In modern cloud environments, infrastructure is typically organized at the hyperscaler level using cloud-native tags and attributes. The latest Dynatrace cloud connection propagates this metadata automatically into Dynatrace signals, so you do not need to reconfigure tags inside Dynatrace separately. These best practices help you get full value from cloud enrichment.
Cloud enrichment falls into two categories:
Cloud attributes: native cloud metadata and properties that Dynatrace uses to enrich entities and topology mapping. Examples include aws.resource.name, aws.account.id, aws.arn, azure.location, and gcp.region. Some of these are Primary Grail Fields—for example, aws.region, aws.account.id, azure.resource.group, and gcp.project.id—which propagate to every signal automatically.
Cloud tags: custom-defined tags set in the hyperscaler (for example, AWS resource tags, Azure resource tags, or GCP labels) that Dynatrace can propagate into platform signals.
Understanding the difference helps you design enrichment correctly. Cloud attributes come in automatically with the cloud connection. Cloud tags require explicit configuration to propagate beyond the entity level.
Cloud attributes are brought into the platform automatically when you use the latest cloud connection. Set up the appropriate connection for your cloud provider to start receiving cloud attribute enrichment:
All cloud tags applied to your cloud resources are collected at the entity level automatically when you use the latest cloud connection. You do not need additional configuration to see cloud tags on cloud entities.
Cloud tags are collected on the entity by default when using the latest cloud connection. To make cloud tags available on all signals—logs, spans, metrics, and events—not just on the entity, you must configure tag enrichment.
Tag enrichment lets you specify the cloud tag key so that Dynatrace propagates the tag value to every available signal type. Configure tag enrichment in your Dynatrace environment settings for each cloud tag you want to make available for segmentation, access control, or cost allocation.
Identify the cloud tags your organization uses to define application ownership, environment, and cost center before configuring enrichment. These are the tags you should propagate to all signals so they are available for IAM boundaries, segments, and bucket routing.
Dynatrace attribute enrichment lets you convert pre-existing cloud tags into Dynatrace-specific attributes. This is especially useful for access control and cost allocation. For example, you can map an AWS tag named app to dt.security_context, or map a tag named cost-center to dt.cost.costcenter.
Use Dynatrace attribute enrichment when your cloud tags align with Dynatrace permission and cost attribution fields. This approach avoids the need to reconfigure OneAgent installations for cloud-native resources, because the mapping is handled automatically by the cloud connection.
For cloud compute resources where OneAgent is installed, cloud tags are not automatically enriched at the process and service level. To enrich process and service signals with cloud tag values on OneAgent-monitored hosts, set the DT_TAGS environment variable on the host or use central enrichment rules.
Explore the other best practices for this stage, or return to Enrich your observability signals to continue your upgrade.