This page showcases new features, changes, and bug fixes in Dynatrace SaaS version 1.344. It contains:
Application Observability | Distributed Tracing
Drill down from Distributed Tracing spans into the related frontend User Events and User Sessions to get frontend context directly in your trace analysis workflow. Spans with frontend links show User Event and Session details in the span panel and provide one‑click navigation to
Users & Sessions,
Experience Vitals, and
Error Inspector.
This allows faster end‑to‑end root‑cause analysis and effectively closes the loop, covering frontend-to-backend and backend-to-frontend analysis directly in the span details panel. No app switch is required to get the full picture.
These drilldowns are ingest-agnostic and cover spans from both OneAgent and OpenTelemetry.
Account Management | Cost Management
Cost monitors now deliver richer cost insights. The improved calculation model logic is reflected in forecasted value adjustments when the update takes effect.
Most values will experience no significant changes; deviations are possible, though rare, and are based on your actual DPS consumption data. If a deviation occurs, you'll receive a notification email. After the adjustment, forecasts are stable and consistent.
Account Management | Cost Management
There are new fields for logs, metrics, traces, and event queries to help you better identify where the query was triggered.
AI Observability | AI Observability
In
AI Observability, prompt evaluations are shown in the new Evaluations screen.
Application Observability | Distributed Tracing
You can now view trace waterfalls without leaving your current app context. This is possible in the Services, Failure Analysis, Response Time Analysis, and Logs tabs across Dynatrace. When you hover over the trace, a dedicated icon identifies what happens when you open the trace: indicates that the waterfall will open as an overlay within your current view; indicates that the trace will open in
Distributed Tracing.
What's new:
Application Observability | Distributed Tracing
You can now enrich your OpenTelemetry spans with heterogeneous arrays and complex records via the OTLP ingest API.
Application Observability | Open Telemetry
Dynatrace now preserves complex attribute values on ingested OTLP spans.
Application Observability | Services
Finding the services you care about in
Services just got easier as you can filter by what a service does, not by its identifiers. Two new filters let you navigate even large inventories in seconds. Both are derived automatically from the telemetry Dynatrace already collects, so there is nothing to tag or configure.
Application Observability | Services
Services now filters and segments by primary Grail fields and primary Grail tags.
Primary Grail fields like Kubernetes namespaces, clusters, and cloud accounts let you narrow down to exactly the services that matter for a given context, fast and across any timeframe.
Primary Grail tags bring your domain perspective in. In other words, they allow filtering by team ownership, organizational boundaries, or any dimension you've defined to surface what's relevant to you and your team.
Because filters and segments behave consistently across all perspectives in
Services, segments you've defined anywhere in Dynatrace work here too. This provides you with a focused view, no matter which angle you're working from.


Application Observability | Services
All service metrics and all metrics extracted from spans in OpenPipeline now include the primary Grail fields and primary Grail tags as metric dimensions. Additionally, an alert configured on these metrics generates an anomaly event that includes those fields.
Now you can:
Services.

Application Observability | Services
Smartscape now draws topology edges from your OpenTelemetry-instrumented services to the hosts and processes that they run on. This is done automatically, based on span context, and lets you trace service issues down to infrastructure in one click without leaving the topology.
To use this new functionality, update your OpenTelemetry Host Monitoring extension to version 3.1.1. Edges for services monitored through the extension's spans pipeline with then appear automatically, with no additional setup required.
Application Security | Vulnerabilities
Malicious package detection coverage in the Dynatrace Vulnerability Feed has been expanded. Runtime Vulnerability Analytics (RVA) now evaluates a broader set of malicious packages against the components loaded and executing in your environment, alongside existing vulnerability data.
Malicious package records use the same structure as vulnerability records, so existing dashboards, filters, and remediation workflows continue to work.
Malicious code to distinguish them from known vulnerabilities.CWE-506 (Embedded Malicious Code).AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).Coverage spans the same six ecosystems as the Dynatrace Vulnerability Feed: Java, JavaScript, Python, Go, .NET, and PHP.
Business Analytics
Connect Snowflake to Dynatrace with a guided configuration wizard in Data Observability Application. You get out-of-the-box warehouse health, query performance, and credit consumption dashboards. This functionality replaces the existing Snowflake extension; if you are currently using the extension, no action is required on your part.
Business Analytics | Business Analytics
Compliance Assistant now supports the APRA CPS 230 framework to track, manage, and automate compliance across your IT and business landscape. The APRA CPS 230 framework (Operational Risk Management framework for Australian financial institutions) sets mandatory requirements for operational resilience, incident reporting, and governance to ensure critical operations are protected, and material incidents are reported appropriately.
This extends the existing support for the DORA framework.
Business Analytics | Business Analytics
Compliance Assistant now supports multi-framework management. In addition to existing support for DORA, we've now added APRA CPS 230 including to the guided onboarding process.
Digital Experience
We’ve upgraded our core experience apps (
Experience Vitals,
Users & Sessions,
Error Inspector,
Synthetic) to natively use Smartscape entities and fields.
dt.smartscape.* entities, instead of dt.entity.* and dt.rum.application.*.
Experience Vitals have been updated to use the new Smartscape entities and relations.We recommend to stop using legacy fields like dt.entity.application, dt.rum.application.entity, dt.rum.application.entities, and dt.rum.application.type in queries, dashboards, segments, and integrations, and start using Smartscape fields (dt.smartscape.*) in:
Digital Experience | Synthetic
You can now install on Windows Server 2025 hosts for private synthetic locations.
Digital Experience | Users & Sessions
In
Users & Sessions, you can now see the reasons why Session Replay recordings are unavailable.
Infrastructure Observability
This extension lets you monitor data pipeline health, performance, and cost for Lakehouse and Spark inside Dynatrace.
Infrastructure Observability | AWS
You can now ingest AWS logs directly from Amazon S3 via the new S3 Logs forwarder. This functionality is added alongside the existing Amazon Data Firehose ingestion method. Direct S3 ingest ships logs without the intermediate CloudWatch Logs or Firehose streaming layer, reducing costs and operational overhead while avoiding the restrictions that security-sensitive environments might impose on Firehose deployment.
To forward logs from sources such as AWS CloudTrail, Amazon VPC Flow Logs, ELB access logs, and Amazon CloudFront, deploy once with a Dynatrace-maintained AWS Lambda function in your centralized logging account. An S3 event notification triggers the Dynatrace forwarder Lambda function when a new S3 Logs object is created. The Lambda function parses, enriches, and forwards records to the new Dynatrace AWS S3 logs ingest API, where records are routed through OpenPipeline for processing and storage.
Infrastructure Observability | Kubernetes
In
Kubernetes, we’ve added a new drill-down navigation to the list, detail, and chart pages. These drill-downs allow troubleshooting into, for example,
Services,
Logs,
Clouds, or
Infrastructure & Operations.
Infrastructure Observability | Kubernetes
Dynatrace will automatically disable stale Kubernetes connection settings if no successful connection has been established for 60 days. This action is recorded in the audit log and can be reversed by re-enabling the connection via the API or the web UI.
Infrastructure Observability | Kubernetes
Starting with Kubernetes app version 1.43, you can now jump directly from any Kubernetes entity to related data in other Dynatrace apps. Active filters, timeframe, and segments are automatically carried over, so you land in the target app with your context already applied.
A context menu for every entity (in Explorer lists and on detail pages) provides one-click access to the most relevant view for that entity type.
The following actions are available across most Kubernetes resources.
Services.
Smartscape.Additional actions appear depending on the Kubernetes resource.
Clouds (Cluster, Node, Persistent Volume).
Infrastructure & Operations (Node).
Infrastructure & Operations (Pod).
Profiling & Optimization.Platform | API Gateway
The openpipeline:events.davis:ingest permission now supports two new IAM policy conditions, openpipeline:event-provider and openpipeline:event-type. Use them to grant event-ingest access for a specific event source and event type, rather than granting the permission for all events. This allows users to have just the access they need.
An example policy condition to allow your user to write comments from
Problems without granting broad event-write permissions is below:
ALLOW openpipeline:events.davis:ingest WHERE openpipeline:event-provider = "PROBLEM_APP" AND openpipeline:event-type = "CUSTOM_ANNOTATION";
Platform | Dashboards
Dashboards and
Notebooks now support labels, which you can use to search and filter your content list.
For details, see Dashboards: Manage labels or Notebooks: Manage labels.

Platform | Dashboards
Dashboard queries now stop automatically when you close the tab or navigate away. This prevents orphaned long-running work, frees capacity, and might reduce query costs.
Platform | Dashboards
We added a new ready-made tile to the Dashboards library that shows the open and closed problem counts as a honeycomb chart, with a built-in drill-down to
Problems.

Platform | Dynatrace Intelligence
You can now configure which personally identifiable information (PII) blocking patterns are active for Dynatrace Intelligence agentic AI. A new setting lets administrators disable individual PII detection patterns or turn off PII blocking entirely, giving you control over the balance between data protection and response quality.
PII blocking protects sensitive data in user and workflow prompts, but overly broad detection can degrade response quality by blocking false-positives. Patterns designed to catch credit card numbers or government IDs were also flagging legitimate observability data; these include timestamps, CVE identifiers, host IDs, Kubernetes metrics, and vulnerability patterns. This overly broad detection led to blocked or degraded responses for common operational queries. With configurable blocking rules, you can selectively disable patterns that cause false positives in your environment while keeping the protections that matter to your organization.
When PII blocking is active and a detection pattern is identified in the user prompt, the chat UI highlights the match and identifies which pattern triggered it, with a link to documentation for further explanation.
Platform | Dynatrace Intelligence
ProblemsYou can now close one or more active problems from
Problems. Select active problems from the problem list or open the details of a single problem to close it and add a closing comment.
Once the current anomaly is closed, future anomalies will trigger a new problem. You can close up to 50 problems in a single bulk action. The closing comment is available in
Problems, and can also be queried from Grail. The closing process may take a short time as the status change is propagated across several systems.
You can also close problems programmatically, via the existing v2 Problems REST API.
Platform | Dynatrace Intelligence
Dynatrace Assist can now tailor every response to your role, expertise, and preferences. Set it once, and benefit in every conversation. With personalization, it means no more repeating context at the start of every chat. The more specific your profile and custom instructions, the more relevant Assist's answers: whether that's terse DQL examples for an experienced SRE, or guided walkthroughs for someone new to the platform.
The new Personalization screen lets you configure:
This context is applied automatically to all future conversations, and you can update, clear, or disable it at any time.
Platform | Notebooks
Annotations are now available in
Notebooks, in addition to the already-released annotations for
Dashboards. You can use annotations to mark important events such as deployments, alerts, or any other noteworthy moments on timeseries-based charts to level up your exploratory analysis.
To add an annotation, select any line, area, or bar chart and click "+" in the Annotations section within the options. Annotations can be based on DQL queries, code, or Alert configurations, and offer various visual options, such as color and icons. Use the Preview tab to verify your annotation looks as expected before saving.
You can add multiple annotations per section, and they automatically refresh with the latest data whenever the section is rerun.

Platform | OneAgent
We’ve introduced two new commands to detach and attach log stream subtasks. These are useful if the subtask unexpectedly terminated, but you don’t want to restart the entire zDC.
To detach both log stream subtasks: Modify ZDCJOB,LOG DETACH.
To attach both log stream subtasks: Modify ZDCJOB,LOG ATTACH.
Platform | OpenPipeline
Duration type fieldsOpenPipeline now supports matching via:
=, !=, >, >=, <, and <=.If the record has a field of type duration, it’s compared against other duration static type conditions (literal or duration functions). It isn’t compared against long, timestamp, or string fields.
Platform | OpenPipeline
To better help you migrate your classic pipelines to OpenPipeline, Dynatrace now has a classic pipeline migration helper tool that is exposed via a public HTTP endpoint. It performs a best-effort conversion and returns an OpenPipeline pipeline equivalent of the classic pipeline.
Platform | Platform Services
You can now select Synthetic monitors with logical AND and OR.
tag(tag1),tag(tag2) is the logical AND.tag(tag1,tag2) is the logical OR.Previously, both formats were the logical OR.
Platform | Smartscape
In
Smartscape, the Service dependency graph now shows FRONTEND nodes. You can use these to drill down the call path from user-facing applications to the services they depend on, all in one view.
Platform | Smartscape
Smartscape now includes a dedicated AI Observability view that visualizes all of your GENAI_ nodes and their relationships, giving you full end-to-end visibility into your AI landscape and the connections between your generative AI components.
Platform | Workflows
You can now configure a delay for Dynatrace Intelligence Problem event triggers. The trigger will fire only if a problem remains open for the configured period. This reduces noisy notifications.
Threat Observability | Security events
Proactively hunt and remediate emerging threats by automatically pulling in threat reports and their indicators of compromise from threat intelligence sources that expose STIX/TAXII 2 server. This helps your team assess exposure and act before the attackers do.
Threat Observability | Security events
Proactively hunt and remediate emerging threats by automatically pulling in threat reports and their indicators of compromise. This lets your team assess exposure and act before the attackers do.
Threat Observability | Security events
Proactively hunt and remediate emerging threats by automatically pulling in threat reports and their indicators of compromise. This lets your team assess exposure and act before the attackers do.
Threat Observability | Security events
Bring adversary-grade threat intelligence into your workflow. You can automatically ingest Falcon Intelligence reports and IOCs to expose your security gaps against the most sophisticated, targeted threats. For more information, see Ingest CrowdStrike detection findings, threat reports, and audit logs.
Threat Observability | Security events
The new security skill expands Dynatrace MCP security capabilities to cover all security event types (vulnerabilities, detections, and compliance findings), enriched with runtime environment context. This lets developers and SREs rely on AI agents to handle any security scenario with complete, accurate insights.
Platform | Dashboards
Starting with Dynatrace version 1.344, Dynatrace will apply stricter validation rules to dashboards and won't display dashboards that fail validation.
This will mainly affect dashboards created or modified via the API or external AI tools. Dashboards created and maintained using
Dashboards can’t fail validation unless you modify them otherwise.
Dashboards will display a warning and a failure reason, but the dashboard will continue to load as usual.DEV was not installed. (PS-46759)dt.smartscape.* was not shown as a recommended field in metric extraction. (PPX-13271)
Clouds, if queries are canceled, the UI will now show the Overview page. (INFOBS-11134)
Infrastructure & Operations so that all text renders correctly. (INFOBS-10716)
Infrastructure & Operations where primary tag filters and the Primary tags column could be missing in Smartscape-based inventory tables. Primary tags are now detected correctly from Smartscape node fields. (INFOBS-10711)
Clouds > Metrics > Other metrics section didn’t load the entity details sidebar properly. (INFOBS-10457)unit property is used. This adds unit.json to the Docker image. (GRAIL-54075)HTTP 403 errors. This fix overrides the authorization scope to use ClientCredentialsAuthProvider. (DI-29513).) was not properly escaped in match patterns for blocked resources; it was treated as a normal character. (DEM-30213)
Users & Sessions to crash. These errors are now handled within the player. (DEM-29038)
Live Debugger where instances weren't visible with certain groupings or filters. (APPOBS-37154)
AI Observability > Evaluations screen, so that the correct data is shown. (AI-263)
Problems. (DI-29326)