Obervability
Services AudiTrace Resources Contact
Book a free audit
Audit domain · 4 checks

Dynatrace RUM audit: real-user monitoring reach and privacy settings

Four checks on the front end — applications with no traffic, session-replay and masking configuration, user-action naming quality, and where real-user data carries personal information it should not.
Book a free audit All 71 checks

What these checks read

Applications and traffic

Every RUM application and its session volume. Applications with no sessions in 90 days still consume licence and still appear in every dropdown.

Masking and session replay

Which applications record sessions, and whether input masking is on where it records.

User-action naming

Action names that carry ids, tokens or query strings, which both explodes cardinality and leaks data into names.

Privacy settings against the data

Whether the configured privacy posture matches what is actually arriving.

Why it matters

RUM has two failure modes and they pull in opposite directions. Applications that were created for a launch and never retired keep consuming quota — 86 of them on the tenant in our case study, none with traffic in 90 days. And applications that are busy tend to record more than anyone intended, because masking defaults are set once, at creation, by whoever created it.
These checks handle both from the same read: the application inventory with its traffic, and the privacy configuration each one carries. Where session replay is on and masking is off, the finding names the application rather than the general risk, because "review your masking settings" is advice and a list of three applications is work.
None of the checks read your users’ session content. They read configuration and volume, which is enough to say whether a problem exists and where.
A finding from a real tenant
RUM applications with no traffic in 90 days
Scale
86
Impact
License and configuration waste
Every finding ships with the source behind it and a CSV of the objects it found, so your team can re-run the check without us.

Questions we get about this domain

Will the audit see our end users’ data?

No. The RUM checks read application configuration, privacy settings and session counts. Where the audit reports a privacy exposure it is describing configuration, not quoting captured content.

Is deleting an unused RUM application safe?

The historical data goes with it, so the report lists them rather than recommending deletion outright. Most teams keep one quarter of history and retire the rest; the finding gives you the traffic history per application so the decision is informed.

The other audit domains

Nineteen domains, 71 checks, one read-only run. Each domain is a page.
FinOps Where the money goes, and what is recoverable Kubernetes Cluster coverage, versions, recurring failures Alerting Whether an incident would actually reach a human Audit log Who changed what, when, and outside business hours Coverage What is monitored, what only looks monitored RUM Real-user monitoring reach and privacy settings Grail Buckets, retention, annualized storage cost Pipelines Ingest processing, masking, drop rules Synthetic Synthetic monitors that pass, fail, or never run Topology Entity detection quality and entity explosion OpenTelemetry OTel sources and dual instrumentation Security Token scopes, expiry, dormant credentials Workflows Automation that fails or never fires Bizevents Business event provider hygiene Dashboards Dashboard inventory Davis Root-cause attribution rate OpenPipeline Route and pipeline resolution SLO SLO definitions that break on re-detection Tagging Environment tagging convention

See what this domain finds on your own tenant.

One read-only run covers all nineteen domains. You keep the report either way.
Book a free audit See how AudiTrace works

Find out what your Obervability is actually doing.

An audit takes one run. The findings take one meeting. What you do with them is up to you.
Certified Dynatrace experts
+1
Send
Obervability
Dynatrace implementation, managed services and support. Every finding comes with the source behind it.
Services
Services AudiTrace Case study
Guides
Dynatrace audit Dynatrace cost optimization Audit case study Articles
Reach us
© 2026 Obervability · All rights reserved.
Privacy Terms of use Accessibility