Skip to content
downpipes docs

Send downpipes backup-health metrics to New Relic

New Relic can take a direct OTLP metrics push from downpipes to your New Relic OTLP endpoint. One caveat first. New Relic’s own documentation describes OTLP protobuf and does not confirm the OTLP/HTTP JSON encoding this engine sends, and New Relic offers no hosted agentless pull. So configure the push, then verify New Relic actually ingested it against a live account before you rely on it.

Do not assume the push works from a 2xx on the delivery trail alone. Confirm the metrics themselves arrived in your account, and if they did not, use the /metrics scrape route instead.

What you need

  • A New Relic ingest key (New Relic’s licence key) and your region’s OTLP metrics endpoint.
  • Owner access to the downpipes console to set the OTLP metrics push.

Set it up

  1. In New Relic, get an ingest key and note your region’s OTLP metrics endpoint: US is https://otlp.nr-data.net/v1/metrics, and EU is https://otlp.eu01.nr-data.net/v1/metrics.
  2. In the console, open Integrations and choose the Datadog tile in the metrics group, not the New Relic one. The OTLP metrics push is a single account-wide destination and the Datadog tile is the only one that opens its form; the New Relic tile opens the /metrics scrape credential instead, which is the pull route in step 5.
  3. On that Datadog tile’s form, set Endpoint URL to your New Relic OTLP metrics URL, Auth header name to api-key, and paste your ingest key as the Auth secret. The secret is write-only: the engine seals it and never reads it back.
  4. Enable the destination. If a second owner must approve the change, nothing changes until they approve it. There is no test send, so wait for the delivery trail after the next scheduler tick.
  5. Verify the data actually landed by querying your account for the downpipe_* metrics. If they do not appear, New Relic has not accepted the JSON body, so switch to the scrape route. Open the New Relic tile in Integrations, mint a read-only token in the metrics scrape scope, and copy the metrics endpoint URL shown beside it. Then scrape that endpoint with the token from something you run, a Prometheus server forwarding through New Relic’s remote-write integration or the infrastructure agent’s Prometheus config, and clear the OTLP push destination so the two do not run at once. Note that the metrics credential is time-boxed: it defaults to a year from the mint and is capped at 400 days, so an unattended scrape stops with a 401 on the day it lapses. The console shows the expiry beside the credential. To renew it, choose Re-mint (replaces the current credential).
  6. If you use that scrape route and Cloudflare Access fronts your console hostname, an unattended scrape is turned away at the edge before the engine ever sees the bearer, whatever credential it carries. Before pointing the scraper at it, either give that scraper an Access service token to send as extra headers (a path-scoped Access application with a Service Auth policy), or add a narrow Bypass over /metrics; the minted credential still gates the scrape either way. The full remedy is on the /metrics endpoint.

Good to know

  • New Relic’s documentation confirms OTLP protobuf but not OTLP/HTTP JSON, which is what this engine sends, so treat the direct push as unverified until you have seen the metrics land in your own account.
  • New Relic has no hosted agentless scraper, so the pull alternative still means running the remote-write integration or the infrastructure agent yourself against a minted metrics token. The push mechanics and the per-vendor OTLP-acceptance table are on OTLP metrics push, and the scrape route is on the /metrics endpoint.

Last updated .