Try it free

Upgrade classic cloud tag propagation to primary Grail tags

  • Latest Dynatrace
  • Upgrade guide
  • 7-min read
  • Published Aug 31, 2026

In Dynatrace Classic, AWS, Azure, and GCP tags flow through auto-tagging rules and management zones to scope dashboards, alerts, and permissions. In Latest Dynatrace, a limited, customer-selected set of your existing cloud tags is enriched directly onto every signal as primary Grail tags, so the same cloud context applies to routing, permissions, segmentation, and cost allocation without rebuilding it within Dynatrace.

Why upgrade?

  • Enrichment on every signal, not only entities: Selected cloud tags become primary_tags.* on logs, metrics, spans, events, Davis events, and problems, not only on the Smartscape nodes they describe.
  • Reuse the tags you already maintain: Select the AWS, Azure, or GCP tags you already use for departments, owners, applications, or cost centers, without redefining them in Dynatrace.
  • Ready for permissions and cost allocation: The same selected tags can also populate dt.security_context, dt.cost.costcenter, or dt.cost.product.
  • Built-in infrastructure context: Fields such as aws.account.id, azure.subscription, and gcp.project.id are enriched automatically. Rules that only existed to surface these identifiers are no longer needed.
  • Automatic enrichment for new connections: New cloud connections use central configuration from the start. No additional enrichment setup is needed once you've selected your tags.

In Dynatrace version 1.348, central configuration is available for newly created connections only. Starting with Dynatrace version 1.349, existing cloud connections (New Cloud Platform Monitoring) also get a Use new unified enrichment settings toggle. Turning it on automatically upgrades their per-connection tag enrichment to central configuration, with no separate upgrade step.

What will you do?

List the AWS, Azure, and GCP tags your classic setup relies on and map each one to a primary Grail field, a primary Grail tag, or a special field (dt.security_context, dt.cost.costcenter, dt.cost.product). Upgrade any classic cloud connections to new cloud connections. Then enrich the tags at the source, verify the result with DQL, and retire the redundant classic rules.

Before you begin

Prerequisites

  • New cloud connections for the cloud accounts you want to enrich. If you're running classic cloud connections, upgrade them before or alongside the enrichment steps in this guide.
  • Access to your AWS, Azure, or GCP tagging conventions so you know which keys to select.
  • Write permission on Settings for the relevant cloud connection, or for central enrichment configuration if it's available in your environment.
  • A list of the cloud tags your current classic auto-tagging rules and management zones depend on.

Prior knowledge

  • Familiarity with how your organization tags or labels resources in AWS, Azure, or Google Cloud.
  • Basic DQL for verifying enriched data.

Breaking changes

  • Auto-tagging rules and management zones built on cloud tags are not evaluated for Grail data and are not used in any app. They remain supported only in classic pages.
  • Only a limited, explicitly selected set of cloud tags is enriched as primary Grail tags. Dynatrace doesn't automatically materialize every cloud tag the way classic entity propagation did.
  • Central enrichment configuration and OpenPipeline primary Grail tag rules have propagation delays and don't support Dynatrace Classic. For details, see the limitations for AWS, Azure, or Google Cloud.

How to upgrade

1. List your classic cloud tagging setup

Before changing anything, list what your classic setup currently depends on.

  1. List the AWS tags, Azure tags, and Google Cloud labels or tags that your classic auto-tagging rules and management zones reference.
  2. Note which values are infrastructure identifiers (account, subscription, project) already covered by a built-in primary Grail field, versus organizational context (owner, department, application, cost center) that needs an explicit selection.
  3. List the dashboards, alerts, or permission policies that depend on the management zones built from these tags.

You have a list of cloud tag keys to upgrade, split into those already covered by a primary Grail field and those that need explicit selection.

2. Upgrade classic cloud connections to new cloud connections

Primary Grail tag enrichment is only available for new cloud connections. If you're running classic cloud connections, upgrade them to new cloud connections before you reach the enrichment steps.

3. Map classic cloud tags to primary Grail fields and tags

For each remaining tag, decide what it becomes in the new model. Your mapping table won't mirror your original tag list one-to-one because the outcome depends on what each tag encodes.

  • If the tag reflects infrastructure context already covered by a built-in primary Grail field, mark it as redundant. No configuration is needed.
  • If the tag feeds permissions or cost allocation, map it to dt.security_context, dt.cost.costcenter, or dt.cost.product instead of a generic primary tag.
  • If the tag's value should populate an existing named primary Grail field that isn't populated automatically, map it directly to that field.
  • If the tag encodes organizational context (team, application, cost center, business unit), decide on a primary_tags.<key> name for it.

You have a mapping table that assigns each classic cloud tag one of four outcomes: redundant (already covered by a built-in field), a special field (dt.security_context, dt.cost.costcenter, dt.cost.product), a named primary Grail field, or a primary_tags.* tag.

4. Enrich at the source

Before applying the mapping, make sure you have at least one new cloud connection set up for the expected cloud accounts. Primary Grail tag enrichment is not available for classic cloud connections.

Apply the tag mapping using the enrichment method that fits each case, starting with the least invasive option.

  1. If a value already varies only by account, subscription, project, or region, check whether a built-in primary Grail field already covers it. If so, no configuration is needed.

  2. For each remaining cloud tag, map it directly to a primary field, or forward it for promotion to a primary tag:

    For details, see Promote AWS tags with central configuration. If central configuration isn't available in your environment yet, use AWS connection settings instead.

    For details, see Promote Azure tags with central configuration. If central configuration isn't available in your environment yet, use Azure connection settings instead.

    For details, see Promote Google Cloud labels and tags with central configuration. If central configuration isn't available in your environment yet, use Google Cloud connection settings instead.

  3. If a cloud tag was forwarded rather than mapped directly to a primary field, promote it to a primary_tags.* tag with an OpenPipeline primary Grail tag rule.

  4. For cloud compute monitored with OneAgent, enrich tags at the host or process level instead. For details, see Enrich OneAgent telemetry with primary Grail fields and tags.

  5. If none of the above covers a case, fall back to OpenPipeline processing.

Check the Resulting mapping preview in the central enrichment configuration, or rerun the DQL query from the next step to confirm the tag applies to the resources you expect.

5. Verify enrichment in Grail

Confirm the new tags and fields are present on the signals they should cover.

  1. Run a DQL query against the signal type most relevant to the upgraded tag, for example:
    fetch logs
    | filter primary_tags.team == "payments" AND aws.region == "us-east-1"
  2. For security context or cost allocation fields, confirm the value with a targeted filter or summary:
    fetch bizevents
    | filter dt.cost.costcenter == "payments"
    | summarize sum(value), by: {dt.cost.product}
  3. Spot-check a resource that previously relied on classic tag propagation and confirm the equivalent primary Grail tag or field is now present on its telemetry.

The query returns the expected records with the new tag or field populated, matching what the old tag propagation used to produce.

6. Retire redundant classic cloud tagging rules

Once permissions, routing, and cost allocation are cut over to the primary Grail model, clean up what's no longer needed.

  1. Re-point any dashboards, alerts, or permission policies that still reference the old management zones to the equivalent primary Grail fields, tags, or segments.
  2. Delete the auto-tagging rules and management zones flagged as redundant when you listed your classic setup.
  3. Keep any auto-tagging rules still required for classic pages. They're unaffected by this upgrade and can stay in place as long as those pages are in use.

Dashboards, alerts, and permissions continue to work using primary Grail fields and tags, and you retain only the classic auto-tagging rules and management zones that classic pages still require.

FAQ

Do I need to select every cloud tag I use today?

No. Select only the tags you specifically need for routing, permissions, segmentation, or cost allocation. Unselected cloud tags remain visible on Smartscape entities as regular tags but aren't enriched as primary Grail tags.

What if central configuration is not yet available in my environment?

Use your provider's connection settings to enrich tags per connection instead. When central configuration becomes available, turning on the connection's unified enrichment settings upgrades your existing setup automatically, with no separate upgrade step. For the full upgrade procedure, see AWS, Azure, or Google Cloud.

What if I need cost center or department from a combination of tags?

Use OpenPipeline processing to derive dt.cost.costcenter, dt.cost.product, or a custom primary Grail tag from a combination of enriched fields, rather than trying to express the combination in the tag selection.

Can I use primary Grail tags with my existing classic cloud connections?

No. Primary Grail tag enrichment is only available for new cloud connections. Classic cloud connections (Dynatrace Classic, via ActiveGate) are not supported. If you're still running classic cloud connections, upgrade them to new cloud connections first, then configure your tag enrichment.

Related topics

  • Enrich AWS telemetry with primary Grail fields and tags
  • Enrich Azure telemetry with primary Grail fields and tags
  • Enrich Google Cloud telemetry with primary Grail fields and tags
  • Differences between classic auto-tagging and primary Grail tags
  • Primary Grail fields and tags
  • Best practices for enriching primary Grail fields and tags
  • Upgrade to primary Grail fields and tags
Related tags
Infrastructure Observability