Dynatrace

EOL Risk Scores
in your Dynatrace® environment

The endoflife.ai integration for use with the Dynatrace® platform brings the EOL Risk Score™, days to end of life and CISA Known Exploited Vulnerabilities exposure for 500+ products into Dynatrace as metrics, so end-of-life risk can be charted, alerted on and read next to the hosts and services Dynatrace already monitors. A small exporter, a ready-made dashboard and an alert recipe. Open source (MIT), free to run, and it reads the same public feed any customer can.

What it sends

Four metric keys, refreshed by one push a day. Every data point carries the product slug, its letter grade, its lifecycle label and whether an active CISA KEV entry applies.

endoflife.risk_score
The EOL Risk Score™ (0–100). Higher means more dangerous to keep running.
endoflife.days_until_eol
Days until the product's end-of-life date; negative once it has passed. Carries the date itself as a dimension.
endoflife.kev_factor_score
The Known Exploited Vulnerabilities component of the score on its own (0–20). Non-zero only when the product has an active KEV entry.
endoflife.days_until_next_eol
Days until the product's next cycle reaches end of life, with the version and date. The "approaching" signal.

Set it up

Three steps. The exporter is a single Python file with no dependencies beyond the standard library, and it never loops or retries on its own.

Step 1
In Dynatrace, generate an access token with the single scope metrics.ingest. That is the only permission the exporter needs.

Step 2
Set two environment variables and preview the payload before anything is sent.

shell
export DT_ENV_URL=https://<environment-id>.live.dynatrace.com
export DT_API_TOKEN=dt0c01....
python dt_push.py --dry-run
python dt_push.py --limit 25
python dt_push.py

Metrics appear under Metrics (search endoflife.) within a minute or two. Schedule the full push once a day; one run is about 2,000 data points.

Step 3
Import the dashboard: Dashboards → New dashboard → Upload and pick eol-risk-overview.dashboard.json from the repository. Eleven tiles: products tracked, average score, past-EOL count, KEV-exposed count, products by grade, a honeycomb of every product's score, the 25 highest-risk products, everything reaching end of life in the next 90 days, the past-EOL-and-exploited intersection, and the score trend.

Alert on it

A custom alert on max(endoflife.risk_score) split by product, firing when a product's score is above 80 (grade F, Critical risk), gives each product its own event. The repository README carries the exact settings.

Every date names its source The scores come from endoflife.ai/scores.json, rebuilt daily. For the products we verify directly, the date behind the score is read from the vendor's own lifecycle page; for the rest it comes from the open endoflife.date dataset, and the API says which. Nothing is guessed.
Open source Exporter, dashboard and alert recipe are MIT-licensed at github.com/endoflife-ai/dynatrace-eol-metrics. Questions or a date you believe is wrong: [email protected]. Corrections are published.

Not on Dynatrace?

The same data runs our Grafana dashboard, Zabbix template, Nagios check and the developer API.

All integrations Developer API Risk Score methodology