Set up telemetry connectors for Incident Command Center

Incident Command Center is currently available through an early access program (EAP). Features, interfaces, and availability may change as we continue development.

The Incident Command Center is available to customers on the Jira Service Management Premium and Enterprise plans.

Incident Command Center integrates with third-party observability providers to display metrics, logs, and telemetry directly within your incident view.

はじめる前に

  • Confirm you have organization administrator permissions for your site.

  • Confirm you can create API keys or OAuth clients in your observability provider.

  • Use a dedicated service account or integration credential with the minimum required permissions.

Privacy, telemetry, and data security

  • Read-only access: Incident Command Center doesn’t create, modify, or delete resources in your observability provider.

  • Secure credential handling: Credentials are encrypted in Atlassian's secure integration store and are not exposed in the UI or logs.

  • Minimum access: Permissions are limited to metric and timeseries queries required for telemetry.

  • No dashboard, log, or trace access: These connectors query only metrics and time series data.

Supported providers

Provider

Credential type

必要な権限

Auth header

Datadog

API key and Application key

metrics_read,timeseries_query, org_management

DD-API-KEY,DD-APPLICATION-KEY

New Relic

User API key

Read-only access with NRQL query permissions

Api-Key

Dynatrace (Grail)

OAuth 2.0 client credentials

storage:metrics:read,storage:buckets:read

Authorization: Bearer <token>

SignalFx

API access token

API authorization scope

X-SF-TOKEN

Set up a connector

Datadog

Datadog requires two credentials:

  • API Key that is created at the organization level.

  • Application Key that inherits permissions from its owner.

We recommend creating a dedicated service account for this integration.

Step 1: Create credentials in Datadog

To set up an account in Datadog:

  1. Create or select a dedicated service account.

  2. Assign a role to the service account containing only the following three permissions:

    • metrics_read: Reads metric names, tags, and points.

    • timeseries_query: Executes scalar and timeseries queries.

    • org_management: Allows a one-time read of your organization’s public_id upon connection.

  3. Go to Organization Settings > API Keys, then select New Key, and copy the API key.

  4. Go to Organization Settings > Application Keys while logged in as the service account. Then select New Key, and copy the Application key.

Step 2: Configure in Atlassian Administration

  1. Go to admin.atlassian.com and select your organization.

  2. Go to Rovo, then select Connectors, and select Datadog.

  3. [Connect] を選択します。

  4. Fill in the connection details:

    • Connection name: A name that is easy to recognize and remember.

    • API key: The Datadog API key that you created in the previous steps.

    • Application key: The Datadog Application key that you created in the previous steps.

    • Domain URL: Your Datadog site API host (for example, https://api.datadoghq.com for US1, https://api.datadoghq.eu for EU, https://api.us3.datadoghq.com, etc.).

    • Environment: Your Datadog APM environment tag (for example, prod).

    • Namespace: (Optional) Custom identifier for grouping.

Don't enter the Datadog region, such as us1 or eu, in the Environment field. Always enter the region in the Domain URL, such as `https://api.datadoghq.com` or `https://api.datadoghq.eu`.

The Environment field corresponds to your APM service env tag.

New Relic

Step 1: Create credentials in New Relic

To create a User key in New Relic:

  1. Create or select a dedicated service user with read-only permissions scoped to the relevant accounts.

  2. Open Administration > API keys.

  3. Select Create a key.

  4. Set the key type User and make sure it’s assigned to your service user.

  5. Copy the generated key. User keys start with NRAK-.

Ingest, License, and Browser keys don't work with this connector. NerdGraph queries require a User key.

Step 2: Configure in Atlassian Administration

  1. Go to admin.atlassian.com and select your organization.

  2. Go to Rovo, then select Connectors, and select New Relic.

  3. [Connect] を選択します。

  4. Fill in the connection details:

    • Connection name: A name that is easy to recognize and remember.

    • API key: The User key that you created in the previous steps starting with NRAK-.

    • Domain URL: Your New Relic site API host (for example, https://api.newrelic.com for US and https://api.eu.newrelic.com for EU).

    • Namespace: (Optional) Custom identifier for grouping.

Dynatrace (Grail)

This integration uses Dynatrace Platform/Grail OAuth 2.0 client authentication.

Step 1: Create an OAuth 2.0 client in Dynatrace

  1. Open Dynatrace Account Management and go to Identity & access management > OAuth clients.

  2. Select Create client and enter a descriptive name. For example, Atlassian ICC Telemetry

  3. Under Scopes, select both mandatory scopes:

    • storage:metrics:read - Authorizes access to the metrics data type.

    • storage:buckets:read - Authorizes access to the underlying Grail storage buckets.

  4. Copy the Client ID, Client secret, and Account URN. Make sure to make a copy of the Client secret because it’s shown only once.

Both scopes are required to connect Dynatrace with Rovo. Without storage:buckets:read, Grail can return empty responses, and charts can remain blank.

Step 2: Configure in Atlassian Administration

  1. Go to admin.atlassian.com and select your organization.

  2. Go to Rovo, then select Connectors, and select Dynatrace.

  3. [Connect] を選択します。

  4. Fill in the connection details:

    • Connector name: A name that is easy to recognize and remember.

    • Client ID: The OAuth Client ID generated in the previous steps.

    • Client Secret: The OAuth Client Secret generated in the previous steps.

    • Account URN: Your Dynatrace account URN.

    • Base URL: Your Dynatrace Platform host URL in the format https://<env-id>.apps.dynatrace.com.

    • Namespace: (Optional) Custom identifier for grouping.

Use a Platform URL in the format `https://<env-id>.apps.dynatrace.com`. Don't use a Classic Dynatrace URL ending in .live.dynatrace.com. If you update scopes in Dynatrace later, re-save the connector configuration to refresh permissions.

SignalFx (Splunk Observability cloud)

Step 1: Create an Access token in Splunk

  1. Open Splunk Observability cloud and go to Settings > Access Tokens.

  2. Create a new token or edit an existing one.

  3. Ensure the token includes the API authorization scope.

  4. Copy the token value.

Tokens scoped only for INGEST may not work. Telemetry queries used by this connector require the tokens with the API scope.

Step 2: Configure in Atlassian Administration

  1. Go to admin.atlassian.com and select your organization.

  2. Go to Rovo, then select Connectors, and select SignalFx.

  3. [Connect] を選択します。

  4. Fill in the connection details:

    • Connection name: A name that is easy to recognize and remember.

    • API token: The access token generated in the previous steps.

    • Domain URL: Your realm’s API host (for example, https://api.us1.signalfx.com for US or https://api.eu0.signalfx.com for EU).

    • Namespace: (Optional) Custom identifier for grouping.

Verify the connection

  1. Save the connector configuration.

  2. Open an ICC incident that uses telemetry.

  3. Confirm that the available services, metrics, and timeseries data load.

  4. Check that charts show data for the expected environment and time range.

さらにヘルプが必要ですか?

アトラシアン コミュニティをご利用ください。