npx skills add ...
npx skills add datadog-labs/agent-skills --skill dd-audit-compliance-report
npx skills add datadog-labs/agent-skills --skill dd-audit-compliance-report
Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output.
Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.
See references/control-mapping.md for the full control → query mapping table and retention requirements by framework.
PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:
If the requested time window exceeds 90 days and no archive is confirmed, surface this gap in the report header.
Same as CC7.2 above. Also include org-level admin actions:
Same as CC6.6 failed logins above.
Datadog Audit Trail covers the Datadog platform as the system being audited. For PCI purposes, this is evidence that the monitoring platform's access controls are functioning — not direct evidence about the cardholder data environment (CDE) itself. Auditors should understand this scope boundary.
pup audit-logs search \
--query "@evt.name:\"Access Management\" @asset.type:user @action:(created OR deleted OR modified)" \
--from PERIOD_START --to PERIOD_END --limit 500 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
actor: .attributes.attributes.usr.email,
action: .attributes.attributes.action,
affected_user: .attributes.attributes.asset.id
}]'pup audit-logs search \
--query "@evt.name:\"Access Management\" @asset.type:role" \
--from PERIOD_START --to PERIOD_END --limit 500 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
actor: .attributes.attributes.usr.email,
action: .attributes.attributes.action,
role_id: .attributes.attributes.asset.id
}]'pup audit-logs search \
--query "@evt.name:Authentication @action:login @status:error" \
--from PERIOD_START --to PERIOD_END --limit 500 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
user: .attributes.attributes.usr.email,
ip: .attributes.attributes.network.client.ip,
country: .attributes.attributes.network.client.geoip.country.name
}]'pup audit-logs search \
--query "@evt.actor.type:SUPPORT_USER" \
--from PERIOD_START --to PERIOD_END --limit 500 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
support_actor: .attributes.attributes.usr.email,
action: .attributes.attributes.action,
resource_type: .attributes.attributes.asset.type,
resource_id: .attributes.attributes.asset.id
}]'pup audit-logs search \
--query "@evt.name:\"Organization Management\"" \
--from PERIOD_START --to PERIOD_END --limit 200 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
actor: .attributes.attributes.usr.email,
action: .attributes.attributes.action,
resource_type: .attributes.attributes.asset.type
}]'pup audit-logs search \
--query "@evt.name:\"Audit Trail\"" \
--from PERIOD_START --to PERIOD_END --limit 200 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
actor: .attributes.attributes.usr.email,
action: .attributes.attributes.action,
resource_type: .attributes.attributes.asset.type
}]'pup audit-logs search \
--query "@evt.name:Authentication @action:login" \
--from PERIOD_START --to PERIOD_END --limit 1000 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
user: .attributes.attributes.usr.email,
auth_method: .attributes.attributes.auth_method,
result: .attributes.attributes.status,
ip: .attributes.attributes.network.client.ip,
country: .attributes.attributes.network.client.geoip.country.name
}]'pup audit-logs search \
--query "@action:(created OR deleted)" \
--from PERIOD_START --to PERIOD_END --limit 1000 -o json \
| jq '[.data[] | {
timestamp: .attributes.timestamp,
user: .attributes.attributes.usr.email,
action: .attributes.attributes.action,
resource_type: .attributes.attributes.asset.type,
resource_id: .attributes.attributes.asset.id,
ip: .attributes.attributes.network.client.ip
}]'# Datadog Audit Trail — Compliance Evidence Report
Framework: [SOC 2 / PCI DSS]
Organization: [org name]
Period: [start] to [end]
Generated: [date]
## Scope Boundary
This report covers administrative actions within the Datadog platform.
It does not cover actions taken within systems that Datadog monitors.
## Retention Status
[✓ Full period covered by Audit Trail retention]
[⚠ Requested period exceeds 90-day default. Archive config required for complete coverage.]
---
## [Control ID] — [Control Name]
Events found: [N]
| Timestamp | Actor | Action | Resource Type | Resource ID | IP | Country |
|-----------|-------|--------|---------------|-------------|-----|---------|
| ... | ... | ... | ... | ... | ... | ... |
[Repeat per control]
---
## Gaps
[List any controls where data was unavailable or incomplete, and why]