Try it free

Best practices for enrichment with central enrichment rules

  • Latest Dynatrace
  • Best practices
  • Published Aug 24, 2026

In Dynatrace Classic, teams used auto-tags and management zones to segregate data. In the latest platform, you must enrich telemetry at the source: through OneAgent, Dynatrace Operator, the Dynatrace ActiveGate Collector (DAC), or the OpenTelemetry Collector. For many organizations, this is a significant challenge because it requires a company-wide enrichment strategy. Central enrichment rules let you orchestrate source enrichment directly from your Dynatrace environment without touching each observability component individually.

This page covers best practices for using central enrichment rules (requires OneAgent 1.343+). For the full configuration reference, see Configure ingest enrichment rules.

Upgrade components to meet version requirements

Central enrichment rules require minimum component versions. Upgrade your observability components to meet these thresholds before configuring central enrichment rules.

ComponentMinimum version for primary_tags.* and dt.security_contextMinimum version for central enrichment

OneAgent

1.337

1.343

Kubernetes Operator

—

1.10

ActiveGate

—

1.341

OneAgent version 1.337 or later supports dt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* enrichment. OneAgent version 1.343 or later is required to receive central enrichment rule configuration.

Components below the minimum version cannot receive central enrichment rule configuration. Identify all components below version 1.343 and schedule upgrades as part of your enrichment stage.

Pre-configure enrichment fields at install time

You do not need central enrichment rules to start enriching signals. Configure dt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* fields as part of OneAgent installation or environment variable configuration.

If you have already configured per-component enrichment, those components do not need to be reconfigured when you set up central enrichment rules. Central enrichment uses the same field names and schema; it adds centralized management on top of existing per-component configuration.

Set enrichment fields using the appropriate method for each technology:

  • OneAgent: set host tags as --set-host-tag parameters during installation or through OneAgent configuration settings
  • Kubernetes Operator: configure enrichment fields in the DynaKube custom resource
  • OpenTelemetry Collector: add enrichment attributes as resource attributes in the collector configuration

Plan your enrichment schema

Central enrichment rules let you configure fields such as dt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* centrally and push them to OneAgent automatically. The same mechanism extends to the Kubernetes Operator, DAC, and OpenTelemetry Collector.

To use central enrichment effectively

  1. Define the dimensions your organization needs, for example, primary_tags.app, primary_tags.team, and primary_tags.stage.
  2. Agree on value conventions across teams; consistent naming ensures segments, IAM policies, and bucket routing rules work without per-team exceptions.
  3. Document the mapping between classic management zone names and the new dimension values: this mapping drives the segment and IAM boundary configuration in subsequent upgrade stages.

A consistent enrichment schema is the key requirement for central enrichment rules to work without per-team exceptions. Define dimension names and value conventions across teams before enabling rules.

Ready for more?

Explore the other best practices for this stage, or return to Enrich your observability signals to continue your upgrade.

  • Best practices for metadata enrichment
  • Best practices for cloud enrichment
  • Best practices for RUM data access controls
Related tags
Dynatrace Platform