Datadog Automation via Rube MCP
Automate Datadog monitoring and observability operations through Composio's Datadog toolkit via Rube MCP.
Prerequisites
- Rube MCP must be connected (RUBE_SEARCH_TOOLS available)
- Active Datadog connection via
RUBE_MANAGE_CONNECTIONS with toolkit datadog
- Always call
RUBE_SEARCH_TOOLS first to get current tool schemas
Setup
Get Rube MCP: Add https://rube.app/mcp as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
- Verify Rube MCP is available by confirming
RUBE_SEARCH_TOOLS responds
- Call
RUBE_MANAGE_CONNECTIONS with toolkit datadog
- If connection is not ACTIVE, follow the returned auth link to complete Datadog authentication
- Confirm connection status shows ACTIVE before running any workflows
Core Workflows
1. Query and Explore Metrics
When to use: User wants to query metric data or list available metrics
Tool sequence:
DATADOG_LIST_METRICS - List available metric names [Optional]
DATADOG_QUERY_METRICS - Query metric time series data [Required]
Key parameters:
query: Datadog metric query string (e.g., avg:system.cpu.user{host:web01})
from: Start timestamp (Unix epoch seconds)
to: End timestamp (Unix epoch seconds)
q: Search string for listing metrics
Pitfalls:
- Query syntax follows Datadog's metric query format:
aggregation:metric_name{tag_filters}
from and to are Unix epoch timestamps in seconds, not milliseconds
- Valid aggregations:
avg, sum, min, max, count
- Tag filters use curly braces:
{host:web01,env:prod}
- Time range should not exceed Datadog's retention limits for the metric type
2. Search and Analyze Logs
When to use: User wants to search log entries or list log indexes
Tool sequence:
DATADOG_LIST_LOG_INDEXES - List available log indexes [Optional]
DATADOG_SEARCH_LOGS - Search logs with query and filters [Required]
Key parameters:
query: Log search query using Datadog log query syntax
from: Start time (ISO 8601 or Unix timestamp)
to: End time (ISO 8601 or Unix timestamp)
sort: Sort order ('asc' or 'desc')
limit: Number of log entries to return
Pitfalls:
- Log queries use Datadog's log search syntax:
service:web status:error
- Search is limited to retained logs within the configured retention period
- Large result sets require pagination; check for cursor/page tokens
- Log indexes control routing and retention; filter by index if known
3. Manage Monitors
When to use: User wants to create, update, mute, or inspect monitors
Tool sequence:
DATADOG_LIST_MONITORS - List all monitors with filters [Required]
DATADOG_GET_MONITOR - Get specific monitor details [Optional]
DATADOG_CREATE_MONITOR - Create a new monitor [Optional]
DATADOG_UPDATE_MONITOR - Update monitor configuration [Optional]
DATADOG_MUTE_MONITOR - Silence a monitor temporarily [Optional]
DATADOG_UNMUTE_MONITOR - Re-enable a muted monitor [Optional]
Key parameters:
monitor_id: Numeric monitor ID
name: Monitor display name
type: Monitor type ('metric alert', 'service check', 'log alert', 'query alert', etc.)
query: Monitor query defining the alert condition
message: Notification message with @mentions
tags: Array of tag strings
thresholds: Alert threshold values (critical, warning, ok)
Pitfalls:
- Monitor
type must match the query type; mismatches cause creation failures
message supports @mentions for notifications (e.g., @slack-channel, @pagerduty)
- Thresholds vary by monitor type; metric monitors need
critical at minimum
- Muting a monitor suppresses notifications but the monitor still evaluates
- Monitor IDs are numeric integers
4. Manage Dashboards
When to use: User wants to list, view, update, or delete dashboards
Tool sequence:
DATADOG_LIST_DASHBOARDS - List all dashboards [Required]
DATADOG_GET_DASHBOARD - Get full dashboard definition [Optional]
DATADOG_UPDATE_DASHBOARD - Update dashboard layout or widgets [Optional]
DATADOG_DELETE_DASHBOARD - Remove a dashboard (irreversible) [Optional]
Key parameters:
dashboard_id: Dashboard identifier string
title: Dashboard title
layout_type: 'ordered' (grid) or 'free' (freeform positioning)
widgets: Array of widget definition objects
description: Dashboard description
Pitfalls:
- Dashboard IDs are alphanumeric strings (e.g., 'abc-def-ghi'), not numeric
layout_type cannot be changed after creation; must recreate the dashboard
- Widget definitions are complex nested objects; get existing dashboard first to understand structure
- DELETE is permanent; there is no undo
5. Create Events and Manage Downtimes
When to use: User wants to post events or schedule maintenance downtimes
Tool sequence:
DATADOG_LIST_EVENTS - List existing events [Optional]
DATADOG_CREATE_EVENT - Post a new event [Required]
DATADOG_CREATE_DOWNTIME - Schedule a maintenance downtime [Optional]
Key parameters for events:
title: Event title
text: Event body text (supports markdown)
alert_type: Event severity ('error', 'warning', 'info', 'success')
tags: Array of tag strings
Key parameters for downtimes:
scope: Tag scope for the downtime (e.g., host:web01)
start: Start time (Unix epoch)
end: End time (Unix epoch; omit for indefinite)
message: Downtime description
monitor_id: Specific monitor to downtime (optional, omit for scope-based)
Pitfalls:
- Event
text supports Datadog's markdown format including @mentions
- Downtimes scope uses tag syntax:
host:web01, env:staging
- Omitting
end creates an indefinite downtime; always set an end time for maintenance
- Downtime
monitor_id narrows to a single monitor; scope applies to all matching monitors
6. Manage Hosts and Traces
When to use: User wants to list infrastructure hosts or inspect distributed traces
Tool sequence:
DATADOG_LIST_HOSTS - List all reporting hosts [Required]
DATADOG_GET_TRACE_BY_ID - Get a specific distributed trace [Optional]
Key parameters:
filter: Host search filter string
sort_field: Sort hosts by field (e.g., 'name', 'apps', 'cpu')
sort_dir: Sort direction ('asc' or 'desc')
trace_id: Distributed trace ID for trace lookup
Pitfalls:
- Host list includes all hosts reporting to Datadog within the retention window
- Trace IDs are long numeric strings; ensure exact match
- Hosts that stop reporting are retained for a configured period before removal
Common Patterns
Monitor Query Syntax
Metric alerts:
avg(last_5m):avg:system.cpu.user{env:prod} > 90
Log alerts:
logs("service:web status:error").index("main").rollup("count").last("5m") > 10
Tag Filtering
- Tags use
key:value format: host:web01, env:prod, service:api
- Multiple tags:
{host:web01,env:prod} (AND logic)
- Wildcard:
host:web*
Pagination
- Use
page and page_size or offset-based pagination depending on endpoint
- Check response for total count to determine if more pages exist
- Continue until all results are retrieved
Known Pitfalls
Timestamps:
- Most endpoints use Unix epoch seconds (not milliseconds)
- Some endpoints accept ISO 8601; check tool schema
- Time ranges should be reasonable (not years of data)
Query Syntax:
- Metric queries:
aggregation:metric{tags}
- Log queries:
field:value pairs
- Monitor queries vary by type; check Datadog documentation
Rate Limits:
- Datadog API has per-endpoint rate limits
- Implement backoff on 429 responses
- Batch operations where possible
Quick Reference
| Task |
Tool Slug |
Key Params |
| Query metrics |
DATADOG_QUERY_METRICS |
query, from, to |
| List metrics |
DATADOG_LIST_METRICS |
q |
| Search logs |
DATADOG_SEARCH_LOGS |
query, from, to, limit |
| List log indexes |
DATADOG_LIST_LOG_INDEXES |
(none) |
| List monitors |
DATADOG_LIST_MONITORS |
tags |
| Get monitor |
DATADOG_GET_MONITOR |
monitor_id |
| Create monitor |
DATADOG_CREATE_MONITOR |
name, type, query, message |
| Update monitor |
DATADOG_UPDATE_MONITOR |
monitor_id |
| Mute monitor |
DATADOG_MUTE_MONITOR |
monitor_id |
| Unmute monitor |
DATADOG_UNMUTE_MONITOR |
monitor_id |
| List dashboards |
DATADOG_LIST_DASHBOARDS |
(none) |
| Get dashboard |
DATADOG_GET_DASHBOARD |
dashboard_id |
| Update dashboard |
DATADOG_UPDATE_DASHBOARD |
dashboard_id, title, widgets |
| Delete dashboard |
DATADOG_DELETE_DASHBOARD |
dashboard_id |
| List events |
DATADOG_LIST_EVENTS |
start, end |
| Create event |
DATADOG_CREATE_EVENT |
title, text, alert_type |
| Create downtime |
DATADOG_CREATE_DOWNTIME |
scope, start, end |
| List hosts |
DATADOG_LIST_HOSTS |
filter, sort_field |
| Get trace |
DATADOG_GET_TRACE_BY_ID |
trace_id |
When to Use
This skill is applicable to execute the workflow or actions described in the overview.
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
Source: sickn33/agentic-awesome-skills → skills/datadog-automation/SKILL.md
Also appears in: sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/datadog-automation/SKILL.md, sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/datadog-automation/SKILL.md
1---2name: datadog-automation3description: Automate Datadog tasks via Rube MCP (Composio): query metrics, search logs, manage monitors/dashboards, create events and downtimes. Always search tools first for current schemas.4---567# Datadog Automation via Rube MCP89Automate Datadog monitoring and observability operations through Composio's Datadog toolkit via Rube MCP.1011## Prerequisites1213- Rube MCP must be connected (RUBE_SEARCH_TOOLS available)14- Active Datadog connection via `RUBE_MANAGE_CONNECTIONS` with toolkit `datadog`15- Always call `RUBE_SEARCH_TOOLS` first to get current tool schemas1617## Setup1819**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.2021221. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds232. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `datadog`243. If connection is not ACTIVE, follow the returned auth link to complete Datadog authentication254. Confirm connection status shows ACTIVE before running any workflows2627## Core Workflows2829### 1. Query and Explore Metrics3031**When to use**: User wants to query metric data or list available metrics3233**Tool sequence**:341. `DATADOG_LIST_METRICS` - List available metric names [Optional]352. `DATADOG_QUERY_METRICS` - Query metric time series data [Required]3637**Key parameters**:38- `query`: Datadog metric query string (e.g., `avg:system.cpu.user{host:web01}`)39- `from`: Start timestamp (Unix epoch seconds)40- `to`: End timestamp (Unix epoch seconds)41- `q`: Search string for listing metrics4243**Pitfalls**:44- Query syntax follows Datadog's metric query format: `aggregation:metric_name{tag_filters}`45- `from` and `to` are Unix epoch timestamps in seconds, not milliseconds46- Valid aggregations: `avg`, `sum`, `min`, `max`, `count`47- Tag filters use curly braces: `{host:web01,env:prod}`48- Time range should not exceed Datadog's retention limits for the metric type4950### 2. Search and Analyze Logs5152**When to use**: User wants to search log entries or list log indexes5354**Tool sequence**:551. `DATADOG_LIST_LOG_INDEXES` - List available log indexes [Optional]562. `DATADOG_SEARCH_LOGS` - Search logs with query and filters [Required]5758**Key parameters**:59- `query`: Log search query using Datadog log query syntax60- `from`: Start time (ISO 8601 or Unix timestamp)61- `to`: End time (ISO 8601 or Unix timestamp)62- `sort`: Sort order ('asc' or 'desc')63- `limit`: Number of log entries to return6465**Pitfalls**:66- Log queries use Datadog's log search syntax: `service:web status:error`67- Search is limited to retained logs within the configured retention period68- Large result sets require pagination; check for cursor/page tokens69- Log indexes control routing and retention; filter by index if known7071### 3. Manage Monitors7273**When to use**: User wants to create, update, mute, or inspect monitors7475**Tool sequence**:761. `DATADOG_LIST_MONITORS` - List all monitors with filters [Required]772. `DATADOG_GET_MONITOR` - Get specific monitor details [Optional]783. `DATADOG_CREATE_MONITOR` - Create a new monitor [Optional]794. `DATADOG_UPDATE_MONITOR` - Update monitor configuration [Optional]805. `DATADOG_MUTE_MONITOR` - Silence a monitor temporarily [Optional]816. `DATADOG_UNMUTE_MONITOR` - Re-enable a muted monitor [Optional]8283**Key parameters**:84- `monitor_id`: Numeric monitor ID85- `name`: Monitor display name86- `type`: Monitor type ('metric alert', 'service check', 'log alert', 'query alert', etc.)87- `query`: Monitor query defining the alert condition88- `message`: Notification message with @mentions89- `tags`: Array of tag strings90- `thresholds`: Alert threshold values (`critical`, `warning`, `ok`)9192**Pitfalls**:93- Monitor `type` must match the query type; mismatches cause creation failures94- `message` supports @mentions for notifications (e.g., `@slack-channel`, `@pagerduty`)95- Thresholds vary by monitor type; metric monitors need `critical` at minimum96- Muting a monitor suppresses notifications but the monitor still evaluates97- Monitor IDs are numeric integers9899### 4. Manage Dashboards100101**When to use**: User wants to list, view, update, or delete dashboards102103**Tool sequence**:1041. `DATADOG_LIST_DASHBOARDS` - List all dashboards [Required]1052. `DATADOG_GET_DASHBOARD` - Get full dashboard definition [Optional]1063. `DATADOG_UPDATE_DASHBOARD` - Update dashboard layout or widgets [Optional]1074. `DATADOG_DELETE_DASHBOARD` - Remove a dashboard (irreversible) [Optional]108109**Key parameters**:110- `dashboard_id`: Dashboard identifier string111- `title`: Dashboard title112- `layout_type`: 'ordered' (grid) or 'free' (freeform positioning)113- `widgets`: Array of widget definition objects114- `description`: Dashboard description115116**Pitfalls**:117- Dashboard IDs are alphanumeric strings (e.g., 'abc-def-ghi'), not numeric118- `layout_type` cannot be changed after creation; must recreate the dashboard119- Widget definitions are complex nested objects; get existing dashboard first to understand structure120- DELETE is permanent; there is no undo121122### 5. Create Events and Manage Downtimes123124**When to use**: User wants to post events or schedule maintenance downtimes125126**Tool sequence**:1271. `DATADOG_LIST_EVENTS` - List existing events [Optional]1282. `DATADOG_CREATE_EVENT` - Post a new event [Required]1293. `DATADOG_CREATE_DOWNTIME` - Schedule a maintenance downtime [Optional]130131**Key parameters for events**:132- `title`: Event title133- `text`: Event body text (supports markdown)134- `alert_type`: Event severity ('error', 'warning', 'info', 'success')135- `tags`: Array of tag strings136137**Key parameters for downtimes**:138- `scope`: Tag scope for the downtime (e.g., `host:web01`)139- `start`: Start time (Unix epoch)140- `end`: End time (Unix epoch; omit for indefinite)141- `message`: Downtime description142- `monitor_id`: Specific monitor to downtime (optional, omit for scope-based)143144**Pitfalls**:145- Event `text` supports Datadog's markdown format including @mentions146- Downtimes scope uses tag syntax: `host:web01`, `env:staging`147- Omitting `end` creates an indefinite downtime; always set an end time for maintenance148- Downtime `monitor_id` narrows to a single monitor; scope applies to all matching monitors149150### 6. Manage Hosts and Traces151152**When to use**: User wants to list infrastructure hosts or inspect distributed traces153154**Tool sequence**:1551. `DATADOG_LIST_HOSTS` - List all reporting hosts [Required]1562. `DATADOG_GET_TRACE_BY_ID` - Get a specific distributed trace [Optional]157158**Key parameters**:159- `filter`: Host search filter string160- `sort_field`: Sort hosts by field (e.g., 'name', 'apps', 'cpu')161- `sort_dir`: Sort direction ('asc' or 'desc')162- `trace_id`: Distributed trace ID for trace lookup163164**Pitfalls**:165- Host list includes all hosts reporting to Datadog within the retention window166- Trace IDs are long numeric strings; ensure exact match167- Hosts that stop reporting are retained for a configured period before removal168169## Common Patterns170171### Monitor Query Syntax172173**Metric alerts**:174```175avg(last_5m):avg:system.cpu.user{env:prod} > 90176```177178**Log alerts**:179```180logs("service:web status:error").index("main").rollup("count").last("5m") > 10181```182183### Tag Filtering184185- Tags use `key:value` format: `host:web01`, `env:prod`, `service:api`186- Multiple tags: `{host:web01,env:prod}` (AND logic)187- Wildcard: `host:web*`188189### Pagination190191- Use `page` and `page_size` or offset-based pagination depending on endpoint192- Check response for total count to determine if more pages exist193- Continue until all results are retrieved194195## Known Pitfalls196197**Timestamps**:198- Most endpoints use Unix epoch seconds (not milliseconds)199- Some endpoints accept ISO 8601; check tool schema200- Time ranges should be reasonable (not years of data)201202**Query Syntax**:203- Metric queries: `aggregation:metric{tags}`204- Log queries: `field:value` pairs205- Monitor queries vary by type; check Datadog documentation206207**Rate Limits**:208- Datadog API has per-endpoint rate limits209- Implement backoff on 429 responses210- Batch operations where possible211212## Quick Reference213214| Task | Tool Slug | Key Params |215|------|-----------|------------|216| Query metrics | DATADOG_QUERY_METRICS | query, from, to |217| List metrics | DATADOG_LIST_METRICS | q |218| Search logs | DATADOG_SEARCH_LOGS | query, from, to, limit |219| List log indexes | DATADOG_LIST_LOG_INDEXES | (none) |220| List monitors | DATADOG_LIST_MONITORS | tags |221| Get monitor | DATADOG_GET_MONITOR | monitor_id |222| Create monitor | DATADOG_CREATE_MONITOR | name, type, query, message |223| Update monitor | DATADOG_UPDATE_MONITOR | monitor_id |224| Mute monitor | DATADOG_MUTE_MONITOR | monitor_id |225| Unmute monitor | DATADOG_UNMUTE_MONITOR | monitor_id |226| List dashboards | DATADOG_LIST_DASHBOARDS | (none) |227| Get dashboard | DATADOG_GET_DASHBOARD | dashboard_id |228| Update dashboard | DATADOG_UPDATE_DASHBOARD | dashboard_id, title, widgets |229| Delete dashboard | DATADOG_DELETE_DASHBOARD | dashboard_id |230| List events | DATADOG_LIST_EVENTS | start, end |231| Create event | DATADOG_CREATE_EVENT | title, text, alert_type |232| Create downtime | DATADOG_CREATE_DOWNTIME | scope, start, end |233| List hosts | DATADOG_LIST_HOSTS | filter, sort_field |234| Get trace | DATADOG_GET_TRACE_BY_ID | trace_id |235236## When to Use237This skill is applicable to execute the workflow or actions described in the overview.238239## Limitations240- Use this skill only when the task clearly matches the scope described above.241- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.242- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.243244---245246**Source:** [`sickn33/agentic-awesome-skills`](https://github.com/sickn33/agentic-awesome-skills) → `skills/datadog-automation/SKILL.md`247248**Also appears in:** `sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/datadog-automation/SKILL.md`, `sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/datadog-automation/SKILL.md`