Network Traffic
Rapport de recherche Datadog : Bilan sur l'adoption de l'informatique sans serveur Rapport : Bilan sur l'adoption de l'informatique sans serveur

Network Traffic

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Traffic is always initiated by the Agent to Datadog. No sessions are ever initiated from Datadog back to the Agent:

  • All traffic is sent over SSL
  • The destination for:
    • APM data is
    • Live Containers data is
    • Logs data is for TCP traffic
    • All other Agent data:
      • Agents < 5.2.0
      • Agents >= 5.2.0 <VERSION>

This decision was taken after the POODLE problem. Versioned endpoints start with Agent v5.2.0, where each version of the Agent calls a different endpoint based on the version of the Forwarder. For example, Agent v5.2.0 calls Therefore you must whitelist * in your firewall(s).

These domains are CNAME records pointing to a set of static IP addresses. These addresses can be found at:

The information is structured as JSON following this schema:

    "version": 1,                       // <-- incremented every time this information is changed
    "modified": "YYYY-MM-DD-HH-MM-SS",  // <-- timestamp of the last modification
    "agents": {                         // <-- the IPs used by the Agent to submit metrics to Datadog
        "prefixes_ipv4": [              // <-- list of IPv4 CIDR blocks
        "prefixes_ipv6": [              // <-- list of IPv6 CIDR blocks
    "apm": {...},                       // <-- same structure as "agents" but IPs used for the APM Agent data
    "logs": {...},                      // <-- same for the logs Agent data
    "process": {...},                   // <-- same for the process Agent data
    "api": {...},                       // <-- not used for Agent traffic (submitting data via API)
    "webhooks": {...}                   // <-- not used for Agent traffic (Datadog source IPs delivering webhooks)

Each section has a dedicated endpoint at<SECTION>.json or<SECTION>.json, for example:


You should whitelist all of these IPs. While only a subset are active at any given moment, there are variations over time within the entire set due to regular network operation and maintenance.

Open Ports

All outbound traffic is sent over SSL via TCP / UDP.

Open the following ports in order to benefit from all the Agent functionalities:

  • Outbound:

  • Inbound:

    • 8125/udp: DogStatsd. Unless non_local_traffic is set to true. This port is available on localhost:

      • ::1
      • fe80::1
    • 8126/tcp: port for the APM Receiver

    • 17123/tcp: Agent forwarder, used to buffer traffic in case of network splits between the Agent and Datadog

    • 17124/tcp: optional graphite adapter

Using Proxies

For a detailed configuration guide on proxy setup, see Agent Proxy Configuration.

Further Reading