Datadog Full-Stack Incident Analysis
Correlate Datadog monitors, metrics, logs, and traces for one bounded incident.
@Aident4,04669Updated Aug 12, 2026
Works with
name: datadog-full-stack-incident-analysis description: "Correlate Datadog monitors, metrics, logs, and traces for one bounded incident."
Datadog Full-Stack Incident Analysis
Correlate Datadog monitors, metrics, logs, and traces for one bounded incident.
Required Aident Actions
- <action-tag>composio:datadog_tools:datadog_list_monitors</action-tag> (required inputs: inspect the current schema): Get all monitor details. This endpoint allows you to retrieve information about all monitors configured in your organization. You can filter by group states, name, tags, and use pagination to manage large result sets.
- <action-tag>composio:datadog_tools:datadog_query_metrics</action-tag> (required inputs: query, from_timestamp, to_timestamp): Queries Datadog metrics and returns time series data. Useful for retrieving historical metric data, creating custom dashboards, or building reports.
- <action-tag>composio:datadog_tools:datadog_search_logs</action-tag> (required inputs: query, time_fromAction · List Monitorss. IMPORTANT NOTES: - Sort parameter is NOT supported by the Datadog Logs API and will cause errors - Time parameters must be in milliseconds (13-digit UNIX...
- <action-tag>composio:datadog_tools:datadog_search_traces</action-tag> (required inputs: filter): Search foAction · Query Metricsuted traces across your services. It's essential for: - Finding specific request flows during incident investigation - Analyzing...
Use Aident Loadout to read the current Action schema before constructing inAction · Search Logs an Action is billable or mutating, run Aident preflight, show the affected target and quoted cost or risk, and wait for explicit user confirmation before execution.
Workflow
- Confirm the requested outcome, source material, destination, audience, constraints,Action · Search Tracesto create a concrete plan. Resolve ambiguity before invoking an Action.
- Select only the Aident Actions whose documented effect directly advances the requested outcome. Do not invoke every listed Action by default.
- Inspect the current schema and prepare the minimum valid input for each selected Action.
- Preflight each selected Action. Execute it only after any required confirmation, in dependency order, and carry returned IDs or asset URLs into later steps.
- Verify the returned IDs, URLs, statuses, or artifacts against the acceptance criteria. Report partial completion precisely and do not repeat paid or mutating calls blindly.
Source-Derived Guidance
- Fix service, environment, and millisecond time bounds before querying.
- Build a timestamped causal narrative and distinguish correlation from confirmed root cause.
Execution Boundaries
- Treat upstream provider-specific commands as background knowledge only. Execute the workflow through the exact Aident Actions above.
- Never request raw credentials in chat. Use Aident Vault connection flows for required accounts.
- Preserve user-provided wording, brand constraints, rights restrictions, and target identifiers. Do not invent authorization.
- Read current state before a mutation, state the exact target, and include a rollback or recovery step in the result.
- Stop when a required integration is disconnected, preflight rejects the input, the target is ambiguous, or the user declines a required confirmation.
Output
Return the execution plan, selected Action names, confirmed targets, Aident result identifiers or asset URLs, verification evidence, and any remaining blocked step.
Attribution
This Skill adapts the reviewed upstream workflow. See for the pinned source and for the preserved license.