":"go.mondoo.com/mql/providers/datadog"},"warningThreshold":{"name":"warningThreshold","type":"\u0006","is_mandatory":true,"title":"Warning threshold (percentage)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Service Level Objective","desc":"Service Level Objective that tracks a reliability or performance target for a service over a rolling window, letting you audit which services have SLOs defined and how strict their commitments are. The `type` field distinguishes metric, monitor, and time_slice SLOs; monitor-based SLOs reference their underlying monitors through `monitorIds`. The `targetThreshold` and `warningThreshold` percentages together with `timeframe` capture the reliability budget being promised.","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.syntheticsGlobalVariable":{"id":"datadog.syntheticsGlobalVariable","name":"datadog.syntheticsGlobalVariable","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Variable ID","provider":"go.mondoo.com/mql/providers/datadog"},"isFido":{"name":"isFido","type":"\u0004","is_mandatory":true,"title":"Whether the variable is a FIDO variable","provider":"go.mondoo.com/mql/providers/datadog"},"isTotp":{"name":"isTotp","type":"\u0004","is_mandatory":true,"title":"Whether the variable is a Time-based One-Time Password (TOTP/MFA) variable","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Variable name","provider":"go.mondoo.com/mql/providers/datadog"},"parseTestPublicId":{"name":"parseTestPublicId","type":"\u0007","is_mandatory":true,"title":"Parse test public ID (source test)","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Synthetics Global Variable","desc":"Reusable value that can be shared and referenced across multiple Datadog Synthetics tests, letting one definition supply data such as credentials, hostnames, or tokens to many tests. The `isTotp` and `isFido` flags mark variables that carry multi-factor authentication material (Time-based One-Time Password and FIDO), which is worth auditing since those variables hold sensitive secrets. When the value is derived from another test, `parseTestPublicId` identifies that source test.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.syntheticsPrivateLocation":{"id":"datadog.syntheticsPrivateLocation","name":"datadog.syntheticsPrivateLocation","fields":{"description":{"name":"description","type":"\u0007","title":"Description of the private location","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Location ID","provider":"go.mondoo.com/mql/providers/datadog"},"metadata":{"name":"metadata","type":"\n","title":"Private-location metadata","desc":"Dict with a single `restrictedRoles` key: the list of role IDs allowed to use this private location. Empty when the location is not restricted to specific roles.","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Location name","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","title":"Tags applied to the private location","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Synthetics private location","desc":"A Synthetics private location: a customer-managed worker that runs synthetics tests from inside a private network, so internal endpoints unreachable from Datadog's public infrastructure can still be monitored. Auditing these tells you which internal surfaces are under test and, through `metadata`, which roles are permitted to attach tests to the location.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.syntheticsTest":{"id":"datadog.syntheticsTest","name":"datadog.syntheticsTest","fields":{"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Request configuration","desc":"Request under test. Keys: `method` (HTTP method, for example GET or POST) and `url` (the endpoint the test probes).","provider":"go.mondoo.com/mql/providers/datadog"},"createdBy":{"name":"createdBy","type":"\u001bdatadog.user","title":"User that created the test","desc":"Null when the creator no longer has an account in the organization.","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"locations":{"name":"locations","type":"\u0019\u0007","is_mandatory":true,"title":"Locations","provider":"go.mondoo.com/mql/providers/datadog"},"message":{"name":"message","type":"\u0007","is_mandatory":true,"title":"Message (notification text)","provider":"go.mondoo.com/mql/providers/datadog"},"monitorId":{"name":"monitorId","type":"\u0005","is_mandatory":true,"title":"Monitor ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Test name","provider":"go.mondoo.com/mql/providers/datadog"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Execution options","desc":"Scheduling and failure-handling settings. Keys: `tickEvery` (run interval in seconds), `followRedirects` (whether HTTP redirects are followed), and `minFailureDuration` (seconds a failure must persist before the test is marked failing).","provider":"go.mondoo.com/mql/providers/datadog"},"publicId":{"name":"publicId","type":"\u0007","is_mandatory":true,"title":"Public ID","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (live, paused)","provider":"go.mondoo.com/mql/providers/datadog"},"subtype":{"name":"subtype","type":"\u0007","is_mandatory":true,"title":"Subtype (http, ssl, dns, websocket, tcp, udp, icmp, grpc, multi)","provider":"go.mondoo.com/mql/providers/datadog"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/datadog"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Test type (api, browser)","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Synthetics Test","desc":"Datadog Synthetics test that continuously verifies application availability and performance by probing endpoints or driving browser flows from managed or private locations. The `type` distinguishes lightweight `api` checks from full `browser` tests, while `subtype` selects the protocol being probed. Query `status` and `message` to see whether a test is live and how it alerts, and use `monitorId` to pivot to the backing monitor. Auditing tests confirms that critical user journeys and public endpoints are monitored for uptime and regressions.","min_provider_version":"13.0.1","defaults":"publicId name type","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.team":{"id":"datadog.team","name":"datadog.team","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/datadog"},"handle":{"name":"handle","type":"\u0007","is_mandatory":true,"title":"Team handle (slug)","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Team ID","provider":"go.mondoo.com/mql/providers/datadog"},"members":{"name":"members","type":"\u0019\u001bdatadog.user","title":"Users that belong to the team","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"modifiedAt":{"name":"modifiedAt","type":"\t","is_mandatory":true,"title":"Modified at","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Team name","provider":"go.mondoo.com/mql/providers/datadog"},"userCount":{"name":"userCount","type":"\u0005","is_mandatory":true,"title":"User count","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog Team","desc":"Group of Datadog users organized for ownership, on-call rotation, and access control. Teams tie people to the resources they are responsible for, so auditing them shows who owns what and how membership is scoped. The `handle` is the team's URL slug, `userCount` reports how many members belong to the team, and `members` resolves those members to their user accounts.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/datadog"},"datadog.user":{"id":"datadog.user","name":"datadog.user","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Created at","provider":"go.mondoo.com/mql/providers/datadog"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Disabled","provider":"go.mondoo.com/mql/providers/datadog"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Email address","provider":"go.mondoo.com/mql/providers/datadog"},"handle":{"name":"handle","type":"\u0007","is_mandatory":true,"title":"Handle (username)","provider":"go.mondoo.com/mql/providers/datadog"},"icon":{"name":"icon","type":"\u0007","is_mandatory":true,"title":"Icon URL","provider":"go.mondoo.com/mql/providers/datadog"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"User ID","provider":"go.mondoo.com/mql/providers/datadog"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"User name","provider":"go.mondoo.com/mql/providers/datadog"},"roles":{"name":"roles","type":"\u0019\u001bdatadog.role","title":"Roles assigned to the user","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"serviceAccount":{"name":"serviceAccount","type":"\u0004","is_mandatory":true,"title":"Is service account","provider":"go.mondoo.com/mql/providers/datadog"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (Active, Pending, Disabled)","provider":"go.mondoo.com/mql/providers/datadog"},"teams":{"name":"teams","type":"\u0019\u001bdatadog.team","title":"Teams the user belongs to","min_provider_version":"13.0.21","provider":"go.mondoo.com/mql/providers/datadog"},"title":{"name":"title","type":"\u0007","is_mandatory":true,"title":"Title","provider":"go.mondoo.com/mql/providers/datadog"},"verified":{"name":"verified","type":"\u0004","is_mandatory":true,"title":"Verified","provider":"go.mondoo.com/mql/providers/datadog"}},"title":"Datadog User","desc":"User account belonging to the Datadog organization, covering both human members and service accounts. Use it to audit who has access, spot dormant or unverified accounts, and confirm disabled users have been deactivated. The status field reports Active, Pending, or Disabled, and serviceAccount distinguishes machine identities from people.","min_provider_version":"13.0.1","defaults":"id email status","provider":"go.mondoo.com/mql/providers/datadog"}},"dependencies":{"core":{"id":"go.mondoo.com/mql/providers/core","name":"core"}},"provider_roots":{"go.mondoo.com/mql/providers/datadog":"datadog"}}