Enrich new Zendesk tickets with Datadog error context

By General Input

Every 10 minutes, an agent enriches brand new Zendesk tickets with the engineering error context support reps would otherwise have to ask an SRE for.

Integrations

  • Zendesk
  • Datadog
  • Slack Bot

Type

Agentic Task

Categories

  • Customer Support
  • Engineering

Build an agent workflow that enriches brand new Zendesk tickets with Datadog error context so support reps stop pinging engineering to ask "is this just my customer, or is something on fire?"

Trigger: a cron that runs every 10 minutes.

On each run, use Zendesk Search Tickets to pull tickets created since the last run (status:new or status:open created>{last_run_iso}). For each ticket, extract:

- The requester's email

- Any account id, order id, tenant id, or trace id mentioned in the subject or description

- The ticket's created_at timestamp

Then call Datadog Search Logs (POST) scoped to a window of roughly 30 minutes before the ticket was opened through the ticket's created_at time, filtered by the requester's email and/or any account id you found, looking for errors and exceptions. Also call Datadog Search Monitors to see if any monitors were in alert state during that window, and Datadog Search Incidents to see if any incidents were active or recently opened.

Use Zendesk Update Ticket to add an internal note (public:false) on the ticket. Keep it under 8 lines. Either:

- "No related errors found in Datadog for {email} in the 30 minutes before this ticket opened." plus a link to the Datadog log search that was run, or

- A summary of the top 3 error patterns observed: for each pattern include status code, service, count, and a one-line summary. Include a link to the Datadog log search and call out any firing monitor or open incident by name.

Never post a public reply. The note is always internal-only.

If across the batch of tickets in this run the agent detects what looks like a platform-wide incident (multiple unrelated tickets in the same window plus a firing Datadog monitor or open incident), also use Slack Bot Send a Message to post a heads-up to a configured incident channel (default #incidents) so on-call and CX leads can coordinate before the ticket queue spikes. The Slack message should name the suspected service or monitor, count of affected tickets in this window, and link to the relevant Datadog log search, monitor, and ticket list.

Configurable parameters: cron interval (default every 10 minutes), Datadog lookback window in minutes (default 30), Slack incident channel (default #incidents), and the list of identifier patterns to extract from ticket bodies (default: email, account_id, order_id, trace_id, tenant_id).

Use agent mode because deciding which errors are relevant to the ticket, summarizing log patterns into a short rep-friendly note, and judging "is this a platform-wide incident" all require reasoning, not a fixed pipeline.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them