Skip to main content
This is an updated and improved version of the Datadog connector! If you’re setting up Datadog with C1 for the first time, you’re in the right place.

Capabilities

This connector can sync secrets and display them on the Inventory page. Organization API keys and service account application keys are synced, issued, and shown as distinct secret kinds: they are two different kinds of API key, not two spellings of one, and a request names which kind it wants. Service account application keys are the default kind. An application key can be issued and revoked through C1 when Sync secrets and Sync service account application keys are both enabled, provided the selected Datadog user is a service account. Datadog does not support an expiration date when creating an application key.
Credential issuance targets a Datadog service account only. C1 re-checks at issuance time that the selected user is still a service account, and refuses to issue against a human user. The issued application key is owned by, and scoped to, that service account.Revoking a service account application key needs the owning service account as well as the key. C1 does not supply it today, so the connector reads it from the key’s own owner record instead. A revoke is refused only when that lookup cannot name an owner either.
‡Organization API key issuance and revocation both require Allow organization API key deletion, which is off by default and is separate from Sync secrets. An organization API key belongs to the whole organization rather than to the person it was issued to, and it cannot be scoped, so C1 will not mint one it has no permission to revoke. With the setting off, organization API keys still sync; they simply cannot be issued or deleted. *Schedules and service account application keys are not enabled by default. Enable Sync schedules for schedules; enable Sync secrets and Sync service account application keys for application keys — Sync secrets alone syncs organization API keys only. †Revoking a service account application key needs the owning service account as well as the key, because Datadog has no delete-by-key-id-alone form for these keys. When the request omits it, the connector looks the owner up from the key and proceeds; a key whose owner cannot be identified is refused rather than guessed at — see the note above.

Connector actions

Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the Perform connector action automation step.

Gather Datadog credentials

Configuring the connector requires you to pass in credentials generated in Datadog. Gather these credentials before you move on.
A user with the Connector Administrator or Super Administrator role in C1 and the Datadog Admin or Datadog standard role in Datadog must perform this task.If your user has a custom Datadog role, make sure it includes User App Keys, User Access Invite, and User Access Manage to create, update, enable, and disable users from C1. If you enable Sync secrets, add API Keys Read to sync organization API keys. Add Service Account Write, which governs syncing, issuing, and revoking service account application keys, only if you also enable Sync service account application keys; add Org App Keys Read alongside it, which the revoke path uses to find the service account that owns a key when the request does not name it. Add API Keys Write and API Keys Delete only if you also enable Allow organization API key deletion; without that setting the connector never creates or deletes an organization API key, so those two permissions are not needed. Service Account Write is required, not optional, once that setting is on: a role that lacks it fails the sync rather than syncing an application-key inventory that is silently missing keys. That is why the setting is off by default — an existing install keeps syncing until the operator grants the permission.

Locate your Datadog site

1
Navigate to the Datadog login screen and make a note of your Datadog site. Valid Datadog sites are datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, datadoghq.eu, ddog-gov.com, and ap1.datadoghq.com.

Create an API key

1
Log into your Datadog account and navigate to User Account > Organizational Settings.
2
Click API Keys and then click + New Key.
3
Enter a name for your new key, such as “C1”, and click Create Key.
4
Copy and save the newly created API key.

Create an application key

1
Navigate back to Organization Settings.
2
Click Application Keys and then click + New Key.
3
Enter a name for your new key, such as “C1”, and click Create Key.
4
Copy and save the newly created application key.
Done. Next, move on to the connector configuration instructions.

Configure the Datadog connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of Datadog credentials generated by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Datadog v2 and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Select your Datadog site from the list.
9
Paste the API key into the API key field.
10
Paste the application key into the Application key field.
11
Optional. Enable Sync secrets to display them on the Inventory page.
12
Optional. Enable Sync service account application keys to sync, issue, and revoke them. It requires the Service Account Write permission, and a role without it fails the whole sync, so it is off by default and Sync secrets alone does not turn it on.Optional. Enable Allow organization API key deletion to let C1 issue and revoke Datadog organization API keys. Leave it off unless you want C1 to be able to delete organization-wide keys; enabling Sync secrets alone does not grant this.
13
Optional. Enable Sync schedules.
14
Click Save.
15
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your Datadog connector is now pulling access data into C1.