dd-audit-cost-spike-investigation

Correlate Datadog Usage Metering data with Audit Trail changes to identify cost spikes.

150|23|Updated Feb 3, 2026
One-click install
npx skills add https://github.com/datadog-labs/agent-skills --skill dd-audit-cost-spike-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dd-audit-cost-spike-investigation
Source: https://github.com/datadog-labs/agent-skills/tree/main/dd-audit/cost-spike-investigation
Command: npx skills add https://github.com/datadog-labs/agent-skills --skill dd-audit-cost-spike-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps users identify the root cause of cost spikes in Datadog usage by correlating Usage Metering data with Audit Trail configuration changes.

Core Features & Use Cases

  • Correlate Usage Metering & Audit Trail: Link billing data with configuration change history to find the cause of usage spikes.
  • Automated Investigation Workflow: Provides a step-by-step guide to pinpoint the spike, search for configuration changes, and analyze results.
  • Product-Specific Audits: Filter and analyze changes affecting specific Datadog products like LLM Observability, Logs, APM, etc.

Quick Start

Use the dd-audit-cost-spike-investigation skill to identify the cause of a cost spike in your Datadog usage by following the provided investigation workflow.

Frequently Asked Questions about dd-audit-cost-spike-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate Datadog cost spikes using audit trail and usage metering?

Datadog cost spike investigation works by correlating Usage Metering data with Audit Trail configuration changes to find the root cause. It links billing anomalies directly to specific configuration modifications, revealing exactly what triggered the usage increase.

Can I find what configuration changes caused a Datadog usage spike?

Yes, you can find configuration changes causing a Datadog usage spike by correlating Usage Metering data with Audit Trail events. This pinpoints the exact timing of the spike and matches it with configuration modifications to identify the specific changes responsible.

How do I audit cost spikes for specific Datadog products like Logs or APM?

To audit cost spikes for specific Datadog products like Logs or APM, you filter the Audit Trail configuration changes to target those products. This narrows the investigation to only the usage metering and changes relevant to the product experiencing the spike.

Do I need Usage Metering and Audit Trail data access to investigate Datadog billing spikes?

Yes, you need Usage Metering and Audit Trail data access to investigate Datadog billing spikes. The investigation workflow requires querying both datasets to correlate billing anomalies with configuration changes and identify the root cause.

What is the workflow for analyzing Datadog cost spike investigation results?

The workflow for analyzing Datadog cost spike investigation results involves pinpointing the spike in Usage Metering, searching for related Audit Trail configuration changes, and analyzing the correlated results. This step-by-step process isolates the root cause of the cost spike.