Obervability
Services
AudiTrace
Resources▾
Contact
Book a free audit
Audit domain · 4 checks
Dynatrace RUM audit: real-user monitoring reach and privacy settings
Four checks on the front end — applications with no traffic, session-replay and masking configuration, user-action naming quality, and where real-user data carries personal information it should not.
Book a free audit
All 71 checks
What these checks read
Applications and traffic
Every RUM application and its session volume. Applications with no sessions in 90 days still consume licence and still appear in every dropdown.
Masking and session replay
Which applications record sessions, and whether input masking is on where it records.
User-action naming
Action names that carry ids, tokens or query strings, which both explodes cardinality and leaks data into names.
Privacy settings against the data
Whether the configured privacy posture matches what is actually arriving.
Why it matters
RUM has two failure modes and they pull in opposite directions. Applications that were created for a launch and never retired keep consuming quota — 86 of them on the tenant in our case study, none with traffic in 90 days. And applications that are busy tend to record more than anyone intended, because masking defaults are set once, at creation, by whoever created it.
These checks handle both from the same read: the application inventory with its traffic, and the privacy configuration each one carries. Where session replay is on and masking is off, the finding names the application rather than the general risk, because "review your masking settings" is advice and a list of three applications is work.
None of the checks read your users’ session content. They read configuration and volume, which is enough to say whether a problem exists and where.
A finding from a real tenant
RUM applications with no traffic in 90 days
Scale
86
Impact
License and configuration waste
Every finding ships with the source behind it and a CSV of the objects it found, so your team can re-run the check without us.
Questions we get about this domain
Will the audit see our end users’ data?
No. The RUM checks read application configuration, privacy settings and session counts. Where the audit reports a privacy exposure it is describing configuration, not quoting captured content.
Is deleting an unused RUM application safe?
The historical data goes with it, so the report lists them rather than recommending deletion outright. Most teams keep one quarter of history and retire the rest; the finding gives you the traffic history per application so the decision is informed.
The other audit domains
Nineteen domains, 71 checks, one read-only run. Each domain is a page.
FinOps
Where the money goes, and what is recoverable
Kubernetes
Cluster coverage, versions, recurring failures
Alerting
Whether an incident would actually reach a human
Audit log
Who changed what, when, and outside business hours
Coverage
What is monitored, what only looks monitored
RUM
Real-user monitoring reach and privacy settings
Grail
Buckets, retention, annualized storage cost
Pipelines
Ingest processing, masking, drop rules
Synthetic
Synthetic monitors that pass, fail, or never run
Topology
Entity detection quality and entity explosion
OpenTelemetry
OTel sources and dual instrumentation
Security
Token scopes, expiry, dormant credentials
Workflows
Automation that fails or never fires
Bizevents
Business event provider hygiene
Dashboards
Dashboard inventory
Davis
Root-cause attribution rate
OpenPipeline
Route and pipeline resolution
SLO
SLO definitions that break on re-detection
Tagging
Environment tagging convention
See what this domain finds on your own tenant.
One read-only run covers all nineteen domains. You keep the report either way.
Book a free audit
See how AudiTrace works
Find out what your Obervability is actually doing.
An audit takes one run. The findings take one meeting. What you do with them is up to you.
Certified Dynatrace experts
+1
Obervability
Dynatrace implementation, managed services and support. Every finding comes with the source behind it.
Services
Services
AudiTrace
Case study
Guides
Dynatrace audit
Dynatrace cost optimization
Audit case study
Articles
Reach us
Contact
hello@obzervability.com
© 2026 Obervability · All rights reserved.
Privacy
Terms of use
Accessibility
Obervability
{{ t.navServices }}
AudiTrace
{{ resLabel }}▾
{{ t.navContact }}
{{ footGuideAudit }}
{{ footGuideCost }}
{{ footGuideCase }}
{{ footGuideArticles }}
{{ langLabel }} ▾
English
{{ altLabel }}
{{ t.heroKicker }}
{{ t.heroTitle }}
{{ t.heroSub }}
{{ t.heroCta1 }}
{{ t.heroCta2 }}
{{ t.badge }}
71
{{ t.stripChecks }}
19
{{ t.stripDomains }}
21
{{ t.stripRem }}
0
{{ t.stripWrite }}
{{ t.svcTitle }}
{{ t.s1t }}
{{ t.s1d }}
{{ t.s2t }}
{{ t.s2d }}
{{ t.s3t }}
{{ t.s3d }}
{{ t.caseKicker }}
{{ t.caseTitle }}
{{ t.caseCtx }}
{{ t.caseNote }}
{{ t.svcKick }}
{{ t.svcTitle2 }}
{{ t.svcSub }}
{{ t.heroCta1 }}
{{ t.svcCta2 }}
71
{{ t.svcL1 }}
$114–178k
{{ t.svcL2 }}
0
{{ t.svcL3 }}
{{ t.svcTracksT }}
{{ t.svcTracksD }}
{{ k.t }}
{{ k.g }}
{{ k.d }}
{{ t.fcTitle }}
{{ t.svcFindD }}
{{ f.t }}
{{ f.d }}
{{ t.svcEngT }}
{{ t.colEng }}
{{ t.colTrack }}
{{ t.colShape }}
{{ e.n }}
{{ e.k }}
{{ e.s }}
{{ t.svcCtaT }}
{{ t.svcCtaD }}
{{ g.kicker }}
{{ g.title }}
{{ g.sub }}
{{ g.cta1 }}
{{ g.cta2 }}
{{ g.s1h }}
{{ p.t }}
{{ g.s2h }}
{{ g.s2sub }}
{{ c.t }}
{{ c.d }}
{{ g.s3h }}
{{ g.s3sub }}
{{ g.s4h }}
{{ g.s4sub }}
{{ g.tableNote }}
{{ g.s5h }}
{{ g.s5sub }}
{{ k.t }}
{{ k.d }}
{{ g.s6h }}
{{ c.t }}
{{ c.d }}
{{ g.faqH }}
{{ f.q }}
{{ f.a }}
{{ g.closerT }}
{{ g.closerD }}
{{ g.cta1 }}
{{ g.closerCta }}
{{ g.kicker }}
{{ g.title }}
{{ g.sub }}
{{ g.cta1 }}
{{ g.cta2 }}
{{ g.s1h }}
{{ p.t }}
{{ g.s2h }}
{{ g.s2sub }}
{{ g.tableNote }}
{{ g.s3h }}
{{ c.t }}
{{ c.d }}
{{ g.s4h }}
{{ c.t }}
{{ c.d }}
{{ g.faqH }}
{{ f.q }}
{{ f.a }}
{{ g.closerT }}
{{ g.closerD }}
{{ g.cta1 }}
{{ g.closerCta }}
{{ dom.kicker }}
{{ dom.title }}
{{ dom.lede }}
{{ dom.ctaBook }}
{{ dom.ctaChecks }}
{{ dom.hReads }}
{{ r.t }}
{{ r.d }}
{{ dom.hWhy }}
{{ p.t }}
{{ dom.findLabel }}
{{ dom.findName }}
{{ dom.lblScale }}
{{ dom.findScale }}
{{ dom.lblImpact }}
{{ dom.findImpact }}
{{ dom.findNote }}
{{ dom.hFaqs }}
{{ f.q }}
{{ f.a }}
{{ dom.hOther }}
{{ dom.otherSub }}
{{ dom.closerT }}
{{ dom.closerD }}
{{ dom.ctaBook }}
{{ dom.closerCta }}
{{ c.kicker }}
{{ c.title }}
{{ c.sub }}
{{ c.cta1 }}
{{ c.cta2 }}
{{ f.n }}
{{ f.l }}
{{ c.s1h }}
{{ c.s1sub }}
{{ c.tableNote }}
{{ c.s2h }}
{{ p.t }}
{{ c.s3h }}
{{ a.t }}
{{ a.d }}
{{ c.s4h }}
{{ f.q }}
{{ f.a }}
{{ c.closerT }}
{{ c.closerD }}
{{ c.cta1 }}
{{ c.closerCta }}
{{ art.kicker }}
{{ art.title }}
{{ art.dek }}
{{ art.dateLine }}
{{ s.h }}
{{ p.t }}
DQL
{{ s.code }}
{{ art.findLabel }}
{{ art.findName }}
{{ art.scaleLabel }}
{{ art.findScale }}
{{ art.impactLabel }}
{{ art.findImpact }}
{{ art.takeawayLabel }}
{{ art.takeaway }}
{{ art.moreLabel }}
{{ art.ctaTitle }}
{{ art.ctaSub }}
{{ art.ctaBtn }}
AudiTrace
{{ artIndexKicker }}
{{ artIndexTitle }}
{{ artIndexSub }}
{{ t.privTitle }}
{{ t.privUpdated }}
{{ s.h }}
{{ s.b }}
{{ t.termsTitle }}
{{ t.termsUpdated }}
{{ s.h }}
{{ s.b }}
{{ t.a11yTitle }}
{{ t.a11yUpdated }}
{{ s.h }}
{{ s.b }}
{{ c.t }}
{{ c.d }}
{{ t.pTitle }}
{{ p.t }}
{{ p.d }}
{{ p.fig }}
{{ t.hTitle }}
{{ s.n }}
{{ s.t }}
{{ s.d }}
{{ t.way1k }}
{{ t.way1t }}
{{ t.way1d }}
{{ t.way2k }}
{{ t.way2t }}
{{ t.way2d }}
{{ t.waysNote }}
{{ t.fcTitle }}
{{ i.t }}
{{ i.d }}
{{ t.prDelTitle }}
{{ d.t }}
{{ d.d }}
{{ t.dTitle }}
{{ t.dSub }}
{{ t.secTitle }}
{{ b.t }}
{{ b.d }}
{{ n.t }}
{{ t.oTitle }}
{{ o.k }}
{{ o.t }}
{{ o.d }}
{{ o.p }}
{{ t.faqTitle }}
{{ q.q }}
{{ q.a }}
{{ t.cTitle }}
{{ t.cSub }}
{{ t.badge }}
{{ t.fSentT }}
{{ t.fSentD }}
{{ ccDial }}
{{ formErrMsg }}
{{ t.footColServices }}
{{ t.navServices }}
AudiTrace
{{ t.navCase }}
{{ t.footColGuides }}
{{ footGuideAudit }}
{{ footGuideCost }}
{{ footGuideCase }}
{{ footGuideArticles }}
{{ t.footColReach }}
{{ t.navContact }}
hello@obzervability.com
© 2026 Obzervability · {{ t.footRights }}
{{ t.navPrivacy }}
{{ t.navTerms }}
{{ t.navA11y }}