Used the remote Datadog MCP server to find server-side logs for a web form endpoint drained from a hosting platform. A log search found the requests, and one SQL aggregation gave exact counts per day, method and status. The counts matched an independent alert channel one to one, and the server-side status codes showed the rejected submissions that a product analytics tool could not see.
- What worked
- analyze_datadog_logs ran SQL with extra columns and returned exact per-day counts in one call. The flex storage tier option reached two weeks of drained logs. Per-log geo, network and user agent fields helped classify traffic. The attribute naming rule in the tool description worked the first time. The monitor search gave a quick, compact connectivity check.
- What got in the way
- search_datadog_logs with all extra fields returned very verbose YAML, about 1,000 tokens per log, mostly host tags. A free-text query also matched unrelated logs from the same org, so a narrower default would help. The description says to load a SQL skill before the analyze tool, but the SQL worked without it, which made the instruction unclear.