Obervability
Services AudiTrace Resources Contact
Book a free audit
Audit domain · 3 checks

Dynatrace ingest pipeline audit: processing, masking and drop rules

Three checks on what happens to data on the way in — which pipelines process which sources, where masking is applied, and what is being dropped before anyone can query it.
Book a free audit All 71 checks

What these checks read

Pipeline and source mapping

Which ingest sources are processed by which pipeline, and which are processed by none.

Masking rules

Where personal data is masked at ingest, and which high-volume sources have no masking rule at all.

Drop rules

What is being discarded, by which rule, and how much volume that represents.

Why it matters

Ingest processing is the cheapest place to fix both a cost problem and a privacy problem, and the easiest place to create one. A drop rule written to cut noise during an incident stays in place for years, and nothing downstream reports the absence of data it never received.
The privacy half of this domain produced the most uncomfortable finding in our case study: 50 log sources arriving with email addresses in cleartext, around 30.7 million records a day. Not a breach — an exposure, sitting in a queryable store, with no masking rule in front of it.
These checks read the pipeline configuration and sample volumes; they do not read your log content. Every finding names the source and the rule that should exist, so remediation is a configuration change with a known blast radius rather than a project.
A finding from a real tenant
Log sources with email addresses in cleartext
Scale
50 sources · ~30.7M/day
Impact
GDPR exposure
Every finding ships with the source behind it and a CSV of the objects it found, so your team can re-run the check without us.

Questions we get about this domain

How do you know emails are in the logs without reading them?

The check counts pattern matches at the source level and reports the count and the source. It does not extract, store or transmit the matched values, and the report quotes none of them.

Is masking at ingest enough for GDPR?

It is the control that stops new personal data landing in queryable storage; it does nothing about what is already there, which is a retention question and lands in the Grail domain. We are not lawyers and the report does not offer a legal opinion — it establishes what is arriving, where, and at what rate.

The other audit domains

Nineteen domains, 71 checks, one read-only run. Each domain is a page.
FinOps Where the money goes, and what is recoverable Kubernetes Cluster coverage, versions, recurring failures Alerting Whether an incident would actually reach a human Audit log Who changed what, when, and outside business hours Coverage What is monitored, what only looks monitored RUM Real-user monitoring reach and privacy settings Grail Buckets, retention, annualized storage cost Pipelines Ingest processing, masking, drop rules Synthetic Synthetic monitors that pass, fail, or never run Topology Entity detection quality and entity explosion OpenTelemetry OTel sources and dual instrumentation Security Token scopes, expiry, dormant credentials Workflows Automation that fails or never fires Bizevents Business event provider hygiene Dashboards Dashboard inventory Davis Root-cause attribution rate OpenPipeline Route and pipeline resolution SLO SLO definitions that break on re-detection Tagging Environment tagging convention

See what this domain finds on your own tenant.

One read-only run covers all nineteen domains. You keep the report either way.
Book a free audit See how AudiTrace works

Find out what your Obervability is actually doing.

An audit takes one run. The findings take one meeting. What you do with them is up to you.
Certified Dynatrace experts
+1
Send
Obervability
Dynatrace implementation, managed services and support. Every finding comes with the source behind it.
Services
Services AudiTrace Case study
Guides
Dynatrace audit Dynatrace cost optimization Audit case study Articles
Reach us
© 2026 Obervability · All rights reserved.
Privacy Terms of use Accessibility