Connect Datadog.
Connect Datadog metrics and log aggregates by authorizing Perfloop in Datadog. To include Go CPU profiles, use API and application keys.
Access you need
- provider authorizationAuthorize Perfloop in Datadog to read metrics and log aggregates. Perfloop renews this access automatically.
- API and application keysFor manual setup, create dedicated API and application keys with only the required read permissions. Manual keys support metrics and aggregate logs. For Go CPU profiles, the application key needs the scope continuous_profiler_pgo_read.
- exact tag scopesChoose the services and environments to read with tags such as service:api and env:prod. Each query keeps those filters.
Setup
1 · choose hosted or manual access
In Perfloop Setup, select Datadog. Use provider authorization for metrics and logs. Select manual setup when Go CPU profiles are required.
2 · authorize access
Choose your Datadog site. Select Connect with Datadog, complete consent, and return to Setup. For manual setup, select Use API and application keys and enter the keys.
3 · select scopes and save
Add each metric, log, or profile tag scope that Perfloop may read, then select Save connection. Perfloop checks the selected resources before it saves the connection.
Data Perfloop reads
- Metrics. Metric names, scalar and time-series responses, group tags, units, and provider fields.
- Logs. Log counts and other aggregates for a set time window, including grouping values. Raw log events stay in Datadog.
- Profiles. Go CPU profile inventory and selected pprof data can include labels, stack values, functions, files, and build identifiers.
Query limits
- Hosted authorization does not support profile reads. Use manual keys for Go CPU profiles.
- Each profile read selects up to five captures within a 32 MiB budget. This is a sample of the requested time window; it does not establish complete coverage.
- Metric labels and grouping values can contain sensitive data. Review the tags and fields in the resources you connect.
Credentials and network access
If you enter a token in Setup, your browser sends it to Perfloop over HTTPS. Tokens from provider authorization go directly to Perfloop.
Perfloop encrypts the credential and uses it only for requests within your connection's scope. Models and execution sandboxes do not receive it.
Requests go to the provider's public HTTPS endpoint. Redirects cannot send the credential to another host.
Change or remove access
Authorize Perfloop again or replace the manual connection in Setup to rotate access or change the selected resources. Revoke the OAuth grant or keys in Datadog to stop later reads.
Removing access does not delete connection details or results already stored in Perfloop.
Provider documentation
Security questions: security@perfloop.ai
