深静脉血栓有什么症状| elsevier是什么期刊| 家家酒是什么意思| hot什么意思| 辅助什么意思| 青蛙趴有什么好处| 海洛因是什么| 毛囊炎吃什么药最有效| 狗狗的鼻子为什么是湿的| 顺其自然是什么意思| 胎盘血池是什么意思| 吃什么精力旺盛有精神| 为什么一直不怀孕是什么原因| 口腔上火了吃什么降火最快| 远房亲戚是什么意思| 什么叫走读生| 纳差是什么症状| 血糖高吃什么食物| 提手旁加茶念什么| 79年属什么生肖| 健胃消食片什么时候吃| 属相是什么| 亚麻籽油是什么植物的籽榨出来的| 味淋是什么调料| 什么族不吃猪肉| 什么的诉说| 什么人容易得淋巴癌| 贡菜是什么做的| 四肢冰凉是什么原因| 绰号是什么意思| a是什么单位| 肱骨头小囊变什么意思| 教师节该送什么礼物| 山魈是什么| 今天是什么冲什么生肖| 孤独的最高境界是什么| 满月送什么礼物好| 律动是什么意思| 手掌中间那条线是什么线| 医学上cr是什么意思| 坐骨神经疼有什么症状| 以梦为马什么意思| 大道无为是什么意思| 95年属什么| 治疗褥疮用什么药| 什么绿什么红| 足度念什么| 头疼吃什么好| 万加一笔是什么字| 关节发黑是什么原因| 什么旺土| 性生活过多有什么危害| 鬼门关是什么意思| 830是什么意思| 温暖的近义词是什么| 属猪的守护神是什么菩萨| 脚趾头麻木是什么原因引起的| 智商100属于什么水平| 嘴歪是什么引起的| 胎心停了会有什么症状| 乳腺结节吃什么好| 蜗牛爱吃什么| 三个降号是什么调| 金益什么字| 宝宝手足口病吃什么药| 梦见鱼是什么预兆| 黑吃黑是什么意思| 认贼作父是什么意思| 凤凰长什么样| 为什么会得甲亢| 小便绿色是什么原因| 什么是备皮| 吃什么可以补肾| 老公是什么意思| 食指中指交叉什么意思| 鱼加它是什么字| 造影检查对身体有什么伤害| aosc是什么病| 小学生的学籍号是什么| 补肾吃什么东西效果最好| 屁股长痘痘是什么原因| 馋肉是身体里缺什么| 牵牛花为什么叫牵牛花| 一事无成是什么生肖| 墨西哥用什么货币| 宫颈肥大伴纳氏囊肿是什么意思| 男人要的归属感是什么| 赵字五行属什么| 故宫为什么叫紫禁城| NF什么意思| pass掉是什么意思| 为什么会抽筋| 神经性头疼吃什么药效果好| 猿人头是什么牌子| 五彩斑斓的意思是什么| 梦见吃西红柿是什么意思| 心梗做什么检查| 肌肉僵硬是什么原因引起的| 艾滋病是什么| 肝病吃什么药好得快| 月经提前十天是什么原因| 什么样的大地| eland是什么牌子| 喝酸奶有什么好处| 即使什么也什么| b3是什么维生素| 子宫低回声结节是什么意思| 玫瑰糠疹吃什么药最有效| 油耳是什么意思| 抗糖是什么意思| 一点点奶茶什么最好喝| 肠息肉是什么原因引起的| 直肠下垂有什么症状| 尿有泡沫是什么原因| 一步登天是什么生肖| 同房为什么会出血| 避孕套和安全套有什么区别| 凤凰单丛属于什么茶| 计算机二级什么时候查成绩| 唐氏综合症是什么意思| 痔疮是什么原因| 梦到人死了是什么意思| 6月份有什么节假日| 小饭桌是什么意思| 2016年属什么生肖| 强扭的瓜不甜什么意思| 什么的水珠| LC什么意思| hpv有什么症状| 贫血吃什么药好| 卉是什么意思| 什么工作好| 送什么礼物好| 武松的绰号是什么| 碳酸氢钠是什么添加剂| 浊是什么意思| 2009属什么生肖| 红细胞压积偏高是什么原因| 迷走神经是什么| 什么什么不周| 孕吐一般什么时候开始| 睡不着觉去医院挂什么科| 吃丝瓜有什么好处| 大蒜有什么功效| 2009年属什么生肖| 什么水果含钾高| 属马的女生和什么属相最配| 为什么今年闰六月| 生蚝是什么东西| 扁桃体炎吃什么药最好| 蚂蚁的触角有什么作用| 双肾尿酸盐结晶是什么意思| 什么金属最硬| 骨科什么意思| 吃什么补内膜最快| 心电图诊断窦性心律什么意思| 青菜炒什么好吃| 狗哭了代表什么预兆| 办理港澳通行证需要带什么证件| 蕃秀什么意思| 腿有淤青是什么原因| 六甲什么意思| 如来藏是什么意思| 胆固醇高是什么病| 碳水化合物指的是什么食物| 缺钾最忌讳吃什么| 糖类抗原是检查什么的| 筒骨炖什么好吃| 铁观音什么季节喝最好| 桃子又什么又什么| 唯小人与女子难养也什么意思| 查心梗应该做什么检查| 解解乏是什么意思| 举的部首是什么| 什么的嗓音| 猪八戒叫什么名字| 蚊子咬了为什么会痒| 鸭子炖汤和什么一起炖最有营养| 梦见鼻子出血是什么意思| 喝酒后呕吐是什么原因| 为什么家里有蟑螂| 尿道感染吃什么药| 1901年属什么生肖| 苹果是什么季节的水果| 北京中秋节有什么活动| 平胸是什么原因导致的怎样解决| 90年属马的是什么命| 茯苓的功效与作用是什么| 惊恐是什么意思| 经常自言自语是什么原因| 什么最珍贵| yeezy是什么牌子| 代字五行属什么| 天生一对是什么意思| 金箔是什么| 能力很强的动物是什么| 手背肿胀是什么原因| 说是什么意思| yw是什么| 脚气挂什么科室| 臭虫长什么样| 眼花是什么原因| 肛痈是什么病| 419什么意思| 孕妇熬夜对胎儿有什么影响| 多囊卵巢综合症有什么症状| 7月4是什么星座| 病灶是什么意思| 补充胶原蛋白吃什么最好| 大堤是什么意思| 67年的羊是什么命| 男人右眉毛里有痣代表什么| 感冒流鼻涕吃什么药好得快| 11.23是什么星座| 漱口杯什么材质好| 令香是什么意思| 1988年是什么命| 例假为什么第一天最疼| 热量是什么| 舌头鱼又叫什么鱼| 身体潮湿是什么原因| 什么心什么心| 梦见下小雨是什么征兆| 怎么看自己五行属什么| 液体变固体叫什么| 阴囊潮湿是什么原因| 金匮是什么意思| 半边脸肿是什么原因引起的| 梦见楼塌了是什么意思| 腱鞘炎在什么位置| jerry英文名什么意思| 猎德村为什么那么有钱| 香菇和什么不能一起吃| 8月10号什么星座| 扒拉是什么意思| 头发麻是什么病的前兆| loveyourself什么意思| 做梦梦到搬家什么意思| 寻麻疹是什么| 灰指甲是什么原因引起的| 琪五行属什么| 腰疼吃什么药效果好| 606是什么意思| 血常规检查能查出什么| 头晕吃什么药好| 巴斯光年是什么意思| 机位是什么意思| 7.14是什么日子| 脸色发黄是什么原因| 手心痒是什么原因| 什么人容易得白塞氏病| 上火吃什么最快能降火| 腹部ct平扫能检查出什么| 93年的鸡是什么命| mlb中文叫什么| 孕妇梦见大蟒蛇是什么意思| 吃什么能胖起来| 什么时候做nt| 复试是什么意思| 感冒为什么会头痛| 做雪糕需要什么材料| 肾囊肿有什么危害| 杏林指什么| 彷徨是什么意思| 百度
为什么睡不醒 草莓什么季节种植 怀孕失眠是什么原因 滞纳金是什么意思 取经是什么意思
乳腺回声不均匀是什么意思 3.22是什么星座 龙眼和桂圆有什么区别 插班生是什么意思 心脏疼是什么感觉
7月15日是什么节日 册那是什么意思 湖北有什么山 上海以前叫什么 人为什么会脱发
什么牌子的蓝牙耳机好 健身吃什么长肌肉最快 肝内小钙化灶是什么意思 六月十一号是什么星座 穿旗袍配什么发型好看
四个火读什么hcv9jop5ns1r.cn 生男孩女孩取决于什么bfb118.com 为什么孩子要跟爸爸姓mmeoe.com 灼是什么意思hcv8jop0ns2r.cn 肛门指检是检查什么hcv7jop4ns5r.cn
pgi2在医学是什么意思hcv7jop7ns4r.cn 头发全白是什么病hcv7jop7ns4r.cn 亭字五行属什么hcv9jop4ns0r.cn pcv是什么意思hcv7jop9ns6r.cn 水命中什么水命最好hcv7jop7ns2r.cn
什么什么之财jinxinzhichuang.com 腋下疣是什么原因造成的naasee.com ct是什么单位hcv9jop1ns1r.cn 单病种是什么意思hcv9jop1ns8r.cn 鲜花又什么又什么hcv7jop5ns3r.cn
咽干是什么原因hcv9jop2ns6r.cn 六月初三是什么日子hcv9jop6ns7r.cn 什么食物属于发物hcv9jop0ns8r.cn 95年是什么年hcv9jop7ns2r.cn 优字五行属什么imcecn.com
The Monitor

李克强促多证合一:一季度日增市场主体4万户

百度 针对元宵节期间人员密集场所人员集中、街镇企业相继复工等特点,大兴支队在对辖区重点单位、高层建筑、老旧小区、大型商市场进行监督的基础上,积极对各社区、大型商市场、重点单位微型消防站进行拉动,督促物业管理单位、企业单位做好灭火救灾、应急处置的充分准备,确保关键时刻能“拉得出、冲得上、打得赢”。

5 minute read

Published

Share

Search your historical logs more efficiently with Datadog Archive Search
Zara Boddula

Zara Boddula

Accessing years of archived logs shouldn’t slow down your audits or investigations. Speed is essential because these events are often unpredictable and urgent, coming at any time with tight deadlines and high stakes. But many organizations struggle with historical data stored in separate systems, making it difficult for them to respond quickly and cost-effectively. This data often requires costly rehydration or data movement before queries can begin.

Datadog Archive Search, now available in Preview, helps solve these challenges. With Archive Search, your teams can search in place across archived logs in Flex Frozen or customer-owned cloud storage (like Amazon S3)—no rehydration needed. This functionality reduces cost, operational overhead, and tool switching while accelerating audits and investigations.

In this post, we’ll explain how Archive Search helps you:

Preview and search archived logs without rehydration

Your financial services team might need to trace old transactions to meet regulatory requirements. Or perhaps your security team is investigating a suspected identity provider breach. Maybe your compliance team is auditing infrastructure changes that occurred over the course of multiple years.

Traditional access to these archived logs requires rehydration—restoring data from cold storage into hot storage—or exporting data to separate query platforms. This process can be time-consuming, expensive, and disruptive. It might also require approvals and budgetary planning, which can create additional delays. More importantly, it forces teams to switch contexts and learn different query languages, slowing down investigations and increasing the risk of errors.

With Archive Search, you can preview and search archived logs in Flex Frozen or customer-owned cloud storage without rehydrating or moving the data. Each log preview delivers full context—including log messages, timestamps, attributes, and tags—from the same Datadog query language and interface that you already know. This consistency lets you confidently investigate historical events, drill into anomalies, and filter results without switching tools or waiting for data to move.

As a result, you gain direct visibility into archived logs to help you answer critical questions such as the following:

  • Who initiated the transaction that is the focus of the compliance request?
  • Which API keys were rotated during the last compliance audit?
  • Who accessed sensitive systems, and what actions did they take?
  • When was a noncompliant infrastructure change made, and by whom?
  • How long did a malicious actor maintain access, and what did that user do?
Preview of an archived Okta log.
Reviewing Okta logs within Archive Search.
Preview of an archived Okta log.
Reviewing Okta logs within Archive Search.

Speed up investigations with cross-telemetry and organizational visibility

When you’re investigating a performance issue, security signal, or compliance concern, having all your relevant telemetry data in one place helps you find answers faster. With Archive Search and Datadog Log Workspaces, you can visualize archived logs alongside key data sources—including RUM events, metrics, and Reference Tables—without switching tools or rehydrating data.

For example, let’s say that your security team just identified a security breach and needs to determine who introduced it. Using a log query in a Workspace, the team can pull up archived authentication logs and correlate them with RUM data to understand what actions the user took in the UI (for example, accessing sensitive pages or performing admin actions).

Logs related to a suspicious login.
Investigating authentication logs within Log Workspaces.
Logs related to a suspicious login.
Investigating authentication logs within Log Workspaces.

As another example, let’s say that your trading compliance team is investigating suspicious transaction failures as part of a quarterly audit. Using Archive Search in Log Workspaces, the team can filter for failed transactions across specific countries.

Chart of failed transactions by country. The results are filtered by high value.
Visualizing transaction failures within Log Workspaces.
Chart of failed transactions by country. The results are filtered by high value.
Visualizing transaction failures within Log Workspaces.

The team can then write SQL queries to identify unusual patterns, such as repeated failures linked to a single user or region, and perform joins with reference tables, like Salesforce known risk indicators.

A SQL query as part of an analysis of failed transactions.
Querying with SQL within Log Workspaces.
A SQL query as part of an analysis of failed transactions.
Querying with SQL within Log Workspaces.

After you have investigated the issue, you can use Datadog Sheets to organize and document your findings. You can reference archived log data directly in the spreadsheet, link the data to metrics, add context by using tags and metadata, and share a structured timeline of events across teams.

Spreadsheet for a user activity audit. The sheet includes columns for status, date, country, user name, user team, event name, event outcome, and authentication type.
Documenting findings in Datadog Sheets.
Spreadsheet for a user activity audit. The sheet includes columns for status, date, country, user name, user team, event name, event outcome, and authentication type.
Documenting findings in Datadog Sheets.

From detection to report, this workflow helps reduce context switching, accelerate investigations, and support audit-ready reporting—all with the same query language and interface that you already use in Datadog.

Maintain end-to-end control and visibility of your log data

Long-term visibility into your logs isn’t just about storage. It’s about making sure that the right data is collected, transformed, routed, and made searchable, all while keeping costs and compliance needs in check.

With Datadog Observability Pipelines, you can transform and route your logs as they flow to different vendors, lowering your DevOps and SIEM storage costs. For example, you can send all security-related logs directly to Amazon S3, enriching them with metadata like team ownership or compliance tags before they land in storage. At the same time, you can route application debug logs to a different destination entirely, applying different retention policies based on business needs.

This functionality gives you flexibility and control. But until now, accessing those archived logs meant switching tools or rehydrating data back into hot storage. Archive Search builds on Observability Pipelines by letting you search your archived logs in place. By combining Observability Pipelines and Archive Search, you can build an end-to-end workflow that gives you full control over your log data—from collection to long-term storage to in-place search. You can:

  • Route and transform logs as they’re ingested
  • Store logs in cost-effective long-term destinations
  • Keep logs fully searchable and audit-ready

This approach helps you reduce unnecessary data ingestion into downstream platforms, like SIEMs. As a result, you can focus on the log data that truly matters for compliance, investigations, and performance monitoring—all within Datadog.

A pipeline that sends logs to different destinations.
Using Observability Pipelines to route logs to Amazon S3 and Datadog.
A pipeline that sends logs to different destinations.
Using Observability Pipelines to route logs to Amazon S3 and Datadog.

Whether you’re focused on lowering storage costs, simplifying compliance efforts, accelerating incident response, or improving historical log visibility, Archive Search gives you fast, flexible access to archived data—without the expense and complexity of rehydration. Sign up for the Preview to get started.

If you don’t already have a Datadog account, you can sign up for a .

Related Articles

Migrate from your existing SIEM and quickly onboard security teams with Datadog Cloud SIEM

Migrate from your existing SIEM and quickly onboard security teams with Datadog Cloud SIEM

How to optimize high-volume log data without compromising visibility

How to optimize high-volume log data without compromising visibility

Build compliance, governance, and transparency across your teams with Datadog Audit Trail

Build compliance, governance, and transparency across your teams with Datadog Audit Trail

How we use Datadog to further our FedRAMP? compliance

How we use Datadog to further our FedRAMP? compliance

Start monitoring your metrics in minutes

百度