Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Logql Generator

ASecurity

Generates LogQL queries for Grafana Loki 3.0-3.6 log aggregation and metric extraction. Use when building Loki queries, dashboards, alerts, or optimizing pipeline performance with bloom filters, structured metadata, pattern matching, and approx_topk aggregations.

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
devopsgodebuggingapisecurityperformance

Works with

cliapimcp

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add bsamiee/Parametric_Portal --skill logql-generator --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Logql Generator?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Logql Generator
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/bsamiee-logql-generator/badge)](https://www.skillsdirectory.com/skills/bsamiee-logql-generator)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: logql-generator
description: >-
  Generates LogQL queries for Grafana Loki 3.0-3.6 log aggregation and metric extraction. Use when building Loki queries, dashboards, alerts, or optimizing pipeline performance with bloom filters, structured metadata, pattern matching, and approx_topk aggregations.
---

# [H1][LOGQL-GENERATOR]
>**Dictum:** *Pipeline order determines query performance.*

<br>

Generate LogQL for Loki 3.0-3.6 (bloom filters, structured metadata, `approx_topk`). Cross-references: **observability-stack** for Loki deployment, **promql-generator** for PromQL metric queries.

**Tasks:**
1. **Goal** -- Error analysis, performance, security, debugging? Dashboard, alert, ad-hoc?
2. **Sources** -- Labels (`job`, `namespace`, `app`), log format (JSON/logfmt/plain), time range.
3. **Query type** -- Log query (return lines) or metric query (calculate values)?
4. **Plan** -- Plain-English plan, confirm with user before generating.
5. **Generate** -- Apply patterns below; consult `references/best_practices.md`.
6. **Deliver** -- Final query + explanation + usage context (Grafana panel, alert rule, logcli, HTTP API).

---
## [1][VERSION_MATRIX]
>**Dictum:** *Version awareness prevents deprecated patterns.*

<br>

| [INDEX] | [VERSION] | [KEY_CHANGES]                                                                     |
| :-----: | --------- | --------------------------------------------------------------------------------- |
|   [1]   | **3.0**   | Bloom filters, structured metadata, pattern match `\|>` / `!>`.                   |
|   [2]   | **3.3**   | Bloom acceleration for structured metadata filters.                               |
|   [3]   | **3.5**   | Promtail deprecated (EOL March 2, 2026 -- use Alloy), SSD mode deprecated.        |
|   [4]   | **3.6**   | `approx_topk` on querier, reduced JSON/logfmt parser allocations, Loki UI plugin. |

**Guidance:**
- Promtail EOL March 2, 2026 -- migrate to Alloy.
- BoltDB deprecated -- use TSDB with v13 schema.

---
## [2][PIPELINE_ORDER]
>**Dictum:** *Each stage filters BEFORE the next -- moving expensive operations earlier wastes resources.*

<br>

```
{stream} -> line filter -> decolorize -> struct metadata -> parser -> label filter -> keep/drop -> format -> aggregate
 cheapest                                                                                              most expensive
```

**Guidance:**
- Structured metadata filters BEFORE parsers enables bloom filter acceleration (3.3+).
- Line filters (`|=`, `!=`) are O(1) substring checks -- place before parsers.
- Pattern match `|>` / `!>` uses `<_>` wildcards, 10x faster than regex (3.0+).

**Best-Practices:**
- Extract only needed JSON fields: `| json level, status` not `| json` -- reduces allocations (3.6).
- `| decolorize` before `| logfmt` -- ANSI codes break key=value parsing.
- `| drop instance, pod` before aggregation -- reduces series cardinality.

---
## [3][STREAM_AND_FILTERS]
>**Dictum:** *Specific stream selectors minimize chunk scanning.*

<br>

| [INDEX] | [OPERATOR] | [MEANING]          | [EXAMPLE]                               |
| :-----: | ---------- | ------------------ | --------------------------------------- |
|   [1]   | **`\|=`**  | Contains.          | `{job="app"} \|= "error"`               |
|   [2]   | **`!=`**   | Not contains.      | `{job="app"} != "debug"`                |
|   [3]   | **`\|~`**  | Regex match.       | `{job="app"} \|~ "error\|fatal"`        |
|   [4]   | **`!~`**   | Regex not match.   | `{job="app"} !~ "health\|metrics"`      |
|   [5]   | **`\|>`**  | Pattern match.     | `{app="api"} \|> "<_> level=error <_>"` |
|   [6]   | **`!>`**   | Pattern not match. | `{app="api"} !> "<_> level=debug <_>"`  |

---
## [4][PARSERS]
>**Dictum:** *Parser selection affects per-line cost.*

<br>

| [INDEX] | [PARSER]      | [SYNTAX]                                      | [USE_WHEN]                       |
| :-----: | ------------- | --------------------------------------------- | -------------------------------- |
|   [1]   | **`pattern`** | `\| pattern "<ip> - <_> <status>"`            | Fixed-delimiter structured text. |
|   [2]   | **`logfmt`**  | `\| logfmt [--strict] [--keep-empty]`         | `key=value` pairs.               |
|   [3]   | **`json`**    | `\| json` or `\| json status="response.code"` | JSON (specify fields for perf).  |
|   [4]   | **`regexp`**  | `\| regexp "(?P<field>\\w+)"`                 | Complex extraction, last resort. |
|   [5]   | **`unpack`**  | `\| unpack`                                   | Packed JSON from Alloy/Promtail. |

---
## [5][AGGREGATIONS]
>**Dictum:** *Metric queries aggregate log entries into time series.*

<br>

### [5.1][LOG_RANGE]

| [INDEX] | [FUNCTION]                        | [USE_WHEN]             |
| :-----: | --------------------------------- | ---------------------- |
|   [1]   | **`rate(log-range)`**             | Dashboard rate panels. |
|   [2]   | **`count_over_time(log-range)`**  | Counting occurrences.  |
|   [3]   | **`bytes_rate(log-range)`**       | Bandwidth monitoring.  |
|   [4]   | **`absent_over_time(log-range)`** | Dead service alerting. |

---
### [5.2][UNWRAPPED_RANGE]

| [INDEX] | [FUNCTION]                           | [USE_WHEN]                     |
| :-----: | ------------------------------------ | ------------------------------ |
|   [1]   | **`sum/avg/max/min_over_time`**      | Aggregate numeric values.      |
|   [2]   | **`quantile_over_time(phi, range)`** | Latency percentiles from logs. |
|   [3]   | **`first/last_over_time`**           | Boundary values.               |
|   [4]   | **`rate_counter(range)`**            | Counter-like log values.       |

Operators: `sum`, `avg`, `min`, `max`, `count`, `stddev`, `topk`, `bottomk`, `approx_topk`, `sort`, `sort_desc`.
Grouping: `sum by (label1, label2) (...)` or `sum without (label1) (...)`.

---
### [5.3][APPROX_TOPK]

`approx_topk(k, expr)` -- probabilistic top-K via count-min sketch, instant queries only. Requires `limits_config.shard_aggregations: [approx_topk]` on querier.

---
## [6][STRUCTURED_METADATA]
>**Dictum:** *Structured metadata enables high-cardinality filtering without index impact.*

<br>

Filter AFTER stream selector, BEFORE parsers for bloom acceleration. NOT indexed -- no cardinality impact.

```logql
{app="api"} | trace_id="abc123" | json | level="error"     # CORRECT -- bloom accelerated
# WRONG: {app="api", trace_id="abc123"}                     # trace_id is NOT an indexed label
```

**Guidance:**
- Bloom filters (3.3+) provide O(1) chunk skipping for string equality and OR filters placed before parsers.
- Automatic labels: `service_name` (from container/OTel), `detected_level` (when `discover_log_levels: true`).
- `vector(0)` fallback in alerting prevents "no data" flapping on sparse logs.

---
## [7][METRIC_PATTERNS]
>**Dictum:** *Metric queries are pre-aggregated -- prefer for dashboards and alerts.*

<br>

| [INDEX] | [PATTERN]            | [QUERY]                                                                                   |
| :-----: | -------------------- | ----------------------------------------------------------------------------------------- |
|   [1]   | **Rate**             | `rate({job="app"} \|= "error" [5m])`                                                      |
|   [2]   | **Count by label**   | `sum by (app) (count_over_time({ns="prod"} \| json [5m]))`                                |
|   [3]   | **Error percentage** | `sum(rate({app="api"} \| json \| level="error" [5m])) / sum(rate({app="api"}[5m])) * 100` |
|   [4]   | **Latency P95**      | `quantile_over_time(0.95, {app="api"} \| json \| unwrap duration [5m])`                   |
|   [5]   | **Approx Top 10**    | `approx_topk(10, sum by (endpoint) (rate({app="api"}[5m])))`                              |
|   [6]   | **Dead service**     | `absent_over_time({app="api"}[5m])`                                                       |
|   [7]   | **Offset compare**   | `sum(rate(...[5m])) - sum(rate(...[5m] offset 1d))`                                       |

---
## [8][NON-EXISTENT_FEATURES]
>**Dictum:** *Generating non-existent operators wastes user time.*

<br>

| [INDEX] | [FEATURE]         | [REALITY]                                                       |
| :-----: | ----------------- | --------------------------------------------------------------- |
|   [1]   | **`\| dedup`**    | UI-level in Grafana Explore. Use `sum by (field)` for dedup.    |
|   [2]   | **`\| distinct`** | Reverted PR #8662. Use `count(count by (field) (...))`.         |
|   [3]   | **`\| limit N`**  | API param `&limit=100`, Grafana "Line limit", logcli `--limit`. |

---
## [9][ALLOY_PIPELINE_STAGES]
>**Dictum:** *Alloy pipeline stages shape labels and metadata arriving in Loki.*

<br>

| [INDEX] | [STAGE]                      | [PURPOSE]                                  |
| :-----: | ---------------------------- | ------------------------------------------ |
|   [1]   | **`loki.relabel`**           | Map K8s labels to Loki labels.             |
|   [2]   | **`loki.process/multiline`** | Aggregate multi-line logs (stack traces).  |
|   [3]   | **`loki.process/sampling`**  | Reduce high-volume streams (cost control). |

[REFERENCE] `infrastructure/src/deploy.ts` lines 29-36.

---
## [10][RESOURCES]
>**Dictum:** *Reference files provide copy-paste patterns and performance guidance.*

<br>

- `examples/log_queries.logql` -- log parsing, filtering, structured metadata, template functions.
- `examples/metric_queries.logql` -- aggregation, alerting, rate/counter functions, label operations.
- `references/best_practices.md` -- performance, anti-patterns, recording rules.
- context7 MCP (`grafana loki`) -- authoritative docs for unclear syntax.

Attribution

bsamieebsamiee
View sourceMore from bsamiee →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

393431 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2459130 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

929660 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

798220 votes
View all in devops →