In Dynatrace Classic, AWS, Azure, and GCP tags flow through auto-tagging rules and management zones to scope dashboards, alerts, and permissions. In Latest Dynatrace, a limited, customer-selected set of your existing cloud tags is enriched directly onto every signal as primary Grail tags, so the same cloud context applies to routing, permissions, segmentation, and cost allocation without rebuilding it within Dynatrace.
primary_tags.* on logs, metrics, spans, events, Davis events, and problems, not only on the Smartscape nodes they describe.dt.security_context, dt.cost.costcenter, or dt.cost.product.aws.account.id, azure.subscription, and gcp.project.id are enriched automatically. Rules that only existed to surface these identifiers are no longer needed.In Dynatrace version 1.348, central configuration is available for newly created connections only. Starting with Dynatrace version 1.349, existing cloud connections (New Cloud Platform Monitoring) also get a Use new unified enrichment settings toggle. Turning it on automatically upgrades their per-connection tag enrichment to central configuration, with no separate upgrade step.
List the AWS, Azure, and GCP tags your classic setup relies on and map each one to a primary Grail field, a primary Grail tag, or a special field (dt.security_context, dt.cost.costcenter, dt.cost.product). Upgrade any classic cloud connections to new cloud connections. Then enrich the tags at the source, verify the result with DQL, and retire the redundant classic rules.
Before changing anything, list what your classic setup currently depends on.
You have a list of cloud tag keys to upgrade, split into those already covered by a primary Grail field and those that need explicit selection.
Primary Grail tag enrichment is only available for new cloud connections. If you're running classic cloud connections, upgrade them to new cloud connections before you reach the enrichment steps.
For each remaining tag, decide what it becomes in the new model. Your mapping table won't mirror your original tag list one-to-one because the outcome depends on what each tag encodes.
dt.security_context, dt.cost.costcenter, or dt.cost.product instead of a generic primary tag.primary_tags.<key> name for it.You have a mapping table that assigns each classic cloud tag one of four outcomes: redundant (already covered by a built-in field), a special field (dt.security_context, dt.cost.costcenter, dt.cost.product), a named primary Grail field, or a primary_tags.* tag.
Before applying the mapping, make sure you have at least one new cloud connection set up for the expected cloud accounts. Primary Grail tag enrichment is not available for classic cloud connections.
Apply the tag mapping using the enrichment method that fits each case, starting with the least invasive option.
If a value already varies only by account, subscription, project, or region, check whether a built-in primary Grail field already covers it. If so, no configuration is needed.
For each remaining cloud tag, map it directly to a primary field, or forward it for promotion to a primary tag:
For details, see Promote AWS tags with central configuration. If central configuration isn't available in your environment yet, use AWS connection settings instead.
If a cloud tag was forwarded rather than mapped directly to a primary field, promote it to a primary_tags.* tag with an OpenPipeline primary Grail tag rule.
For cloud compute monitored with OneAgent, enrich tags at the host or process level instead. For details, see Enrich OneAgent telemetry with primary Grail fields and tags.
If none of the above covers a case, fall back to OpenPipeline processing.
Check the Resulting mapping preview in the central enrichment configuration, or rerun the DQL query from the next step to confirm the tag applies to the resources you expect.
Confirm the new tags and fields are present on the signals they should cover.
fetch logs| filter primary_tags.team == "payments" AND aws.region == "us-east-1"
fetch bizevents| filter dt.cost.costcenter == "payments"| summarize sum(value), by: {dt.cost.product}
The query returns the expected records with the new tag or field populated, matching what the old tag propagation used to produce.
Once permissions, routing, and cost allocation are cut over to the primary Grail model, clean up what's no longer needed.
Dashboards, alerts, and permissions continue to work using primary Grail fields and tags, and you retain only the classic auto-tagging rules and management zones that classic pages still require.
No. Select only the tags you specifically need for routing, permissions, segmentation, or cost allocation. Unselected cloud tags remain visible on Smartscape entities as regular tags but aren't enriched as primary Grail tags.
Use your provider's connection settings to enrich tags per connection instead. When central configuration becomes available, turning on the connection's unified enrichment settings upgrades your existing setup automatically, with no separate upgrade step. For the full upgrade procedure, see AWS, Azure, or Google Cloud.
Use OpenPipeline processing to derive dt.cost.costcenter, dt.cost.product, or a custom primary Grail tag from a combination of enriched fields, rather than trying to express the combination in the tag selection.
No. Primary Grail tag enrichment is only available for new cloud connections. Classic cloud connections (Dynatrace Classic, via ActiveGate) are not supported. If you're still running classic cloud connections, upgrade them to new cloud connections first, then configure your tag enrichment.