Skip to content
Back to skills

Discover Log Groups

ASecurity

List the account's real CloudWatch log groups and return those matching alert keywords (ranked, capped). Run this first so queries target log groups that actually exist instead of guessed names.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
devops

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add Perun-Engineering/sre-on-call --skill discover_log_groups --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Discover Log Groups?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Discover Log Groups
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/perun-engineering-discover-log-groups/badge)](https://www.skillsdirectory.com/skills/perun-engineering-discover-log-groups)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: discover_log_groups
description: List the account's real CloudWatch log groups and return those matching alert keywords (ranked, capped). Run this first so queries target log groups that actually exist instead of guessed names.
tool: agents.cloudwatch_logs.tools:discover_log_groups
---
# When to use

Always call this **first**, before `query_cloudwatch_logs`. Never invent or
guess conventional log group names — derive keywords from the `AlertContext`
(service/application names, cluster name, namespace, resource identifiers) and
let this tool tell you which log groups actually exist.

# Inputs

- `keywords` (required): tokens from the alert used as case-insensitive
  substring filters against real log group names. Pass several — e.g. for a
  pod alert on cluster `eks-uat` in namespace `monitoring`, pass
  `["eks-uat", "monitoring", "<service or workload name>"]`.

# Output

A list of real log group names to feed into `query_cloudwatch_logs`, ranked by
how many keywords they match. If nothing matches, the tool says so plainly —
report that no relevant CloudWatch log groups exist (the logs are likely
shipped elsewhere) rather than guessing names that will be skipped.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…