Logs Search helps you find the root cause of incidents fast. You search and filter Observability logs using a simple query language called ES|QL. This tool is perfect when you see a sudden spike in errors or an unusual pattern in your system. It guides you step by step to narrow down the noise until only the most important logs remain.
You start with a broad time range and a basic filter, then look at the histogram to spot when things went wrong. You iteratively add exclusion filters to remove known normal logs. Each round zeros in on the real problem. Finally you get a small set of logs to analyze, saving you from drowning in thousands of records.
The workflow mimics a funnel: broad first, then tighter. You always keep your previous exclusions so you never lose progress. This method is designed for incident investigation and works best when you need to drill into services, containers, or hosts quickly.
Global
mkdir -p ~/.claude/skills/observability-logs-searchProject
mkdir -p .claude/skills/observability-logs-searchSource Repository
Appinsights Instrumentationmicrosoft/azure-skills
Learn how to add Azure Application Insights monitoring to your web app
Azure Kustomicrosoft/azure-skills
Run fast KQL queries on Azure Data Explorer for log and telemetry analysis
Caveman Statsjuliusbrussee/caveman
See real token usage and estimated savings directly from your session log
Azure Observabilitymicrosoft/azure-skills
Track Azure app errors, performance, and infrastructure with monitoring tools
Convex Performance Auditget-convex/agent-skills
Find and fix Convex performance problems with step-by-step diagnostic guidance
Google Agents Cli Observabilitygoogle/agents-cli
Set up tracing, logging, and analytics for your ADK agents easily
Golang Observabilitysamber/cc-skills-golang
Monitor your Go services with logs metrics traces and profiling
Golang Samber Slogsamber/cc-skills-golang
Compose, sample, and route Go logs to multiple backends with ease