-
Notifications
You must be signed in to change notification settings - Fork 513
Improve historical data querying for logs and metrics #905
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
d041c4f
improve evals
aantn 62884c3
Merge branch 'master' into improve-datadog-evals
aantn 53832b5
Update tests/llm/fixtures/test_ask_holmes/91f_datadog_logs_historical…
aantn fbcb21c
fix PR comments
aantn 1f3b16a
Update send_datadog_logs.sh
aantn a380121
Merge branch 'master' into improve-historical-data
aantn d88cb09
fixes
aantn 697f586
evals fix
aantn fd7bff9
Update test_logging_api.py
aantn 9d88421
Merge branch 'master' into improve-historical-data
aantn 127e6a4
fixes
aantn 272d8c4
Merge branch 'master' into improve-historical-data
arikalon1 3be1ca6
add datadog logger instructions
arikalon1 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
43 changes: 43 additions & 0 deletions
43
holmes/plugins/toolsets/datadog/datadog_logs_instructions.jinja2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| ## Datadog Logs Tools Usage Guide | ||
|
|
||
| Before running logs queries: | ||
|
|
||
| ** You are often (but not always) running in a kubernetes environment. So users might ask you questions about kubernetes workloads without explicitly stating their type. | ||
| ** When getting ambiguous questions, use kubectl_find_resource to find the resource you are being asked about! | ||
| ** Find the involved resource name and kind | ||
| ** If you can't figure out what is the type of the resource, ask the user for more information and don't guess | ||
|
|
||
|
|
||
| ### General guideline | ||
| - This toolset is used to read pod logs. | ||
| - Assume the pod should have logs. If logs not found, try to adjust the query | ||
|
|
||
| ### CRITICAL: Pod Name Resolution Workflow | ||
|
|
||
| **When user provides an exact pod name** (e.g., `my-workload-5f9d8b7c4d-x2km9`): | ||
| - FIRST query Datadog directly with that pod name using appropriate tags | ||
| - Do NOT try to verify if the pod exists in Kubernetes first | ||
| - This allows querying historical pods that have been deleted/replaced | ||
|
|
||
| **When user provides a generic workload name** (e.g., "my-workload", "nginx", "telemetry-processor"): | ||
| - First use `kubectl_find_resource` to find actual pod names | ||
| - Example: `kubectl_find_resource` with "my-workload" → finds pods like "my-workload-8f8cdfxyz-c7zdr" | ||
| - Then use those specific pod names in Datadog queries | ||
| - Alternative: Use deployment-level tags when appropriate | ||
|
|
||
| **Why this matters:** | ||
| - Pod names in Datadog are the actual Kubernetes pod names (with random suffixes) | ||
| - Historical pods that no longer exist in the cluster can still have logs in Datadog | ||
| - Deployment/service names alone are NOT pod names (they need the suffix) | ||
|
|
||
| ### Time Parameters | ||
| - Use RFC3339 format: `2023-03-01T10:30:00Z` | ||
| - Or relative seconds: `-3600` for 1 hour ago | ||
| - Defaults to 1 hour window if not specified | ||
|
|
||
| ### Common Investigation Patterns | ||
|
|
||
| **For Pod/Container Metrics (MOST COMMON):** | ||
| 1. User asks: "Show logs for my-workload" | ||
| 2. Use `kubectl_find_resource` → find pod "my-workload-abc123-xyz" | ||
| 3. Query Datadog for pod "my-workload-abc123-xyz" logs |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
File renamed without changes.
File renamed without changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
58 changes: 58 additions & 0 deletions
58
tests/llm/fixtures/test_ask_holmes/91g_datadog_metrics_mismatched_pod/manifest.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,58 @@ | ||
| apiVersion: v1 | ||
| kind: Namespace | ||
| metadata: | ||
| name: orbit-91g | ||
| --- | ||
| apiVersion: v1 | ||
| kind: Secret | ||
| metadata: | ||
| name: orbiter-script | ||
| namespace: orbit-91g | ||
| type: Opaque | ||
| stringData: | ||
|
arikalon1 marked this conversation as resolved.
|
||
| script.sh: | | ||
| #!/bin/sh | ||
| echo "Starting orbiter-monitor pod..." | ||
| # Simulate some CPU and memory usage | ||
| while true; do | ||
| # Consume some CPU with a calculation | ||
| echo "scale=5000; 4*a(1)" | busybox awk 'BEGIN{for(i=0;i<100;i++){}}' 2>/dev/null | ||
| # Sleep to create varying pattern | ||
| sleep 5 | ||
| done | ||
| --- | ||
| apiVersion: apps/v1 | ||
| kind: Deployment | ||
| metadata: | ||
| name: orbiter-monitor | ||
| namespace: orbit-91g | ||
| spec: | ||
|
arikalon1 marked this conversation as resolved.
|
||
| replicas: 1 | ||
| selector: | ||
| matchLabels: | ||
| app: orbiter-monitor | ||
| template: | ||
| metadata: | ||
| labels: | ||
| app: orbiter-monitor | ||
| spec: | ||
| volumes: | ||
| - name: script-volume | ||
| secret: | ||
| secretName: orbiter-script | ||
| defaultMode: 0755 | ||
| containers: | ||
| - name: app | ||
| image: busybox:latest | ||
| command: ["/bin/sh", "-c"] | ||
| args: ["/etc/scripts/script.sh"] | ||
| volumeMounts: | ||
| - name: script-volume | ||
| mountPath: /etc/scripts | ||
| resources: | ||
| requests: | ||
| memory: "256Mi" | ||
| cpu: "100m" | ||
| limits: | ||
| memory: "512Mi" | ||
| cpu: "500m" | ||
37 changes: 37 additions & 0 deletions
37
tests/llm/fixtures/test_ask_holmes/91g_datadog_metrics_mismatched_pod/test_case.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,37 @@ | ||
| description: | | ||
| This test verifies Holmes behavior when Datadog has metrics for a specific pod name | ||
| that doesn't match any existing pods in the cluster. The test sends metrics to Datadog | ||
| for a hardcoded pod name (orbiter-monitor-77aac74f7c-hl4cd) that doesn't exist in the cluster, | ||
| while deploying a real deployment named orbiter-monitor whose pods have different random suffixes. | ||
| Holmes should still be able to query and display the metrics from Datadog even though | ||
| the exact pod name doesn't exist in Kubernetes. | ||
|
|
||
|
arikalon1 marked this conversation as resolved.
|
||
| before_test: | | ||
| # Deploy the deployment to the cluster | ||
| kubectl apply -f manifest.yaml | ||
|
|
||
| # Wait for the pod to be running | ||
| kubectl wait --for=condition=ready pod -l app=orbiter-monitor -n orbit-91g --timeout=60s | ||
|
|
||
| # Send CPU and memory metrics to Datadog using a hardcoded pod name that won't exist | ||
| # This simulates historical data for a pod that may have been deleted/recreated | ||
| bash ../../shared/send_datadog_metrics.sh orbit-91g orbiter-monitor-77aac74f7c-hl4cd orbiter-monitor | ||
|
|
||
| user_prompt: | ||
| - "Show me a cpu graph of the orbiter-monitor-77aac74f7c-hl4cd pod in namespace orbit-91g?" | ||
| - "Show me memory graph for orbiter-monitor-77aac74f7c-hl4cd in orbit-91g" | ||
|
|
||
| expected_output: | | ||
| Output must contain 1 or more embeds in the following format | ||
| <<{"type": "datadogql", "tool_name": "query_datadog_metrics", "random_key": "iD8G"}>> | ||
|
|
||
| random_key may be different than the above example so long as its a random looking key, but all other parameters (type and tool_name) must be as described | ||
|
|
||
| Output must NOT tell the user it doesn't have access to metrics or that they should use another tool | ||
|
|
||
| tags: | ||
| - datadog | ||
|
|
||
| after_test: | | ||
| # Cleanup the deployed resources | ||
| kubectl delete -f manifest.yaml --ignore-not-found=true | ||
9 changes: 9 additions & 0 deletions
9
tests/llm/fixtures/test_ask_holmes/91g_datadog_metrics_mismatched_pod/toolsets.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| toolsets: | ||
| kubernetes/core: | ||
| enabled: true | ||
| datadog/metrics: | ||
| enabled: true | ||
| config: | ||
| dd_api_key: "{{env.DATADOG_API_KEY}}" | ||
| dd_app_key: "{{env.DATADOG_APP_KEY}}" | ||
| site_api_url: "https://api.datadoghq.eu" |
4 changes: 2 additions & 2 deletions
4
tests/llm/fixtures/test_ask_holmes/92_cpu_graph_conversation/conversation_history.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,12 +1,12 @@ | ||
| [ | ||
| { | ||
| "role": "user", | ||
| "content": "Can you show the memory usage of the robusta-runner pod?", | ||
| "content": "Can you show the memory usage of the robusta-runner-78599b764d-f847h pod?", | ||
| "token_count": 510 | ||
| }, | ||
| { | ||
| "role": "assistant", | ||
| "content": "The `robusta-runner` pod in the `default` namespace is running without any OOM (Out of Memory) issues. Memory limits and requests are set to 1Gi. No OOM-related logs were found.", | ||
| "content": "The `robusta-runner-78599b764d-f847h` pod in the `default` namespace is running without any OOM (Out of Memory) issues. Memory limits and requests are set to 1Gi. No OOM-related logs were found.", | ||
|
arikalon1 marked this conversation as resolved.
|
||
| "annotations": [] | ||
| } | ||
| ] | ||
4 changes: 4 additions & 0 deletions
4
tests/llm/fixtures/test_ask_holmes/92_cpu_graph_conversation/test_case.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.