Skip to content
Back to skills

Capture Snapshot

ASecurity

Capture a snapshot of the top 10 CloudWatch Log groups by ingestion volume in the last 15 minutes, plus an error-line count for each via a bounded Logs Insights query.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
devopsaws

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add Perun-Engineering/sre-on-call --skill capture_snapshot --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Capture Snapshot?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Capture Snapshot
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/perun-engineering-capture-snapshot/badge)](https://www.skillsdirectory.com/skills/perun-engineering-capture-snapshot)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: capture_snapshot
description: Capture a snapshot of the top 10 CloudWatch Log groups by ingestion volume in the last 15 minutes, plus an error-line count for each via a bounded Logs Insights query.
tool: agents.cloudwatch_logs.tools:capture_snapshot
---
# When to use

Call this skill when the user message is a JSON object with `task: "snapshot"` — the master agent dispatches `/sre-snapshot` requests this way. Pass `requested_at` from the master verbatim.

# Inputs

- `requested_at` (required): ISO 8601 timestamp from the master, used as the `captured_at` field of the returned `SnapshotReport`.

# Output

A short human-readable summary plus an embedded `SnapshotReport` footer. One section:

- **Top 10 log groups by ingestion (last 15 min)** — `<group_name> · <bytes_humanized> · <n> errors`. Bytes come from `AWS/Logs/IncomingBytes` via a single `GetMetricData` call (paginated only when the account has more than 500 log groups). Error counts come from one bounded Logs Insights query against just those top 10 groups (`filter @message like /(?i)error|exception|fail/ | stats count() by @logGroup`).

# Anomaly criteria

`anomaly = True` when any of the top 10 groups has `error_count > 0`. The error analysis is best-effort — if the bounded Insights query fails, the section still renders the top-10 ranking by bytes alone, with no anomaly flagged.

The tool never raises — failure to enumerate log groups, fetch metrics, or run the Insights query is folded into a section line and (when it concerns the primary probe) flips the report to anomaly.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…