Identify signals without proper enrichment and close gaps using central enrichment rules, OpenPipeline, and other post-ingest mechanisms. This stage runs after data ingestion has started and is iterative: validate coverage, fix gaps, re-validate until the enrichment ratio meets your defined threshold.
Metadata enrichment is the most critical preparation step in the entire upgrade: every downstream stage depends on dt.security_context and related attributes being consistently applied before IAM, segments, or cost allocation can be configured correctly. Gaps in enrichment propagate into misconfigured access control, broken segmentation, and inaccurate cost attribution.
This stage is iterative. Validate coverage, fix gaps, then re-validate, repeating the cycle until enrichment meets the agreed threshold.
Scope your upgrade to Latest Dynatrace: scope document signed off and classic configuration inventory complete.
| Role | Involvement | Responsibility |
|---|---|---|
Dynatrace Admin | Required | Configures enrichment rules, OpenPipeline processors, and central enrichment |
Data Owner | Recommended | Owns the source-of-truth for dimension mappings |
Application Teams | Recommended | Confirm their data is enriched correctly and flag gaps |
FinOps / Security | Optional | Use enriched dimensions for cost allocation and access control validation |
Confirm that all observability components meet the minimum version requirements to support Primary Grail Fields and Tags enrichment.
Verify: All observability components at or above the minimum required version for primary_tags.* enrichment.
Run the Enrichment Coverage dashboard to measure signal coverage and pinpoint which signals or resources are missing required metadata.
dt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* across all signal types (logs, traces, metrics, events).Verify: Enrichment coverage report generated with all gap areas identified before starting remediation.
Validate enrichment coverage first: insufficient enrichment at this step results in poorly configured access control, segmentation, and cost allocation across all downstream upgrade stages. Do not skip or abbreviate the coverage validation.
Apply central enrichment rules, OpenPipeline processors, and other post-ingest mechanisms to close the gaps identified in the previous step. Repeat the validate → close → re-validate cycle until coverage meets the agreed threshold.
Verify: Enrichment coverage for dt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* at or above the agreed threshold across all signal types.
Refresh your lookup tables regularly: enrichment maps not refreshed after team or product changes attribute data to retired owners. Agree on a refresh cadence with the data owner before closing this stage.
Account for backfill limitations: enrichment applies only to signals ingested after the rule is active. Historical queries may show inconsistent dimensions for signals ingested before enrichment was in place.
Stage complete when:
primary_tags.* enrichmentdt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* is at or above the agreed threshold across all signal typesWith enrichment validated across all signal types, you have the metadata foundation that every downstream stage depends on. The next stage is Upgrade management zones to IAM and segments: configure access boundaries and dynamic segment-based filters using the enrichment attributes you've now applied consistently.
The following resources support your work in this stage. Documentation covers platform concepts, configuration reference, and related guides; best practice cards provide implementation guidance from Dynatrace experts.
Reference for configuring primary_tags.* enrichment across OneAgent, Kubernetes, and OpenTelemetry sources.
Overview of Dynatrace tagging, including central enrichment and tag strategies for enrichment at scale.
Best practices for metadata enrichment
Enrich all observability signals with Primary Grail Fields and Tags to enable IAM, segmentation, and cost allocation.
Best practices for cloud enrichment
Propagate cloud attributes and custom-defined tags into Dynatrace signals using the latest cloud connection.
Best practices for enrichment with central enrichment rules
Configure central enrichment rules and prepare observability components for centralized metadata enrichment.
Best practices for RUM data access controls
Configure RUM data access permissions, restrict sensitive fields, and set up bucket access for user events and sessions in Grail.
When enrichment coverage meets the agreed threshold, you're ready to configure the access boundaries that IAM, segments, and filtering all depend on. The enrichment metadata you've applied here will directly drive segment definitions and IAM policy scope in stage 3.
Continue to Upgrade management zones to IAM & segments.