> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect your data

> Add the data sources your investigations and SLOs read from, including a read-only AWS connection.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

A data source is a place the agent can read from: your metrics, logs, traces and dashboards. Alerts tell SRE Agent that something broke. Data sources are how it finds out why. This page covers the types you can add, what each one enables, and how to connect AWS without giving SRE Agent write access.

<Plan tier="Free" />

The Free plan includes one data source. Pro includes 15. Adding a source past your plan's limit shows `Your plan's data source limit has been reached.` Only organization administrators can add, edit or delete data sources.

## Add a data source

<Steps>
  <Step title="Open Data Sources">
    In the sidebar, select **Settings**, then the **Data Sources** tab, then **Add Data Source**.
  </Step>

  <Step title="Name it and choose a type">
    Enter a **Name** and pick the **Type** from the table below. The rest of the form changes with
    the type.
  </Step>

  <Step title="Tell it where and how to connect">
    For most types, enter the **URL** and choose **Authentication**: **None**, **Basic Auth**,
    **Bearer Token**, **API Key** or **Datadog Keys**. For AWS types, pick the **AWS Regions**
    instead of a URL. Select every region that holds resources you want to read. One data source
    covers all of them.
  </Step>

  <Step title="Test, then save">
    Select **Test Connection**. A successful test reports `Connection successful!`. A failure
    reports `Connection failed:` followed by the reason. When the test passes, select **Save Data
    Source**.
  </Step>
</Steps>

After you save, the source appears as a card with an **Enabled** badge. The card has a signal button to test the connection again, a pencil button to edit, a duplicate button, **Toggle** to disable or enable it, and a trash button. A **Failing** badge and the last error show on a card when queries to the source keep failing.

## Data source types

| Type | What it connects | What it enables |
| - | - | - |
| Prometheus | A Prometheus server, or Amazon Managed Service for Prometheus | PromQL queries during investigations, SLOs and SLIs, SLO wizard discovery |
| Loki | A Loki server | LogQL log search during investigations, SLOs and SLIs, SLO wizard discovery |
| Grafana | A Grafana instance | Dashboard panels in investigations, and links from alerts back to Grafana |
| CloudWatch Metrics | AWS CloudWatch metrics | Metric queries during investigations, SLOs and SLIs, SLO wizard discovery |
| CloudWatch Logs | AWS CloudWatch Logs | Logs Insights queries during investigations, SLOs and SLIs |
| CloudTrail | AWS CloudTrail | Looking up recent API activity during investigations |
| X-Ray | AWS X-Ray | Trace lookups during investigations |
| Elasticsearch | An Elasticsearch cluster | Lucene and Query DSL searches during investigations |
| Datadog Metrics | Datadog metrics | Metric queries during investigations, SLOs and SLIs |
| Datadog Logs | Datadog logs | Log search during investigations |
| New Relic Metrics | New Relic metrics | NRQL metric queries during investigations, SLOs and SLIs |
| New Relic Logs | New Relic logs | NRQL log queries during investigations |

An investigation uses whichever of these exist. With no data source, the agent still receives the alert but has nothing to query, and the alert page warns that results will be shallow.

### Fields that depend on the type

| Type | Extra field | Why |
| - | - | - |
| Grafana | **Public URL (for alert links)** | The address people in your team open in a browser, used for links back to Grafana |
| CloudWatch Logs | **Default log group** | Logs Insights queries and SLIs need a log group. Without one, no query is sent |
| New Relic Metrics, New Relic Logs | **Account ID** | NRQL queries fail without it. It is in your New Relic URL after `/accounts/` |
| Datadog Metrics, Datadog Logs | **Authentication** set to **Datadog Keys** | Enter a **DD API Key** and a **DD Application Key** |
| Prometheus on Amazon Managed Service for Prometheus | **AWS Regions**, with an AWS authentication option | The request signature is bound to one region |

### Data inside a private network

If SRE Agent cannot reach a source from the internet, set **Route through Remote Agent** on the source to send its queries through a remote agent that runs in your network. The default is **Direct connection (no agent)**. Remote agents are on the Pro plan and above.

## Connect AWS

CloudWatch Metrics, CloudWatch Logs, CloudTrail and X-Ray read from your AWS account through a read-only role that you create. [Connect AWS with a read-only role](/guides/get-started/connect-aws) walks through it.

## Keep your data on your own AI provider

Investigations run on SRE Agent's shared AI until you add your own provider under **Settings**, then **AI Providers**, then **Add Provider**. The form asks for a **Name**, the **Provider**, the **Model** and your **API Key**. Select **Save Provider**, then press **Test** on the provider card to check the key. To make sure your alert text and logs only ever reach providers you configured, turn on **Use only my own AI providers** on the same tab. You need at least one enabled provider first. With it on, an AI call that your providers cannot take fails instead of running on the shared AI.

## What you see

A passing test shows `Connection successful!`. A failing test shows `Connection failed:` and the reason.

If a query returns nothing although the credentials are right, check the regions selected on the data source first. A source with the wrong region reads an empty account.

## Related

* [Run and read an investigation](/guides/respond/investigations): what the agent does with these sources.
* [Set up SLOs](/guides/prevent/slos): build SLOs on the metrics you connected.
* [Limits](/guides/reference/limits): data source limits on each plan.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.