Skip to content
OpenSmartRoute
Skillv1.0.0

dd-audit-compliance-report

Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output.

by datadog-labs(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from datadog-labs/agent-skills (dd-audit/compliance-report/SKILL.md) via skills.sh. Install upstream with npx skills add datadog-labs/agent-skills --skill compliance-report. Copyright stays with the author.

Audit Trail: Compliance Evidence Report

Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.

Prerequisites

pup auth login   # OAuth2 (recommended)
# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Read First

See references/control-mapping.md for the full control → query mapping table and retention requirements by framework.

Retention Check (Run First)

PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:

pup audit-logs search --query "@evt.name:\"Audit Trail\" @action:modified" --from 90d -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource: .attributes.attributes.asset.type
    }]'

If the requested time window exceeds 90 days and no archive is confirmed, surface this gap in the report header.

Workflow

  1. Confirm: framework (SOC 2 / PCI DSS), time window, org scope
  2. Run retention check
  3. Run each relevant control query
  4. Format output using the Evidence Report template

SOC 2 Queries

CC6.2 — User Provisioning / Deprovisioning

pup audit-logs search \
  --query "@evt.name:\"Access Management\" @asset.type:user @action:(created OR deleted OR modified)" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      affected_user: .attributes.attributes.asset.id
    }]'

CC6.3 — Role and Permission Changes

pup audit-logs search \
  --query "@evt.name:\"Access Management\" @asset.type:role" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      role_id: .attributes.attributes.asset.id
    }]'

CC6.6 — Failed Logins and Suspicious Access

pup audit-logs search \
  --query "@evt.name:Authentication @action:login @status:error" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      ip: .attributes.attributes.network.client.ip,
      country: .attributes.attributes.network.client.geoip.country.name
    }]'

CC7.2 — Privileged / Support User Actions

pup audit-logs search \
  --query "@evt.actor.type:SUPPORT_USER" \
  --from PERIOD_START --to PERIOD_END --limit 500 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      support_actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id
    }]'

PCI DSS Queries

PCI 10.2.2 — Actions by Privileged Users

Same as CC7.2 above. Also include org-level admin actions:

pup audit-logs search \
  --query "@evt.name:\"Organization Management\"" \
  --from PERIOD_START --to PERIOD_END --limit 200 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type
    }]'

PCI 10.2.3 — Access to Audit Trail Itself

pup audit-logs search \
  --query "@evt.name:\"Audit Trail\"" \
  --from PERIOD_START --to PERIOD_END --limit 200 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      actor: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type
    }]'

PCI 10.2.4 — Invalid Access Attempts

Same as CC6.6 failed logins above.

PCI 10.2.5 — All Authentication Events

pup audit-logs search \
  --query "@evt.name:Authentication @action:login" \
  --from PERIOD_START --to PERIOD_END --limit 1000 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      auth_method: .attributes.attributes.auth_method,
      result: .attributes.attributes.status,
      ip: .attributes.attributes.network.client.ip,
      country: .attributes.attributes.network.client.geoip.country.name
    }]'

PCI 10.2.7 — Object Creation and Deletion

pup audit-logs search \
  --query "@action:(created OR deleted)" \
  --from PERIOD_START --to PERIOD_END --limit 1000 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      user: .attributes.attributes.usr.email,
      action: .attributes.attributes.action,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id,
      ip: .attributes.attributes.network.client.ip
    }]'

Evidence Report Template

# Datadog Audit Trail — Compliance Evidence Report
Framework: [SOC 2 / PCI DSS]
Organization: [org name]
Period: [start] to [end]
Generated: [date]

## Scope Boundary
This report covers administrative actions within the Datadog platform.
It does not cover actions taken within systems that Datadog monitors.

## Retention Status
[✓ Full period covered by Audit Trail retention]
[⚠ Requested period exceeds 90-day default. Archive config required for complete coverage.]

---

## [Control ID] — [Control Name]
Events found: [N]

| Timestamp | Actor | Action | Resource Type | Resource ID | IP | Country |
|-----------|-------|--------|---------------|-------------|-----|---------|
| ...       | ...   | ...    | ...           | ...         | ... | ...     |

[Repeat per control]

---

## Gaps
[List any controls where data was unavailable or incomplete, and why]

Scope Caveat

Datadog Audit Trail covers the Datadog platform as the system being audited. For PCI purposes, this is evidence that the monitoring platform's access controls are functioning — not direct evidence about the cardholder data environment (CDE) itself. Auditors should understand this scope boundary.

References

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/datadog-labs-agent-skills-compliance-report/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

datadog-labs-agent-skills-compliance-report.ocm.jsonjson
{
  "ocm": "1",
  "id": "datadog-labs-agent-skills-compliance-report",
  "kind": "skill",
  "name": "dd-audit-compliance-report",
  "description": "Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output.",
  "publisher": "datadog-labs",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "legal",
      "data_analysis"
    ],
    "tags": [
      "skill-md",
      "datadog",
      "audit",
      "compliance",
      "soc2",
      "pci",
      "dd-audit",
      "skills-sh"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "skills.sh",
      "repository": "https://github.com/datadog-labs/agent-skills",
      "path": "dd-audit/compliance-report/SKILL.md",
      "ref": "HEAD",
      "url": "https://www.skills.sh/datadog-labs/agent-skills/dd-audit-compliance-report",
      "key": "datadog-labs/agent-skills/dd-audit/compliance-report/SKILL.md"
    }
  },
  "instructions": "# Audit Trail: Compliance Evidence Report\n\nGenerate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.\n\n## Prerequisites\n\n```bash\npup auth login   # OAuth2 (recommended)\n# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope\n```\n\n## Read First\n\nSee `references/control-mapping.md` for the full control → query mapping table and retention requirements by framework.\n\n## Retention Check (Run First)\n\nPCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:\n\n```bash\npup audit-logs search --query \"@evt.name:\\\"Audit",
  "cost": {
    "context_tokens": 1632
  }
}

Fetch it by URL: GET /api/v1/registry/datadog-labs-agent-skills-compliance-report/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.