> ## Documentation Index
> Fetch the complete documentation index at: https://docs.resolve.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Dynatrace

This guide explains how to connect ResolveAI with Dynatrace. Resolve uses this connection to ingest metrics, logs, dashboards, and problems for incident investigations.

## 1. Create Tokens

Dynatrace exposes two API surfaces — the classic Environment API and the newer Platform (Grail) API. Resolve needs a token for each.

<Accordion title="Access Token (classic Environment API)">
  1. In Dynatrace, open **Apps → Access Tokens**
  2. Click **Generate new token**
  3. Name it `resolve-access-token`
  4. Select the following scopes:
     * `metrics.read`
     * `entities.read`
     * `problems.read`
     * `events.read`
     * `settings.read`
  5. Click **Generate token** and copy the value
</Accordion>

<Accordion title="Platform Token (Grail / Documents API)">
  1. In Dynatrace, open **Account Management → Identity & access management → Platform tokens**
  2. Click **Generate new token**
  3. Name it `resolve-platform-token`
  4. Select the following scopes:
     * `storage:buckets:read`
     * `storage:bucket-definitions:read`
     * `storage:logs:read`
     * `storage:metrics:read`
     * `storage:spans:read`
     * `storage:events:read`
     * `storage:entities:read`
     * `storage:smartscape:read`
     * `storage:system:read`
     * `document:documents:read`
  5. Click **Generate token** and copy the value
</Accordion>

<Warning>
  **Security Best Practice:** Never store credentials in plaintext in configuration files or source control. Treat both tokens as secrets and rotate them on a regular cadence.
</Warning>

## 2. Find Your Environment URLs

Resolve needs the base URL for each Dynatrace API surface. Both can be found in your Dynatrace tenant URL:

* **Classic API URL** (`apiUrl`): `https://<tenant-id>.live.dynatrace.com`
* **Platform API URL** (`appUrl`): `https://<tenant-id>.apps.dynatrace.com`

Where `<tenant-id>` is the alphanumeric identifier for your environment (e.g. `abc12345`).

## 3. Connect Dynatrace

Set up the integration either in the **Resolve UI** or in the **Satellite** configuration.

<Tabs>
  <Tab title="Resolve UI">
    ### Connect Via Resolve UI

    1. Open [Dynatrace Integration](https://app0.resolve.ai/integrations/dynatrace/connect) in Resolve
    2. Click **Add Connection**
    3. Enter a name (ex. `Dynatrace-Main`)
    4. Set the **Environment** that matches the data this connection will ingest (ex. `production`)
    5. Paste the **Access token** from Step 1 (Access Token)
    6. Paste the **Platform token** from Step 1 (Platform Token)
    7. Enter your **API URL** (ex. `https://abc12345.live.dynatrace.com`)
    8. Enter your **App URL** (ex. `https://abc12345.apps.dynatrace.com`)
    9. (Optional) Enable [Sensitive Data Redaction](/sensitive-data-redaction)
    10. Click **Save**
  </Tab>

  <Tab title="Satellite">
    ### Connect Via Satellite

    Save the Dynatrace **Access token** and **Platform token** in a Kubernetes secret, then update the Resolve Satellite to use this secret.

    #### 1. Create Kubernetes Secret

    Create a Kubernetes secret using this structure.

    ```yaml secret creation theme={null}
    apiVersion: v1
    kind: Secret
    type: Opaque
    metadata:
      name: dynatrace-resolve-token
    stringData:
      apiToken: "<your access token>"
      appToken: "<your platform token>"
    ```

    <Warning>
      **Security Best Practice:** Never store credentials in plaintext in configuration files or source control.
      Always use Kubernetes secrets and encrypt etcd or use enterprise secret management systems.
      See [Secret Management](/secret-management) for detailed guidance.
    </Warning>

    Apply the secret.

    ```shell apply secret theme={null}
    kubectl apply -f dynatrace-resolve-token.yml
    ```

    ***

    #### 2. Update Values File

    Add the Dynatrace integration to `resolve-values.yaml`.

    ```yaml resolve-values.yaml theme={null}
    integrations:
      dynatrace:
        type: "dynatrace"
        create: true
        secretName: "dynatrace-resolve-token"
        connection:
          apiUrl: https://abc12345.live.dynatrace.com
          appUrl: https://abc12345.apps.dynatrace.com
    ```

    (Optional) Add [sensitive data redaction](/sensitive-data-redaction) with `redactionConfig`.

    ```yaml resolve-values.yaml theme={null}
    integrations:
      dynatrace:
        type: "dynatrace"
        create: true
        secretName: "dynatrace-resolve-token"
        connection:
          apiUrl: https://abc12345.live.dynatrace.com
          appUrl: https://abc12345.apps.dynatrace.com
          redactionConfig:
            enabled: true
    ```

    ***

    #### 3. Apply Changes

    Update the satellite with the new `resolve-values.yaml` file.

    ```shell theme={null}
    helm upgrade --install resolve-satellite \
      oci://registry-1.docker.io/resolveaihq/satellite-chart \
      --values resolve-values.yaml
    ```

    ***

    #### 4. Verify Integration

    Open [Dynatrace Integration](https://app0.resolve.ai/integrations/dynatrace/connect) and check the connection.
  </Tab>
</Tabs>

***

## What Resolve Ingests

Once connected, Resolve continuously ingests the following from Dynatrace:

* **Infrastructure entities** — hosts, services, processes, and Smartscape topology used to build the service map
* **Alert rules** — Dynatrace metric events and problem patterns
* **Problems** — open and historical Dynatrace problems, used as alerts during investigations
* **Logs** — queried on demand via Grail using the Dynatrace Query Language (DQL)
* **Metrics** — queried on demand using the Dynatrace Metric Selector language
* **Dashboards** — Platform dashboards (Documents API) are loaded for chart-level context during investigations
