# Triagic + Dynatrace: ticket investigations over your logs, errors and metrics, read-only

> Dynatrace in Triagic: Run DQL against Grail and read problems, vulnerabilities, exceptions, Kubernetes events and Davis analyzers.

Source: https://triagic.com/integrations/dynatrace

## What you can ask

- Check Dynatrace for errors from the checkout service in the last hour and group them by message
- In Dynatrace, did latency for the import worker change after the 16:02 deploy?
- Find every Dynatrace event that mentions request id 7f3a-…-c2 and put them in order
- Is the alert in Dynatrace for the export queue still firing, and since when?
- What did Dynatrace record for the pod that restarted at 11:31?

## What the agent can do

- `get_environment_info`
- `list_problems`
- `list_vulnerabilities`
- `list_exceptions`
- `find_entity_by_name`
- `get_kubernetes_events`
- `verify_dql`
- `execute_dql`
- `generate_dql_from_natural_language`
- `explain_dql_in_natural_language`
- `chat_with_davis_copilot`
- `list_davis_analyzers`
- `execute_davis_analyzer`

## Connect in three steps

1. **Mint a read-only credential in Dynatrace.** Create a dedicated user or token that can only read. An allowlist of the query and read tools keeps the Slack, email, event and notebook tools out, and the token's read scopes bound the rest.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Dynatrace. Fill in: Environment URL (required): The platform URL, ending in .apps.dynatrace.com. A classic …live.dynatrace.com URL is refused.; Platform token (required): Create one under Dynatrace's identity and access management settings. Give it app-engine:apps:run, the storage:*:read scopes for the data you want reachable (logs, spans, events, metrics, entities, bizevents, security.events, system, buckets, smartscape, files), and the davis-copilot and davis:analyzers scopes if you want those tools. Leave out every write scope. A classic API token (dt0c01.…) won't work.; OAuth client ID (required); OAuth client secret (required): From an OAuth client with the same read scopes as above. Both halves are needed: with only the ID, the server tries to open a browser to sign in.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Dynatrace locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/observability#dynatrace

## Read-only, by construction

An allowlist of the query and read tools keeps the Slack, email, event and notebook tools out, and the token's read scopes bound the rest.

## FAQ

**Can Triagic change anything in Dynatrace?**
No. An allowlist of the query and read tools keeps the Slack, email, event and notebook tools out, and the token's read scopes bound the rest. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Dynatrace?**
Environment URL, Platform token, OAuth client ID, OAuth client secret. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Dynatrace cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [Sentry](https://triagic.com/integrations/sentry)
- [Prometheus](https://triagic.com/integrations/prometheus)
- [OpenSearch](https://triagic.com/integrations/opensearch)
- [Elasticsearch](https://triagic.com/integrations/elasticsearch)
