Loading...
Loading...
Suggest and validate semantic dictionary (SD) mappings for audit log integrations using raw vendor log payloads or live ingested events. Use when: mapping a vendor audit log feed, authentication logs, user activity logs to the Dynatrace SD; checking required semantic fields; proposing OpenPipeline processor extraction rules based on DQL; running runtime validation (fetches live logs by log.source, then applies static validation).
npx skill4agent add dynatrace/dynatrace-for-ai dt-obs-log-semantic-mappingfetch logslog.source| Class | Description | Key namespaces | Example sources |
|---|---|---|---|
| Login, logout, MFA, token | | CyberArk, Okta, Azure SignInLogs |
| Access decisions, permission changes | | CyberArk, Okta |
| CRUD on platform resources | | Okta, GitHub, Sonatype |
| HTTP request/response (WAF, network devices) | | Akamai SIEM, Cloudflare |
| Mode | Input | Source |
|---|---|---|
| Workflow A — Suggest mapping | Raw vendor log payload | |
| Workflow B1 — Static validation | Pasted ingested log event | |
| Workflow B2 — Runtime validation | | |
contentPrerequisite: When proposing OpenPipeline processor extraction rules, load theskill first. OpenPipeline processors use DQL functions (dt-dql-essentials,parse,fieldsAdd, etc.) — using non-DQL syntax produces invalid rules.splitString
timestamplog.sourcecontentloglevelaudit.actionaudit.identityreferences/data-model-notes.mdreferences/mapping-workflow.mdreferences/validation-rules.mdreferences/openpipeline-constraints.mdparseJsonparsefieldsFlattenreferences/report-format.mdreferences/runtime-validation.mdsamples/audit-logs.jsonsamples/http-logs.json