How destinations work
- Your AWS account always gets everything. Logs and metrics go to Amazon CloudWatch and traces go to AWS X-Ray, whether or not you add a destination.
- Each signal is configured on its own. Logs, metrics, and traces can each go to one additional destination, and each signal can use a different one. For example, you can send logs to Datadog and traces to an OTLP endpoint.
- You own the settings; Superblocks applies them. You store destination settings and credentials in AWS Secrets Manager in your Cloud-Prem account. Superblocks applies them at the next deployment.
Choose a destination
Configure a destination
1
Gather your destination details
Collect the values for each signal you want to send. You only need values for the signals you are configuring.
- Datadog
- OpenTelemetry and Prometheus
2
Create the secret in AWS Secrets Manager
In your Cloud-Prem AWS account, create a secret named exactly See the secret reference for every supported key.
superblocks-main/superblocks/customer_exporter. Include only the signals you want to send, and write every value as a string, including "true".- Datadog
- OpenTelemetry and Prometheus
3
Tell Superblocks
Let your Superblocks deployment team know the secret is ready. Superblocks applies the configuration at the next deployment.
4
Verify data is arriving
After the deployment completes, check your destination for new data from each signal you configured.
Send signals to different destinations
To split signals across destinations, combine keys from both in the same secret and enable each signal for only one destination. This example sends logs to Datadog and traces to an OTLP endpoint, and leaves metrics in your AWS account only:Forward from your AWS account
If you’d rather route telemetry yourself, use AWS features to forward it from your Cloud-Prem account. Superblocks doesn’t configure or manage this forwarding.
You can combine approaches. For example, send traces to an OTLP endpoint through the secret and forward logs yourself with a subscription filter.
Change or remove a destination
To change the secret, replace its value with the full, updated JSON, then tell your Superblocks deployment team:- Change a destination: update its endpoint, credentials, or site.
- Stop sending a signal: set that signal’s
_ENABLEDkey to"false". - Stop sending all signals: set every
_ENABLEDkey to"false", or delete the secret.
Troubleshooting
If data isn’t arriving after the deployment completes, check:- Secret name: the secret is named exactly
superblocks-main/superblocks/customer_exporterand is in your Cloud-Prem account. - Secret contents: the secret is valid JSON, uses the exact key names in the secret reference, and every value is a string (
"true", nottrue). - One destination per signal: a signal isn’t enabled for both Datadog and an OpenTelemetry or Prometheus endpoint.
- Credentials: the API key or
Authorizationvalue is valid, includes the scheme (such asBasic), and has permission to write data. - Datadog site: the site matches your Datadog account.
- Network access: outbound traffic from the Cloud-Prem account can reach your destination’s endpoints.

