<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: hisatomo futahashi</title>
    <description>The latest articles on DEV Community by hisatomo futahashi (@futahashi).</description>
    <link>https://dev.to/futahashi</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3874488%2F24c4aa88-a385-4dde-bb5d-e673371f0f67.jpg</url>
      <title>DEV Community: hisatomo futahashi</title>
      <link>https://dev.to/futahashi</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/futahashi"/>
    <language>en</language>
    <item>
      <title>Getting Started with Bits Agent Builder: An Introduction and Five Real-World Use Cases</title>
      <dc:creator>hisatomo futahashi</dc:creator>
      <pubDate>Wed, 26 Aug 2026 00:27:31 +0000</pubDate>
      <link>https://dev.to/futahashi/getting-started-with-bits-agent-builder-an-introduction-and-five-real-world-use-cases-3gmp</link>
      <guid>https://dev.to/futahashi/getting-started-with-bits-agent-builder-an-introduction-and-five-real-world-use-cases-3gmp</guid>
      <description>&lt;p&gt;Hi, I'm &lt;a href="https://x.com/futahashi" rel="noopener noreferrer"&gt;@futahashi&lt;/a&gt;, a Principal Engineer at Nulab.&lt;/p&gt;

&lt;p&gt;On August 10, 2026, I gave a talk at &lt;a href="https://datadog-jp.connpass.com/event/389998/" rel="noopener noreferrer"&gt;Japan Datadog User Group Meetup #20&lt;/a&gt; (JDDUG #20) in Sapporo. The topic was "Getting Started with Bits Agent Builder and Real-World Use Cases." Bits Agent Builder is a feature that lets you build custom agents inside Datadog, the observability platform. This post is a digest of that talk.&lt;/p&gt;

&lt;p&gt;On a personal note, the trip was a genuinely rewarding one: I got to return the favor to people who had traveled all the way from Hokkaido to speak in Fukuoka, and I finally met someone from Classmethod whose work I've long admired.&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
        &lt;div class="c-embed__cover"&gt;
          &lt;a href="https://speakerdeck.com/nulabinc/getting-started-with-bits-agent-builder-real-world-use-cases" class="c-link align-middle" rel="noopener noreferrer"&gt;
            &lt;img alt="" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Ffiles.speakerdeck.com%2Fpresentations%2F9e971316ce5b43bcb2857c5e0a42055c%2Fslide_0.jpg%3F40225057" height="810" class="m-0" width="1440"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="c-embed__body"&gt;
        &lt;h2 class="fs-xl lh-tight"&gt;
          &lt;a href="https://speakerdeck.com/nulabinc/getting-started-with-bits-agent-builder-real-world-use-cases" rel="noopener noreferrer" class="c-link"&gt;
            Getting Started with Bits Agent Builder: Real-World Use Cases - Speaker Deck
          &lt;/a&gt;
        &lt;/h2&gt;
          
        &lt;div class="color-secondary fs-s flex items-center"&gt;
            &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fd1eu30co0ohy4w.cloudfront.net%2Fassets%2Ffavicon-bdd5839d46040a50edf189174e6f7aacc8abb3aaecd56a4711cf00d820883f47.png" width="512" height="512"&gt;
          speakerdeck.com
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftyqk9swce47glsug9rka.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftyqk9swce47glsug9rka.jpeg" alt="Speaking at JDDUG #20" width="800" height="600"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why do we need AI agents?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0gaazzhm3xi6x18oxqd5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0gaazzhm3xi6x18oxqd5.png" alt=" " width="800" height="460"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;With the rise of generative AI, work like research, summarization, and writing text or code became something a human could delegate and speed up. Tasks too complex for traditional programming came within reach, and I've genuinely felt the amount of toil — repetitive, automatable manual work — shrink as a result.&lt;/p&gt;

&lt;p&gt;The next thing that matters is expanding the space where AI works autonomously, without waiting for human instructions. That's where agents come in.&lt;/p&gt;

&lt;p&gt;You give an agent a goal, tools, constraints, and trigger conditions. From there, it starts work on its own — not only when a human asks, but when an alert fires or a schedule comes due — making judgment calls as the situation demands, operating tools, and carrying the task through to completion. Chaining together multiple tool operations and processing steps no longer requires assembling a program. In the talk, I described this shift as "growing AI into a worker that acts on its own."&lt;/p&gt;

&lt;p&gt;The work best suited to agents, I think, is work that's too complex for static automation but too repetitive for a person to handle every single time. Handing that work off means humans no longer carry every task themselves, and can spend their time on higher-value activities: prioritization, decision-making, communicating with people, and improving the systems around them. The goal isn't simply to make work faster — it's to free humans from the work itself.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is Bits Agent Builder?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0a1l3zs54t27beg4kj1n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0a1l3zs54t27beg4kj1n.png" alt=" " width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Bits Agent Builder is a custom AI agent that runs inside Datadog, and it became generally available in June 2026. I see three strengths as distinctive:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Rich context&lt;/strong&gt;: It can use Datadog's rich data — logs, metrics, traces — directly.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Diverse tools&lt;/strong&gt;: Roughly 3,000 actions, around 50 services, and 4 MCPs. It can operate AWS, Kubernetes, GitHub, Slack, and more.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Flexible triggers&lt;/strong&gt;: It can be started from around 30 sources, including Workflows, Monitors, and Incidents.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In one sentence: it's an AI agent that runs on Datadog and uses the power of a unified observability platform to move your organization's operations forward.&lt;/p&gt;

&lt;p&gt;Unlike an AI agent you fire up ad hoc on your local machine, this one is hosted on Datadog — so the data collected on the platform, the integrations you've already configured, and the wide range of triggers are all shared and reused across the team. Because it runs without depending on any individual's environment, you can make it a durable part of how your organization operates.&lt;/p&gt;

&lt;h2&gt;
  
  
  Four building blocks for creating and improving an agent
&lt;/h2&gt;

&lt;p&gt;There are three ways to create an agent: from a prompt, from a Blueprint, or from scratch. Once created, you configure and improve it using four building blocks:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Instructions&lt;/strong&gt;: What you tell the agent. Its role, its procedures, its constraints.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tools&lt;/strong&gt;: What the agent can use. If you don't give it a tool, it can't use it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Automation&lt;/strong&gt;: When it starts. Schedules, Monitors, Incidents, and so on.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Chat&lt;/strong&gt;: The conversational interface. Run it, debug it, ask it questions.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Beyond these, you can also choose which model the agent uses, depending on the task.&lt;/p&gt;

&lt;p&gt;Instructions aren't something you write once and walk away from. You watch how runs turn out, write down what you learn, and iteratively refine the agent's behavior over time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Use cases
&lt;/h2&gt;

&lt;p&gt;Bits Agent Builder hasn't been GA for long, but here are several agents I've actually run and found effective. I'm only showing the Slack reports here, but Notebook output is also worth trying — it renders as a clean, rich view.&lt;/p&gt;

&lt;h3&gt;
  
  
  Use case 1: Cross-organization monitoring of AWS Commitments, with purchase recommendations
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fudvubuys22q2lsot2mz9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fudvubuys22q2lsot2mz9.png" alt=" " width="800" height="446"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;AWS Commitments (Reserved Instances, Savings Plans, and the like) are AWS's mechanism for granting discounts in exchange for committing to usage up front — a handful of large purchases each year. In an organization running many AWS accounts, the types of commitments, when they were purchased, and when they expire end up scattered across accounts and services.&lt;/p&gt;

&lt;p&gt;If you leave that management to individual teams, the frequency of review and the criteria for renewal decisions vary from team to team. Knowledge of how commitments work and when they apply also varies, so sometimes they aren't even recognized as an option and the opportunity is missed entirely. And when someone transfers to another team or changes roles, the history behind past decisions can disappear with them. Rather than relying on each team's knowledge and attention, you need shared policies and decision criteria, plus a mechanism that manages this continuously across the organization.&lt;/p&gt;

&lt;p&gt;AWS's built-in features do surface expiration dates, utilization rates, and purchase recommendations. But organization-wide visibility lives in the management account, and a member account can generally only see its own information. Cross-account investigation requires the right permissions, and tracing actual usage across accounts means bouncing between multiple screens. Pulling all that together, layering your own company's policies on top, deciding what to renew and what to let expire, and getting that decision to the right person — doing all of that end to end with AWS features alone is not straightforward.&lt;/p&gt;

&lt;p&gt;So I built an agent that monitors commitments across the entire organization against the same criteria. If all you want is a list, a script is enough. What I delegated to the agent was the &lt;em&gt;judgment&lt;/em&gt;: taking usage and organizational policy into account, separating what it recommends renewing from what it doesn't, and reporting to Slack along with the reasoning behind each call. The value here is that finding these opportunities and continuing to review and decide becomes a shared organizational process, rather than something that depends on having a commitments expert or on any one team's effort.&lt;/p&gt;

&lt;h3&gt;
  
  
  Use case 2: Cross-organization cost trend analysis (Datadog and AWS spend)
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1j8lmbhcyfgfkwwza1jf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1j8lmbhcyfgfkwwza1jf.png" alt=" " width="799" height="444"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv1vfkjay7a46dclzmtbp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fv1vfkjay7a46dclzmtbp.png" alt=" " width="800" height="444"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Datadog and AWS costs span multiple accounts, services, and teams. If each team only reviews its own slice, the comparison windows and the thresholds for "this looks abnormal" won't line up, and changes that cross team boundaries can slip through. Rather than leaving continuous monitoring to individual teams, it's important to watch across the whole organization with the same lens and the same cadence, as shared work.&lt;/p&gt;

&lt;p&gt;So when an anomaly appears in Datadog or AWS cost trends, I have an agent analyze it. Seeing that a bill went up or down is something an invoice or dashboard can tell you; the hard part is judging &lt;em&gt;why&lt;/em&gt; it changed and &lt;em&gt;whether&lt;/em&gt; it's a change that needs action. When this agent finds an abnormal cost trend, it doesn't stop there — it follows the related data and investigates the cause.&lt;/p&gt;

&lt;p&gt;For Datadog cost analysis, it compares daily usage against the prior period to distinguish a temporary fluctuation from a real increase. For AWS cost analysis, it correlates telemetry, events, and logs alongside billing data, pinpointing the resources driving the increase down to the ID or ARN level. I find real value in getting insights that billing data alone could never produce.&lt;/p&gt;

&lt;p&gt;What comes back from the agent isn't just the trend, but the insights from its investigation in a consistent format: likely reasons for the increase, the services and resources involved, and the evidence behind its conclusions. Because cross-organization monitoring and initial investigation are guaranteed by the system, whether an investigation happens at all — and how good it is — no longer depends on which team happens to have spare capacity. The people running cross-cutting operations, and the teams that need to act, can skip chasing data point by point and focus on verifying the identified cause and deciding what to do.&lt;/p&gt;

&lt;h3&gt;
  
  
  Use case 3: A scribe for incident response
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgl1j174lkgd4ti7hl91s.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgl1j174lkgd4ti7hl91s.png" alt=" " width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Ever been asked "so, where are we right now?" in the middle of an incident? This agent takes the incident response conversation and records a summary, a timeline, action items, and responders in our company's own format. Pulling "what happened, and when did we do what" out of an unstructured conversation that's also full of side chatter is exactly the kind of judgment-heavy work you couldn't write as a program. Communication during response becomes structured, and responders can focus on the substance of fixing the incident.&lt;/p&gt;

&lt;p&gt;As an aside, Datadog offers &lt;a href="https://docs.datadoghq.com/incident_response/incident_management/" rel="noopener noreferrer"&gt;Incident Management&lt;/a&gt;, which handles timeline management, postmortem assistance, and more. We haven't adopted it yet, so I used Bits Agent Builder to replicate part of it. I'll skip the details here, but if it sounds relevant to you, it's well worth a look.&lt;/p&gt;

&lt;p&gt;We also use &lt;a href="https://www.datadoghq.com/product/ai/bits-investigation/" rel="noopener noreferrer"&gt;Bits Investigation&lt;/a&gt; (formerly Bits AI SRE) in our incident response. By having multiple agents take over investigation and reporting, we're building an environment where humans can concentrate on directing the response and making decisions.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzuih6ps4gl6nbl9z4wsx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzuih6ps4gl6nbl9z4wsx.png" alt=" " width="800" height="443"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;For more on how we use Bits Investigation and what's changed with it, see my earlier talk, "&lt;a href="https://speakerdeck.com/nulabinc/the-evolution-of-bits-ai-sre" rel="noopener noreferrer"&gt;The Evolution of Bits AI SRE, Me, and My Organization&lt;/a&gt;."&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
        &lt;div class="c-embed__cover"&gt;
          &lt;a href="https://speakerdeck.com/nulabinc/the-evolution-of-bits-ai-sre" class="c-link align-middle" rel="noopener noreferrer"&gt;
            &lt;img alt="" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Ffiles.speakerdeck.com%2Fpresentations%2F65c5e37b7c604f22b96c32311d647ed7%2Fslide_0.jpg%3F38697213" height="810" class="m-0" width="1440"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="c-embed__body"&gt;
        &lt;h2 class="fs-xl lh-tight"&gt;
          &lt;a href="https://speakerdeck.com/nulabinc/the-evolution-of-bits-ai-sre" rel="noopener noreferrer" class="c-link"&gt;
            The_Evolution_of_Bits_AI_SRE.pdf - Speaker Deck
          &lt;/a&gt;
        &lt;/h2&gt;
          
        &lt;div class="color-secondary fs-s flex items-center"&gt;
            &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fd1eu30co0ohy4w.cloudfront.net%2Fassets%2Ffavicon-bdd5839d46040a50edf189174e6f7aacc8abb3aaecd56a4711cf00d820883f47.png" width="512" height="512"&gt;
          speakerdeck.com
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


&lt;h3&gt;
  
  
  Use case 4: Security Signal triage
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0ohyhem1txq00if9509o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0ohyhem1txq00if9509o.png" alt=" " width="800" height="442"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffi6egs1am8w349vi2og6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffi6egs1am8w349vi2og6.png" alt=" " width="800" height="443"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Plenty of security alerts turn out, after investigation, to need no action at all. But you can't know that until you investigate — so every one of them becomes a burden on a human.&lt;/p&gt;

&lt;p&gt;When a Security Signal (Datadog's security event detection) fires, the agent immediately investigates the related information and produces an initial verdict. For example, a signal generated by a burst of AccessDenied errors caused by insufficient permissions was judged as benign — the detection itself was correct, but the activity wasn't malicious — and auto-archived with the reasoning and supporting information attached. Things that can't be confidently declared benign, such as a path traversal detection, get escalated to a human via a Security Case.&lt;/p&gt;

&lt;p&gt;As an aside, Datadog also offers &lt;a href="https://www.datadoghq.com/product/ai/bits-security-analyst/" rel="noopener noreferrer"&gt;Bits Security Analyst&lt;/a&gt;. There are some signals it can't handle yet, though, so we're using Bits Agent Builder partly as a point of comparison. I'll leave the details for another time.&lt;/p&gt;

&lt;h3&gt;
  
  
  Use case 5: WAF log analysis and continuous improvement
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frgligo0dnsezvked7fh9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frgligo0dnsezvked7fh9.png" alt=" " width="800" height="446"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;A WAF isn't something you deploy, configure once, and forget. Writing a perfect rule set that blocks every attack from day one while never affecting legitimate requests is essentially impossible. You have to analyze real logs, confirm your rules are actually working, and improve them continuously. But finding anomalies in a massive volume of logs — while carefully assessing the blast radius so you don't accidentally block legitimate traffic — is far from easy.&lt;/p&gt;

&lt;p&gt;This agent extracts anomalies from WAF logs and prioritizes them, evaluates how effective the existing rules are as defenses, and compiles improvement proposals into a report. The final rule changes are still a human call, made after reviewing the impact on the service; the agent handles the ongoing analysis and proposals. Down the road, this could extend into responding to attacks in real time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Common pitfalls
&lt;/h2&gt;

&lt;p&gt;Here are some mistakes people commonly hit when building agents. To make real failures easy to grasp, I deliberately exaggerated them in the slides.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pitfall 1: Vague instructions produce the wrong procedure
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3p1vqxthcoxmnuomdqv3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3p1vqxthcoxmnuomdqv3.png" alt=" " width="799" height="443"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This one comes from the cost analysis agent in use case 2. I assumed it would look at the cost metrics — instead, it tried to compute the numbers itself from usage volume and unit prices. The lesson: give the agent explicit instructions, and check the evidence behind its output so you can correct errors.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pitfall 2: Context overflow
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmgfdubx9v9ts5jfdiq96.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmgfdubx9v9ts5jfdiq96.png" alt=" " width="800" height="443"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There's a limit to how much information AI can handle at once, and cramming too much processing into a single run leads to unintended behavior or outright errors. The fix is to split the task up and narrow the scope of the output.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we got out of it
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Outcome 1: Work starts moving proactively
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fifu9ksjr9h4913dlmokp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fifu9ksjr9h4913dlmokp.png" alt=" " width="799" height="444"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Previously, a task would arise, a human would notice it, instruct the AI, and check the result. In other words, work sat still until a human noticed it and picked it up. Agents change that ordering. The task itself triggers the agent, which moves first, and what reaches the human is the investigation results and the points that need a decision. When a security signal fires, the initial investigation is already done before I even notice it.&lt;/p&gt;

&lt;p&gt;The value isn't only in reduced hands-on time. Work that had been pushed aside as "we should do this, but nobody has the bandwidth" now starts moving the moment it arises. High-impact decisions stay with humans, but humans no longer carry every first response — they can concentrate on review and decision-making.&lt;/p&gt;

&lt;h3&gt;
  
  
  Outcome 2: Operations become articulated
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F05d91ytsbdzao111h9ti.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F05d91ytsbdzao111h9ti.png" alt=" " width="799" height="443"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Writing Instructions means putting your procedures into words. Ways of working that only existed in someone's head get written down. Once they're in words, the team can review them, improve them, and share the same decision criteria. Operational knowledge that lived with one person becomes an asset the team owns.&lt;/p&gt;

&lt;p&gt;And when the agent doesn't behave as expected, that itself reveals where your own procedures and criteria were ambiguous.&lt;/p&gt;

&lt;h3&gt;
  
  
  Outcome 3: You can start small and grow big
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsr9vulcjn4rn6c401jzp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsr9vulcjn4rn6c401jzp.png" alt=" " width="800" height="444"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;You don't have to hand over all the judgment and execution from day one. Start with a narrow scope and delegate only investigation and recommendations. Humans review the results, and once you're satisfied with the quality, you can gradually expand its permissions and its scope.&lt;/p&gt;

&lt;p&gt;The foundation is the three strengths I mentioned at the start. Because you can reuse the context already collected in Datadog, the integrations already connected, and the flexible triggers, you don't need to stand up a new execution environment every time — you can start small and grow both deeper and wider.&lt;/p&gt;

&lt;h2&gt;
  
  
  Managing usage and cost
&lt;/h2&gt;

&lt;p&gt;In the talk I briefly covered how AI Credits work, and I also got a question from the audience about Bits Agent Builder pricing. Running agents continuously requires visibility into cost, not just capability.&lt;/p&gt;

&lt;p&gt;Bits Agent Builder consumes AI Credits. According to &lt;a href="https://www.datadoghq.com/pricing/?product=ai-credits#products" rel="noopener noreferrer"&gt;Datadog's official pricing page&lt;/a&gt;, a single run averages about 3 credits — but note that actual consumption varies with task complexity and the volume of context the model processes.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://docs.datadoghq.com/ai_agents_console/" rel="noopener noreferrer"&gt;Agent Console&lt;/a&gt; (Preview) gives you a single place to review usage and cost across Datadog's AI agents (including Bits Agent Builder) and coding agents like Claude Code and Cursor. You can analyze usage over time by user, team, and agent, which makes it easy to pinpoint where consumption is running hot.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://docs.datadoghq.com/account_management/billing/ai_credit_limits/" rel="noopener noreferrer"&gt;AI Credit Limits&lt;/a&gt; lets you set monthly caps at both the organization and per-user level. Once a cap is reached, new runs stop — a useful guardrail against unintended charges. Note, though, that these limits are shared across every Datadog AI feature that uses AI Credits, not just Bits Agent Builder, so you'll want to set them with your other usage in mind.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wrapping up
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fof8go0m96z043y7h2uo3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fof8go0m96z043y7h2uo3.png" alt=" " width="799" height="443"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The value of Bits Agent Builder is that it combines the rich context collected in Datadog, your already-connected tools, and a wide range of triggers — and turns complex, judgment-heavy work that humans used to carry into team operations that keep running on their own.&lt;/p&gt;

&lt;p&gt;Three things I hoped to get across in this post:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Agents are a good fit for work that's too complex for static automation and too repetitive for a person to handle every time.&lt;/li&gt;
&lt;li&gt;Bits Agent Builder leverages a unified observability platform to make investigation, judgment, and execution part of how your organization operates.&lt;/li&gt;
&lt;li&gt;Don't aim for perfection from the start — try something small and feed what you learn back into the Instructions, and you can grow it safely.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That said, handing work to AI doesn't make operational expertise unnecessary. Deciding what evidence to base a judgment on, how far execution should be allowed to go, and under what conditions to hand off to a human — those are human decisions. Checking the evidence and quality of the output and continuously reflecting it in the Instructions is what raises an agent's quality.&lt;/p&gt;

&lt;p&gt;I'd love for you to try building a custom agent with Bits Agent Builder to make your own work more efficient — and to share what you learn at a user group. JDDUG is the community for Datadog users, and I help run the Fukuoka side of it. Event announcements go up on the &lt;a href="https://datadog-jp.connpass.com/" rel="noopener noreferrer"&gt;Japan Datadog User Group connpass&lt;/a&gt;, so please join us if you're interested.&lt;/p&gt;

&lt;p&gt;Last but not least: thank you to everyone who organized JDDUG #20, everyone who came and talked with me at the venue, the Classmethod team for hosting us, and everyone at Datadog!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyul8lbhuftstcorgl0xu.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyul8lbhuftstcorgl0xu.jpg" alt=" " width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>datadog</category>
      <category>ai</category>
    </item>
    <item>
      <title>Datadog Archive Search is now GA — A Hands-on Walkthrough with S3</title>
      <dc:creator>hisatomo futahashi</dc:creator>
      <pubDate>Thu, 14 May 2026 13:14:32 +0000</pubDate>
      <link>https://dev.to/futahashi/datadog-archive-search-is-now-ga-a-hands-on-walkthrough-with-s3-5c73</link>
      <guid>https://dev.to/futahashi/datadog-archive-search-is-now-ga-a-hands-on-walkthrough-with-s3-5c73</guid>
      <description>&lt;h2&gt;
  
  
  Introduction
&lt;/h2&gt;

&lt;p&gt;Hi, this is futahashi from Japan. In this post, I'd like to share my experience trying out Datadog Archive Search. Logs are something everyone uses on a daily basis, but they are also notoriously hard to design well and easy to overspend on, so I'm sure many of you will appreciate this update as much as I do.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;A small note before we begin&lt;/strong&gt;: I'm not a native English speaker, so please bear with any awkward phrasing. I've done my best to keep the technical content accurate — feedback and corrections are very welcome.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This article focuses on AWS only.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;You can stream-query archived logs immediately, without Rehydration&lt;/li&gt;
&lt;li&gt;You can also run a Rehydration on top if you need to&lt;/li&gt;
&lt;li&gt;You can narrow the scan by time or attribute&lt;/li&gt;
&lt;li&gt;Pricing is based on the scanned data size&lt;/li&gt;
&lt;li&gt;Each search keeps up to 100k events of search results for 24 hours, for free&lt;/li&gt;
&lt;li&gt;Without Rehydration:

&lt;ul&gt;
&lt;li&gt;No advanced analysis such as aggregations or visualizations&lt;/li&gt;
&lt;li&gt;No references from other features (Dashboard / Notebook / Log Explorer, etc.)&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  What changed
&lt;/h2&gt;

&lt;p&gt;"I want to search for logs from three weeks ago" — but the Log Retention Periods on this environment is only 15 days. Situations like this come up sometimes. To deal with this, we humans have historically had the following options:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;① Run a Rehydrate&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use Datadog Rehydrate feature to index Archived Logs. It runs as a batch process and takes anywhere from minutes to hours before the logs become searchable. Indexing also costs money.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;② Use a different tool (Amazon Athena, etc.)&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use another tool built for analyzing archive logs. You lose Datadog excellent UI, and investigation efficiency drops.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;③ Revisit Log Retention Periods&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;This only takes effect going forward, but depending on the frequency of the use case, revisiting Log Retention Periods is an option. However, the Indexing bill scales with retention, so weighing return on investment is important.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is exactly where the now-GA Archive Search comes in. There is no batch waiting time like Rehydrate — results stream in incrementally. Before you run, you can preview your query against up to 1,000 sample Archive Logs, so you can verify your filter before kicking off a wasted scan. The billing model is also different from Rehydrate: Archive Search charges only for scan, and indexing through Rehydrate is optional. On top of that, each Archive Search keeps up to 100k events of logs for 24 hours, for free. You can search Archive Logs in Datadog quickly, easily, and intelligently, which is a big win both for investigation efficiency and for cost savings.&lt;/p&gt;

&lt;p&gt;To summarize:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Before (Rehydrate only)&lt;/th&gt;
&lt;th&gt;Archive Search&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Log retrieval&lt;/td&gt;
&lt;td&gt;Batched, delayed&lt;/td&gt;
&lt;td&gt;Streaming, fast&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Wait time&lt;/td&gt;
&lt;td&gt;Minutes to hours&lt;/td&gt;
&lt;td&gt;Streamed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Pre-query check&lt;/td&gt;
&lt;td&gt;Not possible&lt;/td&gt;
&lt;td&gt;Verifiable on a 1,000-event sample&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indexing required&lt;/td&gt;
&lt;td&gt;Required&lt;/td&gt;
&lt;td&gt;Optional&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Pricing axis&lt;/td&gt;
&lt;td&gt;Index + Scan&lt;/td&gt;
&lt;td&gt;Scan only (Index only if you Rehydrate)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Retention&lt;/td&gt;
&lt;td&gt;3–180 days&lt;/td&gt;
&lt;td&gt;24h (3–180 days if Rehydrated)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Event count&lt;/td&gt;
&lt;td&gt;No limit&lt;/td&gt;
&lt;td&gt;Up to 100k events per Archive Search, free for 24h&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Example use case&lt;/td&gt;
&lt;td&gt;Investigating Archive Logs beyond 24 hours; needing advanced analysis&lt;/td&gt;
&lt;td&gt;Simply searching Archive Logs; intelligently narrowing logs before Rehydrate&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Overall architecture
&lt;/h2&gt;

&lt;p&gt;Here's an image of Archive Search and the things related to it. This is just my own cheerful mental model, not official information, so please take it as something to give you a feel for how it fits together.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fksyvdljtpwmpib89ekvd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fksyvdljtpwmpib89ekvd.png" alt=" " width="800" height="564"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;① Logs are ingested into Datadog from a Datadog Forwarder, etc.&lt;/li&gt;
&lt;li&gt;② Once logs are ingested, based on the Log Archive config, filtered logs are sent to the S3 bucket used for archiving. At this point, the Role that Datadog uses (usually &lt;code&gt;DatadogIntegrationRole&lt;/code&gt;) needs a policy that grants read/write access to the S3 bucket.&lt;/li&gt;
&lt;li&gt;③ When you run Archive Search, logs are retrieved from the archive S3 and kept in a dedicated Archive Search index for up to 100k events for 24 hours. This index is not accessible from Log Explorer.&lt;/li&gt;
&lt;li&gt;④ If needed, you can Rehydrate to keep the logs in an index that's accessible from Log Explorer.&lt;/li&gt;
&lt;li&gt;Notes

&lt;ul&gt;
&lt;li&gt;⑤ The regular Log Index keeps logs based on a config separate from Log Archive.&lt;/li&gt;
&lt;li&gt;⑥ The reason I draw conventional Rehydration and Rehydration from Archive Search as separate is that, at the moment, Rehydrations triggered from Archive Search don't show up in Historical Views, so they appear to be treated as separate things — and I'm following that.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;h2&gt;
  
  
  Let's try it
&lt;/h2&gt;

&lt;p&gt;Here's what I tried with Archive Search, and what I learned. I'm assuming you're starting from creating a new archive, so if you already have an archive, feel free to skip ahead to the permissions section.&lt;/p&gt;

&lt;h3&gt;
  
  
  S3 bucket and IAM policy
&lt;/h3&gt;

&lt;p&gt;First, if you don't already have an S3 bucket to store the archive logs, create one. The output path for archive logs is configurable, so you can also use an existing suitable bucket.&lt;/p&gt;

&lt;p&gt;Next, attach an S3 read/write policy to the Datadog AWS Integration Role. Below is an example — replace the bucket name and prefix with values appropriate to your environment.&lt;/p&gt;

&lt;p&gt;Example target bucket&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Bucket name: &lt;code&gt;some-datadog-enthusiast-bucket&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Prefix: &lt;code&gt;datadog/logs/&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Example policy to add:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"Version"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2012-10-17"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"Statement"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Sid"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"DatadogUploadAndRehydrateLogArchives"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Allow"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"s3:PutObject"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3:GetObject"&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Resource"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"arn:aws:s3:::some-datadog-enthusiast-bucket/datadog/logs/*"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Sid"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"DatadogRehydrateLogArchivesListBucket"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Allow"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3:ListBucket"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Resource"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"arn:aws:s3:::some-datadog-enthusiast-bucket"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Archive configuration
&lt;/h3&gt;

&lt;p&gt;Create the archive. The fields are as follows:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Archive Name&lt;/strong&gt;: The archive name.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Define Which Data To Forward&lt;/strong&gt;: A filter for which logs to archive.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Set Archive Type&lt;/strong&gt;: The archive type (Amazon S3 / Google Cloud Storage / Azure Storage).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Configure Bucket&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;AWS Account&lt;/strong&gt;: The AWS account and &lt;code&gt;DatadogIntegrationRole&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;S3 bucket&lt;/strong&gt;: The name of the archive S3 bucket.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Storage Class&lt;/strong&gt;: The object class (Standard / Standard IA / Intelligent Tiering / One Zone IA / Glacier IR).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Path (Optional)&lt;/strong&gt;: The output prefix.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;li&gt;

&lt;strong&gt;Advanced Settings&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Compression method&lt;/strong&gt;: The compression method (ZSTD / GZIP).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Encryption Type&lt;/strong&gt;: The encryption type (Default S3 Bucket-Level Encryption / Amazon S3 Managed Keys / AWS Key Management Service).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tags in your Archive&lt;/strong&gt;: A setting to additionally store Datadog Tags with the logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tags on your Rehydrated Logs&lt;/strong&gt;: A setting to add specific tags to Rehydrated logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scan size for your rehydration&lt;/strong&gt;: The setting for the maximum scan size of Rehydration.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;p&gt;With &lt;strong&gt;Define Which Data To Forward&lt;/strong&gt;, you can configure a filter for the logs you want to archive, so you can avoid archiving unnecessary logs.&lt;/p&gt;

&lt;p&gt;For &lt;strong&gt;Compression method&lt;/strong&gt;, ZSTD is recommended when your goal is Archive Search or Rehydrate, since it reduces scan and egress cost. If you also plan to use other tools, GZIP may be an option as well.&lt;/p&gt;

&lt;p&gt;You can also specify &lt;strong&gt;Storage Class&lt;/strong&gt; and &lt;strong&gt;Encryption Type&lt;/strong&gt;, which lets you optimize cost and apply appropriate security for your environment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frt5fbwtaqt6s0m7runxo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frt5fbwtaqt6s0m7runxo.png" alt=" " width="800" height="299"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frhdownmcp4a3886jwdfr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frhdownmcp4a3886jwdfr.png" alt=" " width="800" height="362"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F03s5suv6hhgezsbtax2w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F03s5suv6hhgezsbtax2w.png" alt=" " width="800" height="324"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;By running &lt;strong&gt;Test Configuration&lt;/strong&gt;, you can verify whether the role has the appropriate read/write permissions on the configured bucket.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fazx4n1zcpw227qbzqcku.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fazx4n1zcpw227qbzqcku.png" alt=" " width="800" height="304"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In addition, there are settings called &lt;strong&gt;Partition Attributes&lt;/strong&gt; and &lt;strong&gt;Lookup Attributes&lt;/strong&gt;, which are currently in Preview. These are said to reduce scan size by splitting data into directory hierarchies by attribute, or by skipping unneeded data blocks. I haven't applied for the Preview and couldn't try them out, so I'm leaving them out of this post.&lt;/p&gt;

&lt;h3&gt;
  
  
  Permissions
&lt;/h3&gt;

&lt;p&gt;To run Archive Search, two kinds of permissions are required. Make sure to grant the necessary permissions for usage.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;① &lt;strong&gt;Logs Write Historical Views&lt;/strong&gt;: Required to run Archive Search&lt;/li&gt;
&lt;li&gt;② &lt;strong&gt;Logs Read Archive&lt;/strong&gt;: Required to read the archive&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;code&gt;Datadog Admin Role&lt;/code&gt; and &lt;code&gt;Datadog Standard Role&lt;/code&gt; carry both of these permissions, but &lt;code&gt;Datadog Read Only Role&lt;/code&gt; only has Logs Read Archive — please be careful. Also, Archive Search results have &lt;a href="https://docs.datadoghq.com/logs/guide/logs-rbac/?tab=ui#restrict-access-to-logs" rel="noopener noreferrer"&gt;Restriction Queries&lt;/a&gt; applied, so only logs you're allowed to view will be shown. That's reassuring!&lt;/p&gt;

&lt;h3&gt;
  
  
  Running Archive Search
&lt;/h3&gt;

&lt;p&gt;From the Datadog left-hand menu, open Logs and switch to the &lt;strong&gt;Archive Search&lt;/strong&gt; tab. On this screen, you can configure Archive Search, see a list of past Archive Searches, and start a new Archive Search. You can start one with the &lt;strong&gt;New Search&lt;/strong&gt; button.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxw9eqixyey1fmjlnynam.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxw9eqixyey1fmjlnynam.png" alt=" " width="800" height="305"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;By the way, in the settings, you can configure the &lt;strong&gt;Rehydration volume limit&lt;/strong&gt; and &lt;strong&gt;Rehydration retention periods&lt;/strong&gt; as shown below.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxqsxe5qgfu921uu832oz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxqsxe5qgfu921uu832oz.png" alt=" " width="800" height="594"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Next, to choose what to search, fill in the following:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Archive Name&lt;/strong&gt;: Specify the target archive.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Filter (Optional)&lt;/strong&gt;: Optionally specify a filter.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timeframe&lt;/strong&gt;: The target time range.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Mode&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;① &lt;strong&gt;Search&lt;/strong&gt;: Up to 100,000 events kept for 24 hours, free.&lt;/li&gt;
&lt;li&gt;② &lt;strong&gt;Search &amp;amp; Rehydration&lt;/strong&gt;: 3–180 days of Indexing.&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;p&gt;Specifying a filter lets you keep down the Indexing cost at Rehydration time, and, with Lookup Attributes (currently in Preview), it also enables reductions in scan size.&lt;/p&gt;

&lt;p&gt;For choosing the mode, &lt;strong&gt;Search&lt;/strong&gt; seems good for lightweight searches, and &lt;strong&gt;Search &amp;amp; Rehydration&lt;/strong&gt; for use cases that need complex analysis. Even if you choose &lt;strong&gt;Search&lt;/strong&gt;, you can still Rehydrate afterward, so there's nothing to worry about.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F22mnwg8v6a5ygs5j9le5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F22mnwg8v6a5ygs5j9le5.png" alt=" " width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;By checking &lt;strong&gt;Estimated scan size&lt;/strong&gt;, you can see an estimate of the scan size before you actually run. &lt;strong&gt;Preview Log Sample&lt;/strong&gt; lets you preview up to 1,000 logs from the same partition in the target period. You can click into logs to see details and to validate whether your filter query makes sense. That's a thoughtful touch!&lt;/p&gt;

&lt;p&gt;Pressing &lt;strong&gt;Search&lt;/strong&gt; runs Archive Search.&lt;/p&gt;

&lt;h3&gt;
  
  
  Checking the Archive Search results
&lt;/h3&gt;

&lt;p&gt;Once Archive Search runs, results stream in incrementally and you can quickly search Archive Logs. This is a dedicated Archive Search view, different from Log Explorer. Aggregations and similar analysis aren't available, but filtering is.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwz36wqnkd69zo2rogidd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwz36wqnkd69zo2rogidd.png" alt=" " width="800" height="608"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In addition, you can show/hide columns from &lt;strong&gt;Options&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fw1cynv3jed8xzb25trk7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fw1cynv3jed8xzb25trk7.png" alt=" " width="574" height="694"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;You can run a Rehydration as needed. With Rehydration, you gain the ability to explore and analyze the logs in Log Explorer. If you need complex analysis, or if you need to retain the logs for a certain period, go ahead and Rehydrate.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fybh9wzv6pd5nnfvf2702.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fybh9wzv6pd5nnfvf2702.png" alt=" " width="562" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Both Archive Search and Rehydration results can be referenced from the Archive Search screen anytime within their retention period. For Rehydrated results, a link to Explorer is also generated — another thoughtful touch.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnwkitzg9a5jp6nozctxl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnwkitzg9a5jp6nozctxl.png" alt=" " width="800" height="297"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Notes and caveats
&lt;/h2&gt;

&lt;p&gt;Here are the notes and caveats around using Archive Search.&lt;/p&gt;

&lt;h3&gt;
  
  
  ① No aggregations / visualizations / integration with other features
&lt;/h3&gt;

&lt;p&gt;Archive Search provides a dedicated view that's different from Log Explorer. Here, group-by aggregations, visualizations like pie charts, and integrations with other Datadog features (Dashboard / Notebook / Log Explorer, etc.) are not available. If you want any of those, you'll need to run the Rehydration option to perform Indexing.&lt;/p&gt;

&lt;h3&gt;
  
  
  ② Scan appears to run at the same S3 path level
&lt;/h3&gt;

&lt;p&gt;Archives have the following structure, and the &lt;code&gt;hour&lt;/code&gt; directory contains multiple compressed files:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;dt=YYYYMMDD/hour=HH/archive_*****&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;I couldn't find this documented officially, but the scan behavior looks like it operates at the same S3 path level. In other words, all the compressed data for one hour is in scope for the scan. As an extreme example, scanning 00:00–00:01 and scanning 00:00–00:59 have the same scan size, and 00:59–01:00 would be twice that size. As a workaround, you could split your archives based on the ranges you query most often, but in practice that's painful, so I'm looking forward to Partition Attributes and Lookup Attributes.&lt;/p&gt;

&lt;h3&gt;
  
  
  ③ Query Preview is a 1,000-event sample
&lt;/h3&gt;

&lt;p&gt;Query Preview samples appear to show 1,000 archive samples from the same partition that falls within the Timeframe you specified. As mentioned above, partitions are split at the hourly level, so these are 1,000 samples within an hour-sized window. Treat Preview as a feature for validating query syntax and confirming the archive structure — don't misread a zero-result preview as meaning "no matches for that time."&lt;/p&gt;

&lt;h3&gt;
  
  
  ④ Scan stops at 100k events
&lt;/h3&gt;

&lt;p&gt;Archive Search scans stop at 100,000 events per scan. To retrieve everything within a specified range, you'll need to use the results to exclude unneeded logs via a filter, or narrow the timeframe, so the result fits within 100k events, then re-run.&lt;/p&gt;

&lt;p&gt;When re-running, the Clone feature is handy. The form gets pre-filled with the original search's filter and timeframe, so you can tweak only what you need and re-submit.&lt;/p&gt;

&lt;h3&gt;
  
  
  ⑤ Cloud-side retrieval and transfer costs are billed separately
&lt;/h3&gt;

&lt;p&gt;In addition to Datadog's scan-based billing, retrieval from S3 cold storage and egress to Datadog are billed by your cloud provider.&lt;/p&gt;

&lt;h3&gt;
  
  
  ⑥ Archive config does not apply retroactively
&lt;/h3&gt;

&lt;p&gt;Archive config applies only to logs archived after the setting is in place. It does not apply retroactively to logs archived in the past, so it needs to be set up in advance.&lt;/p&gt;

&lt;h2&gt;
  
  
  Pricing
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Overview
&lt;/h3&gt;

&lt;p&gt;The price table below uses the AP1 On-demand prices at the time of writing for reference. For the latest and most accurate information, refer to the official &lt;a href="https://www.datadoghq.com/pricing/?product=log-management" rel="noopener noreferrer"&gt;Datadog Pricing&lt;/a&gt;.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Unit price&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Archive Search&lt;/td&gt;
&lt;td&gt;$0.07 / GB scanned&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Temporary index for Archive Search results&lt;/td&gt;
&lt;td&gt;Free (up to 100k events, 24 hours)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rehydration Scan&lt;/td&gt;
&lt;td&gt;$0.13 / GB scanned&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rehydration Indexing&lt;/td&gt;
&lt;td&gt;Same as Logs Indexing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Logs Ingestion&lt;/td&gt;
&lt;td&gt;$0.13 / GB ingested&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Logs Indexing (15 day retention)&lt;/td&gt;
&lt;td&gt;$3.19 / 1M log events&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Forwarding to S3 / GCS / Azure (archive writes)&lt;/td&gt;
&lt;td&gt;Included in Logs Ingestion&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Archive Search is billed based on scanned data size. At the moment, you reduce scan size via the Archive &amp;amp; Forwarding filter and the Archive Search Timeframe. Once the Lookup Attribute setting (currently in Preview) is available, you'll also be able to reduce scan via the Archive Search filter. There's also an annual contract option for Archive Search, so if you can predict a certain volume of usage, you can get a commit-based discount. Archive Search results — up to 100,000 events — are kept for 24 hours with no Rehydration charge. That's lovely!&lt;/p&gt;

&lt;p&gt;There's no additional charge for writing archive logs. Forwarding to S3 / GCS / Azure Storage is included in the Logs Ingestion price. Forwarding to destinations other than archives, such as external SIEMs and BI vendors, is billed separately, so be careful.&lt;/p&gt;

&lt;p&gt;Rehydration pricing has a two-tier structure. One part scales with the size of the compressed logs scanned. The other is the Indexing cost when you index the matched logs, which follows the same pricing as regular Logs Indexing. Also, as mentioned above, Archive Search's scan price is roughly half the price.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pricing comparison examples
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;① 15 Day Retention&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Assume a service generates 100 GB / 100M log events per month, runs Indexed Logs at 15-day retention, and the data is roughly 10 GB on S3.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Calculation&lt;/th&gt;
&lt;th&gt;Monthly&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ingestion&lt;/td&gt;
&lt;td&gt;100 GB × $0.13&lt;/td&gt;
&lt;td&gt;$13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indexing (15 Day Retention)&lt;/td&gt;
&lt;td&gt;100M × $3.19&lt;/td&gt;
&lt;td&gt;$319&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;$322&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;② 7 Day Retention + Archive Search&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Now consider running Archive Search alongside, so that 7-day retention is enough. Even if you go wild with Archive Search and scan the full 10 GB, the cost is as follows — about a 21% cost reduction. You can see how much of the total cost Indexing accounts for, and how cheap Archive Search is.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Calculation&lt;/th&gt;
&lt;th&gt;Monthly&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ingestion&lt;/td&gt;
&lt;td&gt;100 GB × $0.13&lt;/td&gt;
&lt;td&gt;$13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indexing (7 Day Retention)&lt;/td&gt;
&lt;td&gt;100M × $2.39&lt;/td&gt;
&lt;td&gt;$239&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Archive Search&lt;/td&gt;
&lt;td&gt;10 × $0.07&lt;/td&gt;
&lt;td&gt;$0.70&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;S3 Standard Storage&lt;/td&gt;
&lt;td&gt;10 × $0.025&lt;/td&gt;
&lt;td&gt;$0.25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;S3 Internet Out&lt;/td&gt;
&lt;td&gt;10 × $0.114&lt;/td&gt;
&lt;td&gt;$1.14&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;$254.09&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;③ 7 Day Retention + Archive Search + Rehydration&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Under the same conditions, if you Rehydrate 10% of what Archive Search returned, the Indexing portion grows by 10%, so:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Calculation&lt;/th&gt;
&lt;th&gt;Monthly&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ingestion&lt;/td&gt;
&lt;td&gt;100 GB × $0.13&lt;/td&gt;
&lt;td&gt;$13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indexing (7 Day Retention)&lt;/td&gt;
&lt;td&gt;(100M + 10M) × $2.39&lt;/td&gt;
&lt;td&gt;$262.9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Archive Search&lt;/td&gt;
&lt;td&gt;10 × $0.07&lt;/td&gt;
&lt;td&gt;$0.70&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;S3 Standard Storage&lt;/td&gt;
&lt;td&gt;10 × $0.025&lt;/td&gt;
&lt;td&gt;$0.25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;S3 Internet Out&lt;/td&gt;
&lt;td&gt;10 × $0.114&lt;/td&gt;
&lt;td&gt;$1.14&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;$277.99&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;I went with an extreme example where Archive Search and Rehydration are pushed to the limit, but in practice the scan volume should be much smaller than the full archive, and the Rehydrated index can be kept down further by tuning the time range and queries. You can also pick a shorter Day Retention for Rehydration to make it even cheaper.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wrap-up
&lt;/h2&gt;

&lt;p&gt;In this post, I covered how to use Datadog Archive Search and the caveats to watch out for. This feature solves the conventional Index and Rehydrate pain points around cost and time while still leveraging existing features, and it brings cost reduction and operational efficiency benefits to many users.&lt;/p&gt;

&lt;p&gt;Depending on the use case, you can revisit Log Retention Periods, or even whether you keep logs in Indexed Logs at all, and dramatically cut Indexing cost. It also serves as a clever and inexpensive option as a pre-stage to Rehydrate. You can now narrow down past logs first, then Rehydrate only the parts you actually need.&lt;/p&gt;

&lt;p&gt;I'm looking forward to seeing more cheap, fast, and clever evolutions from Datadog.&lt;/p&gt;

</description>
      <category>datadog</category>
      <category>aws</category>
    </item>
  </channel>
</rss>
